mirror of
https://github.com/Sea-Haven-Industries/.github.git
synced 2026-09-30 08:13:12 +00:00
chore(iam): remove soaked githubdeploy roles from the template (PLAT-232)
Drops the management-account deploy roles for front-integrations, afi-backup-monitor, exec-aide, seahaven-door-unlock-api, and apm-wo-analysis. CloudTrail showed no successful mutation for 14 days. Deploying this stack deletes those roles. This change does not deploy it. Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com>
This commit is contained in:
parent
0a1010e632
commit
f0caef85db
1 changed files with 8 additions and 232 deletions
|
|
@ -1051,146 +1051,6 @@ Resources:
|
||||||
Resource:
|
Resource:
|
||||||
- !GetAtt SamCfnExecutionRole.Arn
|
- !GetAtt SamCfnExecutionRole.Arn
|
||||||
|
|
||||||
FrontIntegrationsDeployRole:
|
|
||||||
Type: AWS::IAM::Role
|
|
||||||
Properties:
|
|
||||||
RoleName: githubdeploy-front-integrations
|
|
||||||
AssumeRolePolicyDocument:
|
|
||||||
Version: "2012-10-17"
|
|
||||||
Statement:
|
|
||||||
- Effect: Allow
|
|
||||||
Principal:
|
|
||||||
Federated: !Sub arn:aws:iam::${AWS::AccountId}:oidc-provider/token.actions.githubusercontent.com
|
|
||||||
Action: sts:AssumeRoleWithWebIdentity
|
|
||||||
Condition:
|
|
||||||
StringEquals:
|
|
||||||
token.actions.githubusercontent.com:aud: sts.amazonaws.com
|
|
||||||
StringLike:
|
|
||||||
token.actions.githubusercontent.com:sub: !Sub repo:${GitHubOrg}/front-integrations:ref:refs/heads/main
|
|
||||||
Policies:
|
|
||||||
- PolicyName: sam-deploy
|
|
||||||
PolicyDocument:
|
|
||||||
Version: "2012-10-17"
|
|
||||||
Statement:
|
|
||||||
- Effect: Allow
|
|
||||||
Action:
|
|
||||||
- cloudformation:CreateChangeSet
|
|
||||||
- cloudformation:DeleteChangeSet
|
|
||||||
- cloudformation:DescribeChangeSet
|
|
||||||
- cloudformation:DescribeStackEvents
|
|
||||||
- cloudformation:DescribeStacks
|
|
||||||
- cloudformation:ExecuteChangeSet
|
|
||||||
- cloudformation:GetTemplate
|
|
||||||
- cloudformation:ListStackResources
|
|
||||||
- cloudformation:UpdateStack
|
|
||||||
- cloudformation:CreateStack
|
|
||||||
- cloudformation:TagResource
|
|
||||||
Resource:
|
|
||||||
- !Sub arn:aws:cloudformation:us-east-1:${AWS::AccountId}:stack/front-integrations/*
|
|
||||||
- Effect: Allow
|
|
||||||
Action:
|
|
||||||
- cloudformation:GetTemplateSummary
|
|
||||||
Resource: "*"
|
|
||||||
- Effect: Allow
|
|
||||||
Action:
|
|
||||||
- cloudformation:DescribeStacks
|
|
||||||
- cloudformation:CreateChangeSet
|
|
||||||
- cloudformation:DescribeChangeSet
|
|
||||||
- cloudformation:ExecuteChangeSet
|
|
||||||
- cloudformation:CreateStack
|
|
||||||
Resource:
|
|
||||||
- !Sub arn:aws:cloudformation:us-east-1:${AWS::AccountId}:stack/aws-sam-cli-managed-default/*
|
|
||||||
- Effect: Allow
|
|
||||||
Action:
|
|
||||||
- s3:PutObject
|
|
||||||
- s3:GetObject
|
|
||||||
- s3:ListBucket
|
|
||||||
- s3:GetBucketLocation
|
|
||||||
- s3:CreateBucket
|
|
||||||
- s3:PutBucketPolicy
|
|
||||||
- s3:GetBucketPolicy
|
|
||||||
- s3:PutLifecycleConfiguration
|
|
||||||
- s3:PutBucketVersioning
|
|
||||||
- s3:DeleteObject
|
|
||||||
Resource:
|
|
||||||
- arn:aws:s3:::aws-sam-cli-managed-default-samclisourcebucket-*
|
|
||||||
- arn:aws:s3:::aws-sam-cli-managed-default-samclisourcebucket-*/*
|
|
||||||
- Effect: Allow
|
|
||||||
Action:
|
|
||||||
- iam:PassRole
|
|
||||||
Resource:
|
|
||||||
- !GetAtt SamCfnExecutionRole.Arn
|
|
||||||
|
|
||||||
AfiBackupMonitorDeployRole:
|
|
||||||
Type: AWS::IAM::Role
|
|
||||||
Properties:
|
|
||||||
RoleName: githubdeploy-afi-backup-monitor
|
|
||||||
AssumeRolePolicyDocument:
|
|
||||||
Version: "2012-10-17"
|
|
||||||
Statement:
|
|
||||||
- Effect: Allow
|
|
||||||
Principal:
|
|
||||||
Federated: !Sub arn:aws:iam::${AWS::AccountId}:oidc-provider/token.actions.githubusercontent.com
|
|
||||||
Action: sts:AssumeRoleWithWebIdentity
|
|
||||||
Condition:
|
|
||||||
StringEquals:
|
|
||||||
token.actions.githubusercontent.com:aud: sts.amazonaws.com
|
|
||||||
StringLike:
|
|
||||||
token.actions.githubusercontent.com:sub: !Sub repo:${GitHubOrg}/afi-backup-monitor:ref:refs/heads/main
|
|
||||||
Policies:
|
|
||||||
- PolicyName: sam-deploy
|
|
||||||
PolicyDocument:
|
|
||||||
Version: "2012-10-17"
|
|
||||||
Statement:
|
|
||||||
- Effect: Allow
|
|
||||||
Action:
|
|
||||||
- cloudformation:CreateChangeSet
|
|
||||||
- cloudformation:DeleteChangeSet
|
|
||||||
- cloudformation:DescribeChangeSet
|
|
||||||
- cloudformation:DescribeStackEvents
|
|
||||||
- cloudformation:DescribeStacks
|
|
||||||
- cloudformation:ExecuteChangeSet
|
|
||||||
- cloudformation:GetTemplate
|
|
||||||
- cloudformation:ListStackResources
|
|
||||||
- cloudformation:UpdateStack
|
|
||||||
- cloudformation:CreateStack
|
|
||||||
- cloudformation:TagResource
|
|
||||||
Resource:
|
|
||||||
- !Sub arn:aws:cloudformation:us-east-1:${AWS::AccountId}:stack/afi-backup-monitor/*
|
|
||||||
- Effect: Allow
|
|
||||||
Action:
|
|
||||||
- cloudformation:GetTemplateSummary
|
|
||||||
Resource: "*"
|
|
||||||
- Effect: Allow
|
|
||||||
Action:
|
|
||||||
- cloudformation:DescribeStacks
|
|
||||||
- cloudformation:CreateChangeSet
|
|
||||||
- cloudformation:DescribeChangeSet
|
|
||||||
- cloudformation:ExecuteChangeSet
|
|
||||||
- cloudformation:CreateStack
|
|
||||||
Resource:
|
|
||||||
- !Sub arn:aws:cloudformation:us-east-1:${AWS::AccountId}:stack/aws-sam-cli-managed-default/*
|
|
||||||
- Effect: Allow
|
|
||||||
Action:
|
|
||||||
- s3:PutObject
|
|
||||||
- s3:GetObject
|
|
||||||
- s3:ListBucket
|
|
||||||
- s3:GetBucketLocation
|
|
||||||
- s3:CreateBucket
|
|
||||||
- s3:PutBucketPolicy
|
|
||||||
- s3:GetBucketPolicy
|
|
||||||
- s3:PutLifecycleConfiguration
|
|
||||||
- s3:PutBucketVersioning
|
|
||||||
- s3:DeleteObject
|
|
||||||
Resource:
|
|
||||||
- arn:aws:s3:::aws-sam-cli-managed-default-samclisourcebucket-*
|
|
||||||
- arn:aws:s3:::aws-sam-cli-managed-default-samclisourcebucket-*/*
|
|
||||||
- Effect: Allow
|
|
||||||
Action:
|
|
||||||
- iam:PassRole
|
|
||||||
Resource:
|
|
||||||
- !GetAtt SamCfnExecutionRole.Arn
|
|
||||||
|
|
||||||
PaymentsDashboardDeployRole:
|
PaymentsDashboardDeployRole:
|
||||||
Type: AWS::IAM::Role
|
Type: AWS::IAM::Role
|
||||||
Properties:
|
Properties:
|
||||||
|
|
@ -1262,90 +1122,12 @@ Resources:
|
||||||
- !GetAtt SamCfnExecutionRole.Arn
|
- !GetAtt SamCfnExecutionRole.Arn
|
||||||
|
|
||||||
# ---------------------------------------------------------------------------
|
# ---------------------------------------------------------------------------
|
||||||
# CDK deploy roles (4 repos)
|
# CDK deploy role for seahaven-org-baseline.
|
||||||
|
# Soaked githubdeploy roles for front-integrations, afi-backup-monitor,
|
||||||
|
# exec-aide, seahaven-door-unlock-api, and apm-wo-analysis are removed
|
||||||
|
# here (PLAT-232). Deploying this stack deletes those roles.
|
||||||
# ---------------------------------------------------------------------------
|
# ---------------------------------------------------------------------------
|
||||||
|
|
||||||
ExecAideDeployRole:
|
|
||||||
Type: AWS::IAM::Role
|
|
||||||
Properties:
|
|
||||||
RoleName: githubdeploy-exec-aide
|
|
||||||
AssumeRolePolicyDocument:
|
|
||||||
Version: "2012-10-17"
|
|
||||||
Statement:
|
|
||||||
- Effect: Allow
|
|
||||||
Principal:
|
|
||||||
Federated: !Sub arn:aws:iam::${AWS::AccountId}:oidc-provider/token.actions.githubusercontent.com
|
|
||||||
Action: sts:AssumeRoleWithWebIdentity
|
|
||||||
Condition:
|
|
||||||
StringEquals:
|
|
||||||
token.actions.githubusercontent.com:aud: sts.amazonaws.com
|
|
||||||
StringLike:
|
|
||||||
token.actions.githubusercontent.com:sub: !Sub repo:${GitHubOrg}/exec-aide:ref:refs/heads/main
|
|
||||||
Policies:
|
|
||||||
- PolicyName: cdk-deploy
|
|
||||||
PolicyDocument:
|
|
||||||
Version: "2012-10-17"
|
|
||||||
Statement:
|
|
||||||
- Effect: Allow
|
|
||||||
Action:
|
|
||||||
- sts:AssumeRole
|
|
||||||
Resource:
|
|
||||||
- !Sub arn:aws:iam::${AWS::AccountId}:role/cdk-hnb659fds-*
|
|
||||||
|
|
||||||
SeahavenDoorUnlockApiDeployRole:
|
|
||||||
Type: AWS::IAM::Role
|
|
||||||
Properties:
|
|
||||||
RoleName: githubdeploy-seahaven-door-unlock-api
|
|
||||||
AssumeRolePolicyDocument:
|
|
||||||
Version: "2012-10-17"
|
|
||||||
Statement:
|
|
||||||
- Effect: Allow
|
|
||||||
Principal:
|
|
||||||
Federated: !Sub arn:aws:iam::${AWS::AccountId}:oidc-provider/token.actions.githubusercontent.com
|
|
||||||
Action: sts:AssumeRoleWithWebIdentity
|
|
||||||
Condition:
|
|
||||||
StringEquals:
|
|
||||||
token.actions.githubusercontent.com:aud: sts.amazonaws.com
|
|
||||||
StringLike:
|
|
||||||
token.actions.githubusercontent.com:sub: !Sub repo:${GitHubOrg}/seahaven-door-unlock-api:ref:refs/heads/main
|
|
||||||
Policies:
|
|
||||||
- PolicyName: cdk-deploy
|
|
||||||
PolicyDocument:
|
|
||||||
Version: "2012-10-17"
|
|
||||||
Statement:
|
|
||||||
- Effect: Allow
|
|
||||||
Action:
|
|
||||||
- sts:AssumeRole
|
|
||||||
Resource:
|
|
||||||
- !Sub arn:aws:iam::${AWS::AccountId}:role/cdk-hnb659fds-*
|
|
||||||
|
|
||||||
ApmWoAnalysisDeployRole:
|
|
||||||
Type: AWS::IAM::Role
|
|
||||||
Properties:
|
|
||||||
RoleName: githubdeploy-apm-wo-analysis
|
|
||||||
AssumeRolePolicyDocument:
|
|
||||||
Version: "2012-10-17"
|
|
||||||
Statement:
|
|
||||||
- Effect: Allow
|
|
||||||
Principal:
|
|
||||||
Federated: !Sub arn:aws:iam::${AWS::AccountId}:oidc-provider/token.actions.githubusercontent.com
|
|
||||||
Action: sts:AssumeRoleWithWebIdentity
|
|
||||||
Condition:
|
|
||||||
StringEquals:
|
|
||||||
token.actions.githubusercontent.com:aud: sts.amazonaws.com
|
|
||||||
StringLike:
|
|
||||||
token.actions.githubusercontent.com:sub: !Sub repo:${GitHubOrg}/apm-wo-analysis:ref:refs/heads/main
|
|
||||||
Policies:
|
|
||||||
- PolicyName: cdk-deploy
|
|
||||||
PolicyDocument:
|
|
||||||
Version: "2012-10-17"
|
|
||||||
Statement:
|
|
||||||
- Effect: Allow
|
|
||||||
Action:
|
|
||||||
- sts:AssumeRole
|
|
||||||
Resource:
|
|
||||||
- !Sub arn:aws:iam::${AWS::AccountId}:role/cdk-hnb659fds-*
|
|
||||||
|
|
||||||
SeahavenAccountBaselineDeployRole:
|
SeahavenAccountBaselineDeployRole:
|
||||||
Type: AWS::IAM::Role
|
Type: AWS::IAM::Role
|
||||||
Properties:
|
Properties:
|
||||||
|
|
@ -1394,24 +1176,18 @@ Outputs:
|
||||||
Name: github-cfn-execution-role-arn
|
Name: github-cfn-execution-role-arn
|
||||||
AfterhoursShiftManagerDeployRoleArn:
|
AfterhoursShiftManagerDeployRoleArn:
|
||||||
Value: !GetAtt AfterhoursShiftManagerDeployRole.Arn
|
Value: !GetAtt AfterhoursShiftManagerDeployRole.Arn
|
||||||
FrontIntegrationsDeployRoleArn:
|
|
||||||
Value: !GetAtt FrontIntegrationsDeployRole.Arn
|
|
||||||
AfiBackupMonitorDeployRoleArn:
|
|
||||||
Value: !GetAtt AfiBackupMonitorDeployRole.Arn
|
|
||||||
PaymentsDashboardDeployRoleArn:
|
PaymentsDashboardDeployRoleArn:
|
||||||
Value: !GetAtt PaymentsDashboardDeployRole.Arn
|
Value: !GetAtt PaymentsDashboardDeployRole.Arn
|
||||||
# SeahavenSlackBotDeployRoleArn removed 2026-07-27: the role was deleted
|
# SeahavenSlackBotDeployRoleArn removed 2026-07-27: the role was deleted
|
||||||
# out-of-band on 2026-07-23, so this !GetAtt failed as a live IAM read and
|
# out-of-band on 2026-07-23, so this !GetAtt failed as a live IAM read and
|
||||||
# broke every stack update. Nothing imported it (the Output had no
|
# broke every stack update. Nothing imported it (the Output had no
|
||||||
# ExportName, and no stack imports any export from this stack).
|
# ExportName, and no stack imports any export from this stack).
|
||||||
ExecAideDeployRoleArn:
|
|
||||||
Value: !GetAtt ExecAideDeployRole.Arn
|
|
||||||
SeahavenDoorUnlockApiDeployRoleArn:
|
|
||||||
Value: !GetAtt SeahavenDoorUnlockApiDeployRole.Arn
|
|
||||||
# ProcurementIngestDeployRoleArn removed 2026-08-07 (PLAT-88): HCP sole
|
# ProcurementIngestDeployRoleArn removed 2026-08-07 (PLAT-88): HCP sole
|
||||||
# mutate path; prod githubdeploy role deleted; mgmt twin already gone.
|
# mutate path; prod githubdeploy role deleted; mgmt twin already gone.
|
||||||
ApmWoAnalysisDeployRoleArn:
|
# FrontIntegrations, AfiBackupMonitor, ExecAide, SeahavenDoorUnlockApi,
|
||||||
Value: !GetAtt ApmWoAnalysisDeployRole.Arn
|
# and ApmWoAnalysis deploy role outputs removed 2026-09-28 (PLAT-232).
|
||||||
|
# CloudTrail showed no successful mutation for 14 days. The roles are
|
||||||
|
# deleted only when this stack is deployed. That deploy is not this change.
|
||||||
SeahavenAccountBaselineDeployRoleArn:
|
SeahavenAccountBaselineDeployRoleArn:
|
||||||
Value: !GetAtt SeahavenAccountBaselineDeployRole.Arn
|
Value: !GetAtt SeahavenAccountBaselineDeployRole.Arn
|
||||||
# MealOrderManagerWeeklyMenuRoleArn removed 2026-08-20 (PLAT-70): role deleted with resource.
|
# MealOrderManagerWeeklyMenuRoleArn removed 2026-08-20 (PLAT-70): role deleted with resource.
|
||||||
|
|
|
||||||
Loading…
Add table
Reference in a new issue