mirror of
https://github.com/Sea-Haven-Industries/.github.git
synced 2026-09-30 04:43:12 +00:00
Add seahaven-account-baseline deploy role; codify cfn-exec cloudfront/ssm (audit H-16) (#31)
- New githubdeploy-seahaven-account-baseline OIDC role (CDK pattern: assumes cdk-hnb659fds-*, scoped to the repo's main branch). Wires CD for the shared account-baseline repo (CloudTrail C-1 + AWS Backup C-7). - Codify cloudfront:* and ssm:* on github-cfn-execution-role to reconcile out-of-band drift (audit H-16). These are needed by live SAM deploys (meal-order CloudFront; afterhours/payments/meal-order SSM params). Deployed via change set wire-account-baseline-and-h16; stack now IN_SYNC. IAM cross-review completed (new role confirmed; cfn-exec breadth documented).
This commit is contained in:
parent
87318ac8dd
commit
f5e93b7933
1 changed files with 35 additions and 0 deletions
|
|
@ -69,6 +69,12 @@ Resources:
|
|||
- sqs:*
|
||||
- sns:*
|
||||
- ec2:*
|
||||
# cloudfront:* and ssm:* reconciled from out-of-band drift
|
||||
# (audit H-16) — needed by SAM deploys that manage CloudFront
|
||||
# distributions (meal-order-manager) and SSM parameters
|
||||
# (afterhours / payments / meal-order). Codified 2026-05-29.
|
||||
- cloudfront:*
|
||||
- ssm:*
|
||||
Resource: "*"
|
||||
|
||||
# ---------------------------------------------------------------------------
|
||||
|
|
@ -494,6 +500,33 @@ Resources:
|
|||
Resource:
|
||||
- !Sub arn:aws:iam::${AWS::AccountId}:role/cdk-hnb659fds-*
|
||||
|
||||
SeahavenAccountBaselineDeployRole:
|
||||
Type: AWS::IAM::Role
|
||||
Properties:
|
||||
RoleName: githubdeploy-seahaven-account-baseline
|
||||
AssumeRolePolicyDocument:
|
||||
Version: "2012-10-17"
|
||||
Statement:
|
||||
- Effect: Allow
|
||||
Principal:
|
||||
Federated: !Sub arn:aws:iam::${AWS::AccountId}:oidc-provider/token.actions.githubusercontent.com
|
||||
Action: sts:AssumeRoleWithWebIdentity
|
||||
Condition:
|
||||
StringEquals:
|
||||
token.actions.githubusercontent.com:aud: sts.amazonaws.com
|
||||
StringLike:
|
||||
token.actions.githubusercontent.com:sub: !Sub repo:${GitHubOrg}/seahaven-account-baseline:ref:refs/heads/main
|
||||
Policies:
|
||||
- PolicyName: cdk-deploy
|
||||
PolicyDocument:
|
||||
Version: "2012-10-17"
|
||||
Statement:
|
||||
- Effect: Allow
|
||||
Action:
|
||||
- sts:AssumeRole
|
||||
Resource:
|
||||
- !Sub arn:aws:iam::${AWS::AccountId}:role/cdk-hnb659fds-*
|
||||
|
||||
Outputs:
|
||||
SamCfnExecutionRoleArn:
|
||||
Value: !GetAtt SamCfnExecutionRole.Arn
|
||||
|
|
@ -517,3 +550,5 @@ Outputs:
|
|||
Value: !GetAtt ProcurementIngestDeployRole.Arn
|
||||
ApmWoAnalysisDeployRoleArn:
|
||||
Value: !GetAtt ApmWoAnalysisDeployRole.Arn
|
||||
SeahavenAccountBaselineDeployRoleArn:
|
||||
Value: !GetAtt SeahavenAccountBaselineDeployRole.Arn
|
||||
|
|
|
|||
Loading…
Add table
Reference in a new issue