Add seahaven-account-baseline deploy role; codify cfn-exec cloudfront/ssm (audit H-16) (#31)

- New githubdeploy-seahaven-account-baseline OIDC role (CDK pattern: assumes
  cdk-hnb659fds-*, scoped to the repo's main branch). Wires CD for the shared
  account-baseline repo (CloudTrail C-1 + AWS Backup C-7).
- Codify cloudfront:* and ssm:* on github-cfn-execution-role to reconcile
  out-of-band drift (audit H-16). These are needed by live SAM deploys
  (meal-order CloudFront; afterhours/payments/meal-order SSM params).

Deployed via change set wire-account-baseline-and-h16; stack now IN_SYNC.
IAM cross-review completed (new role confirmed; cfn-exec breadth documented).
This commit is contained in:
Adam Moussa 2026-05-29 18:28:00 -04:00 • committed by GitHub
parent 87318ac8dd
commit f5e93b7933
No known key found for this signature in database
GPG key ID: B5690EEEBB952194

View file

@ -69,6 +69,12 @@ Resources:
- sqs:*
- sns:*
- ec2:*
# cloudfront:* and ssm:* reconciled from out-of-band drift
# (audit H-16) — needed by SAM deploys that manage CloudFront
# distributions (meal-order-manager) and SSM parameters
# (afterhours / payments / meal-order). Codified 2026-05-29.
- cloudfront:*
- ssm:*
Resource: "*"
# ---------------------------------------------------------------------------
@ -494,6 +500,33 @@ Resources:
Resource:
- !Sub arn:aws:iam::${AWS::AccountId}:role/cdk-hnb659fds-*
SeahavenAccountBaselineDeployRole:
Type: AWS::IAM::Role
Properties:
RoleName: githubdeploy-seahaven-account-baseline
AssumeRolePolicyDocument:
Version: "2012-10-17"
Statement:
- Effect: Allow
Principal:
Federated: !Sub arn:aws:iam::${AWS::AccountId}:oidc-provider/token.actions.githubusercontent.com
Action: sts:AssumeRoleWithWebIdentity
Condition:
StringEquals:
token.actions.githubusercontent.com:aud: sts.amazonaws.com
StringLike:
token.actions.githubusercontent.com:sub: !Sub repo:${GitHubOrg}/seahaven-account-baseline:ref:refs/heads/main
Policies:
- PolicyName: cdk-deploy
PolicyDocument:
Version: "2012-10-17"
Statement:
- Effect: Allow
Action:
- sts:AssumeRole
Resource:
- !Sub arn:aws:iam::${AWS::AccountId}:role/cdk-hnb659fds-*
Outputs:
SamCfnExecutionRoleArn:
Value: !GetAtt SamCfnExecutionRole.Arn
@ -517,3 +550,5 @@ Outputs:
Value: !GetAtt ProcurementIngestDeployRole.Arn
ApmWoAnalysisDeployRoleArn:
Value: !GetAtt ApmWoAnalysisDeployRole.Arn
SeahavenAccountBaselineDeployRoleArn:
Value: !GetAtt SeahavenAccountBaselineDeployRole.Arn