Fix CFN execution role transform permission and pip install path

- Add cloudformation:CreateChangeSet on aws:transform/* to the shared
  CFN execution role (required for SAM's Serverless transform)
- Remove working-directory from pip install step so it finds
  requirements.txt at repo root (not just cdk-dir)
This commit is contained in:
Adam Moussa 2026-05-08 17:11:36 -04:00
parent 9a8d1f7736
commit fffc08da43
2 changed files with 10 additions and 1 deletions

View file

@ -57,7 +57,6 @@ jobs:
- name: Install Python dependencies
if: ${{ inputs.python-version != '' }}
working-directory: ${{ inputs.cdk-dir }}
run: |
for req in $(find . -name requirements.txt -not -path '*/node_modules/*'); do
pip install -r "$req"

View file

@ -54,6 +54,16 @@ Resources:
- arn:aws:iam::aws:policy/AmazonEventBridgeFullAccess
- arn:aws:iam::aws:policy/AmazonSESFullAccess
- arn:aws:iam::aws:policy/IAMFullAccess
Policies:
- PolicyName: cloudformation-transforms
PolicyDocument:
Version: "2012-10-17"
Statement:
- Effect: Allow
Action:
- cloudformation:CreateChangeSet
Resource:
- arn:aws:cloudformation:us-east-1:aws:transform/*
# ---------------------------------------------------------------------------
# SAM deploy roles (5 repos)