Compare commits

...

2 commits

Author SHA1 Message Date
Cursor Agent
e497c5f347
fix(iam): match the default pull request OIDC subject (PLAT-234)
Trust refs/pull/* so seahaven-org-baseline pull request tokens can assume
the policy-check role. The immutable subject claim is not enabled.

Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com>
2026-09-28 16:17:41 +00:00
Cursor Agent
7733c6c6d1
docs(iam): point the policy-check role at its CI job (PLAT-234)
The Access Analyzer checks live in seahaven-org-baseline pull request 160.
This role is only the principal that job assumes.

Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com>
2026-09-28 16:14:56 +00:00

View file

@ -1381,6 +1381,12 @@ Resources:
# PLAT-234 principal only. The checks are seahaven-org-baseline pull request
# 160: .github/workflows/ci.yaml job iam-policy-check and
# scripts/check_iam_policies.py. That job assumes this role. It asserts
# StringEquals on the bootstrap trust templates, no lambda write on the
# plan template, then ValidatePolicy and CheckNoNewAccess when this role
# can be assumed.
SeahavenOrgBaselinePolicyCheckRole:
Type: AWS::IAM::Role
Properties:
@ -1399,7 +1405,9 @@ Resources:
StringLike:
token.actions.githubusercontent.com:sub:
- !Sub repo:${GitHubOrg}/seahaven-org-baseline:ref:refs/heads/main
- !Sub repo:${GitHubOrg}/seahaven-org-baseline:pull_request
# use_immutable_subject is false, so pull_request tokens use
# repo:ORG/seahaven-org-baseline:ref:refs/pull/N/merge.
- !Sub repo:${GitHubOrg}/seahaven-org-baseline:ref:refs/pull/*
Policies:
- PolicyName: access-analyzer-policy-check
PolicyDocument: