mirror of
https://github.com/Sea-Haven-Industries/.github.git
synced 2026-10-03 19:03:16 +00:00
Compare commits
2 commits
c040bfaa22
...
6db9f44a47
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
6db9f44a47 | ||
|
|
333a9613b5 |
2 changed files with 37 additions and 0 deletions
8
.github/workflows/ci-python-sam.yaml
vendored
8
.github/workflows/ci-python-sam.yaml
vendored
|
|
@ -35,6 +35,10 @@ on:
|
|||
description: "Node.js version for CDK CLI"
|
||||
type: string
|
||||
default: "24"
|
||||
enable-qemu:
|
||||
description: "Enable QEMU so cdk synth can bundle arm64 Lambda assets on x86 runners"
|
||||
type: boolean
|
||||
default: false
|
||||
run-conventions-check:
|
||||
description: "Run lightweight conventions audit"
|
||||
type: boolean
|
||||
|
|
@ -80,6 +84,10 @@ jobs:
|
|||
with:
|
||||
node-version: ${{ inputs.node-version }}
|
||||
|
||||
- name: Set up QEMU
|
||||
if: ${{ inputs.run-cdk-synth && inputs.enable-qemu }}
|
||||
uses: docker/setup-qemu-action@v3
|
||||
|
||||
- name: CDK synth
|
||||
if: ${{ inputs.run-cdk-synth }}
|
||||
working-directory: ${{ inputs.cdk-dir }}
|
||||
|
|
|
|||
|
|
@ -467,6 +467,33 @@ Resources:
|
|||
Resource:
|
||||
- !Sub arn:aws:iam::${AWS::AccountId}:role/cdk-hnb659fds-*
|
||||
|
||||
ApmWoAnalysisDeployRole:
|
||||
Type: AWS::IAM::Role
|
||||
Properties:
|
||||
RoleName: githubdeploy-apm-wo-analysis
|
||||
AssumeRolePolicyDocument:
|
||||
Version: "2012-10-17"
|
||||
Statement:
|
||||
- Effect: Allow
|
||||
Principal:
|
||||
Federated: !Sub arn:aws:iam::${AWS::AccountId}:oidc-provider/token.actions.githubusercontent.com
|
||||
Action: sts:AssumeRoleWithWebIdentity
|
||||
Condition:
|
||||
StringEquals:
|
||||
token.actions.githubusercontent.com:aud: sts.amazonaws.com
|
||||
StringLike:
|
||||
token.actions.githubusercontent.com:sub: !Sub repo:${GitHubOrg}/apm-wo-analysis:ref:refs/heads/main
|
||||
Policies:
|
||||
- PolicyName: cdk-deploy
|
||||
PolicyDocument:
|
||||
Version: "2012-10-17"
|
||||
Statement:
|
||||
- Effect: Allow
|
||||
Action:
|
||||
- sts:AssumeRole
|
||||
Resource:
|
||||
- !Sub arn:aws:iam::${AWS::AccountId}:role/cdk-hnb659fds-*
|
||||
|
||||
Outputs:
|
||||
SamCfnExecutionRoleArn:
|
||||
Value: !GetAtt SamCfnExecutionRole.Arn
|
||||
|
|
@ -488,3 +515,5 @@ Outputs:
|
|||
Value: !GetAtt SeahavenDoorUnlockApiDeployRole.Arn
|
||||
ProcurementIngestDeployRoleArn:
|
||||
Value: !GetAtt ProcurementIngestDeployRole.Arn
|
||||
ApmWoAnalysisDeployRoleArn:
|
||||
Value: !GetAtt ApmWoAnalysisDeployRole.Arn
|
||||
|
|
|
|||
Loading…
Add table
Reference in a new issue