Compare commits

...

2 commits

Author SHA1 Message Date
Cursor Agent
6a811c0f0b
merge main into the soaked-role removal so the policy-check role stays
Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com>
2026-09-28 16:47:08 +00:00
Adam Moussa
8e6b8e8665
feat(iam): add org-baseline Access Analyzer CI role (PLAT-234) (#153)
Some checks are pending
ci / ci / ci (push) Waiting to run
* feat(iam): add org-baseline Access Analyzer CI role (PLAT-234)

Adds githubdeploy-seahaven-org-baseline-policy-check with only
ValidatePolicy and CheckNoNewAccess, trusted for main and pull_request.
The deploy role stays limited to main and CDK assume.

Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com>

* docs(iam): point the policy-check role at its CI job (PLAT-234)

The Access Analyzer checks live in seahaven-org-baseline pull request 160.
This role is only the principal that job assumes.

Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com>

* fix(iam): match the default pull request OIDC subject (PLAT-234)

Trust refs/pull/* so seahaven-org-baseline pull request tokens can assume
the policy-check role. The immutable subject claim is not enabled.

Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com>

---------

Co-authored-by: Cursor Agent <cursoragent@cursor.com>
Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com>
2026-09-28 16:23:57 +00:00

View file

@ -1162,6 +1162,46 @@ Resources:
# Mgmt role github-meal-order-manager-weekly-menu deleted with this stack update.
# PLAT-234 principal only. The checks are seahaven-org-baseline pull request
# 160: .github/workflows/ci.yaml job iam-policy-check and
# scripts/check_iam_policies.py. That job assumes this role. It asserts
# StringEquals on the bootstrap trust templates, no lambda write on the
# plan template, then ValidatePolicy and CheckNoNewAccess when this role
# can be assumed.
SeahavenOrgBaselinePolicyCheckRole:
Type: AWS::IAM::Role
Properties:
RoleName: githubdeploy-seahaven-org-baseline-policy-check
Description: Access Analyzer policy checks for seahaven-org-baseline CI. No deploy permissions.
AssumeRolePolicyDocument:
Version: "2012-10-17"
Statement:
- Effect: Allow
Principal:
Federated: !Sub arn:aws:iam::${AWS::AccountId}:oidc-provider/token.actions.githubusercontent.com
Action: sts:AssumeRoleWithWebIdentity
Condition:
StringEquals:
token.actions.githubusercontent.com:aud: sts.amazonaws.com
StringLike:
token.actions.githubusercontent.com:sub:
- !Sub repo:${GitHubOrg}/seahaven-org-baseline:ref:refs/heads/main
# use_immutable_subject is false, so pull_request tokens use
# repo:ORG/seahaven-org-baseline:ref:refs/pull/N/merge.
- !Sub repo:${GitHubOrg}/seahaven-org-baseline:ref:refs/pull/*
Policies:
- PolicyName: access-analyzer-policy-check
PolicyDocument:
Version: "2012-10-17"
Statement:
- Sid: AccessAnalyzerPolicyCheck
Effect: Allow
Action:
- access-analyzer:ValidatePolicy
- access-analyzer:CheckNoNewAccess
Resource: "*"
Outputs:
LambdaExecutionBoundaryArn:
Value: !Ref LambdaExecutionBoundary
@ -1190,4 +1230,6 @@ Outputs:
# deleted only when this stack is deployed. That deploy is not this change.
SeahavenAccountBaselineDeployRoleArn:
Value: !GetAtt SeahavenAccountBaselineDeployRole.Arn
SeahavenOrgBaselinePolicyCheckRoleArn:
Value: !GetAtt SeahavenOrgBaselinePolicyCheckRole.Arn
# MealOrderManagerWeeklyMenuRoleArn removed 2026-08-20 (PLAT-70): role deleted with resource.