AWSTemplateFormatVersion: "2010-09-09" Description: >- GitHub Actions OIDC deploy roles for Sea Haven Industries repos. Each repo gets a scoped IAM role that GitHub Actions assumes via OIDC. Parameters: GitHubOrg: Type: String Default: Sea-Haven-Industries CreateOIDCProvider: Type: String Default: "false" AllowedValues: ["true", "false"] Description: Set to true only if the GitHub OIDC provider does not already exist in this account Conditions: ShouldCreateOIDCProvider: !Equals [!Ref CreateOIDCProvider, "true"] Resources: # --------------------------------------------------------------------------- # OIDC Provider (conditional — already exists for seahaven-site) # --------------------------------------------------------------------------- GitHubOIDCProvider: Type: AWS::IAM::OIDCProvider Condition: ShouldCreateOIDCProvider Properties: Url: https://token.actions.githubusercontent.com ClientIdList: - sts.amazonaws.com ThumbprintList: - 6938fd4d98bab03faadb97b34396831e3780aea1 # --------------------------------------------------------------------------- # Lambda execution permissions boundary (INFRA-103) # # This managed policy is the CEILING for every Lambda execution role that the # five SAM stacks auto-generate via AWS::Serverless::Function. Applying it as # PermissionsBoundary on those roles means the effective permissions are the # intersection of the role's own policies and this boundary, so a misconfigured # SAM role can never exceed what is listed here. # # The boundary is intentionally a SUPERSET of the union of all runtime # permissions currently granted across the five stacks. Being slightly broad # is the correct trade-off at this stage — a boundary that is too tight will # break Lambda functions at runtime after deploy, which is worse than a slightly # loose boundary that is tightened in a follow-up. # # Permission sources per stack: # # afterhours-shift-manager # - DynamoDB CRUD (afterhours-shifts table) # - secretsmanager:GetSecretValue (afterhours-shift-manager/*) # - ses:SendEmail (SES identity) # - CloudWatch Logs (all functions) # # payments-dashboard # - DynamoDB CRUD / Read (PaymentsDashboard table) # - S3 GetObject (payroll-emails, payments-csv buckets) # - secretsmanager:GetSecretValue (payments-dashboard/*) # - sqs:SendMessage + sqs:ReceiveMessage + sqs:DeleteMessage etc. # (PayrollBatchQueue + DLQs) # - lambda:InvokeFunction (ExpenseReceiver → ExpenseProcessor) # - ec2:CreateNetworkInterface / DescribeNetworkInterfaces / # DeleteNetworkInterface (VPC-attached functions) # - CloudWatch Logs # # meal-order-manager # - DynamoDB CRUD / Read (meal-order-manager-orders table) # - S3 CRUD (ReportsBucket) + s3:GetObject (ReportsBucket presigned URLs) # - secretsmanager:GetSecretValue (meal-order-manager/*) # - ssm:GetParameter (/meal-order-manager/*) # - lambda:InvokeFunction (submit-order → slack-notifier, # close-form → aggregate-orders) # - ses:SendRawEmail # - CloudWatch Logs # # front-integrations # - DynamoDB CRUD (front-sla-alerts table) # - secretsmanager:GetSecretValue (by ARN, various) # - CloudWatch Logs # # afi-backup-monitor # - secretsmanager:GetSecretValue (by ARN) # - CloudWatch Logs # # --------------------------------------------------------------------------- LambdaExecutionBoundary: Type: AWS::IAM::ManagedPolicy Properties: ManagedPolicyName: seahaven-lambda-execution-boundary Description: >- Permissions boundary ceiling for all SAM-managed Lambda execution roles. Applied via PermissionsBoundary on every Globals.Function in the five SAM stacks (INFRA-103). Effective permissions are the intersection of this policy and the role's own inline policies. PolicyDocument: Version: "2012-10-17" Statement: # ── CloudWatch Logs (every Lambda) ────────────────────────────────── - Sid: CloudWatchLogs Effect: Allow Action: - logs:CreateLogGroup - logs:CreateLogStream - logs:PutLogEvents - logs:DescribeLogGroups - logs:DescribeLogStreams Resource: "*" # ── X-Ray tracing (standard Lambda execution) ──────────────────── - Sid: XRay Effect: Allow Action: - xray:PutTraceSegments - xray:PutTelemetryRecords Resource: "*" # ── VPC / ENI management (payments-dashboard VPC functions) ──────── # Matches AWSLambdaVPCAccessExecutionRole exactly. # AssignPrivateIpAddresses / UnassignPrivateIpAddresses are for EFA # and secondary IPs — not part of the Lambda ENI lifecycle — omitted. - Sid: Ec2Eni Effect: Allow Action: - ec2:CreateNetworkInterface - ec2:DescribeNetworkInterfaces - ec2:DeleteNetworkInterface - ec2:DescribeSubnets - ec2:DescribeSecurityGroups - ec2:DescribeVpcs Resource: "*" # ── DynamoDB (afterhours, payments, meal-order, front-integrations) ─ # Table/* covers base-table operations; table/*/index/* is required for # Query/Scan on Global Secondary Indexes. - Sid: DynamoDB Effect: Allow Action: - dynamodb:GetItem - dynamodb:PutItem - dynamodb:UpdateItem - dynamodb:DeleteItem - dynamodb:Query - dynamodb:Scan - dynamodb:BatchGetItem - dynamodb:BatchWriteItem - dynamodb:DescribeTable - dynamodb:ConditionCheckItem Resource: - !Sub "arn:aws:dynamodb:us-east-1:${AWS::AccountId}:table/*" - !Sub "arn:aws:dynamodb:us-east-1:${AWS::AccountId}:table/*/index/*" # ── S3 (payments-dashboard read, meal-order-manager CRUD) ────────── - Sid: S3 Effect: Allow Action: - s3:GetObject - s3:PutObject - s3:DeleteObject - s3:ListBucket - s3:GetBucketLocation - s3:GetObjectVersion - s3:GetObjectTagging - s3:PutObjectTagging Resource: - !Sub "arn:aws:s3:::*-${AWS::AccountId}" - !Sub "arn:aws:s3:::*-${AWS::AccountId}/*" # meal-order-manager ReportsBucket (non-AccountId suffix pattern) - !Sub "arn:aws:s3:::meal-order-manager-reports-${AWS::AccountId}" - !Sub "arn:aws:s3:::meal-order-manager-reports-${AWS::AccountId}/*" - !Sub "arn:aws:s3:::meal-order-manager-form-${AWS::AccountId}" - !Sub "arn:aws:s3:::meal-order-manager-form-${AWS::AccountId}/*" # ── Secrets Manager (all stacks) ────────────────────────────────── - Sid: SecretsManager Effect: Allow Action: - secretsmanager:GetSecretValue - secretsmanager:DescribeSecret Resource: - !Sub "arn:aws:secretsmanager:us-east-1:${AWS::AccountId}:secret:*" # ── SSM Parameter Store (meal-order-manager, afterhours) ────────── - Sid: SSMParameterRead Effect: Allow Action: - ssm:GetParameter - ssm:GetParameters - ssm:GetParametersByPath Resource: - !Sub "arn:aws:ssm:us-east-1:${AWS::AccountId}:parameter/*" # ── SQS (payments-dashboard batch queues) ───────────────────────── - Sid: SQS Effect: Allow Action: - sqs:SendMessage - sqs:ReceiveMessage - sqs:DeleteMessage - sqs:GetQueueAttributes - sqs:GetQueueUrl - sqs:ChangeMessageVisibility Resource: - !Sub "arn:aws:sqs:us-east-1:${AWS::AccountId}:*" # ── Lambda invocation (payments, meal-order inter-function calls) ── - Sid: LambdaInvoke Effect: Allow Action: - lambda:InvokeFunction Resource: - !Sub "arn:aws:lambda:us-east-1:${AWS::AccountId}:function:*" # ── SES (afterhours weekly-post, meal-order email-report) ────────── - Sid: SES Effect: Allow Action: - ses:SendEmail - ses:SendRawEmail Resource: - !Sub "arn:aws:ses:us-east-1:${AWS::AccountId}:identity/*" - !Sub "arn:aws:ses:us-east-1:${AWS::AccountId}:configuration-set/*" # ── KMS (CMK-encrypted resources) ───────────────────────────────── # Required for Lambda functions that read/write CMK-encrypted AWS # resources. Verified live state: # - PaymentsDashboard DynamoDB table: CMK key/0b660af3 (KMS:ENABLED) # - payments-dashboard CloudWatch log groups: CMK key/b748750c # Secrets Manager + SQS queues in these stacks use AWS-managed keys # (aws/secretsmanager, aws/sqs) which do not require explicit kms:* # actions in the execution role policy. The CMK keys are scoped to # this account to prevent cross-account KMS calls. - Sid: KMS Effect: Allow Action: - kms:Decrypt - kms:GenerateDataKey - kms:DescribeKey Resource: - !Sub "arn:aws:kms:us-east-1:${AWS::AccountId}:key/*" # --------------------------------------------------------------------------- # Shared CloudFormation execution role (SAM stacks) # --------------------------------------------------------------------------- SamCfnExecutionRole: Type: AWS::IAM::Role Properties: RoleName: github-cfn-execution-role AssumeRolePolicyDocument: Version: "2012-10-17" Statement: - Effect: Allow Principal: Service: cloudformation.amazonaws.com Action: sts:AssumeRole ManagedPolicyArns: - arn:aws:iam::aws:policy/AWSLambda_FullAccess - arn:aws:iam::aws:policy/AmazonAPIGatewayAdministrator - arn:aws:iam::aws:policy/AmazonDynamoDBFullAccess - arn:aws:iam::aws:policy/AmazonS3FullAccess - arn:aws:iam::aws:policy/CloudWatchLogsFullAccess - arn:aws:iam::aws:policy/AmazonEventBridgeFullAccess - arn:aws:iam::aws:policy/AmazonSESFullAccess - arn:aws:iam::aws:policy/IAMFullAccess Policies: - PolicyName: additional-service-permissions PolicyDocument: Version: "2012-10-17" Statement: - Effect: Allow Action: - cloudformation:CreateChangeSet Resource: - arn:aws:cloudformation:us-east-1:aws:transform/* - Effect: Allow Action: - sqs:* - sns:* - ec2:* # cloudfront:* and ssm:* reconciled from out-of-band drift # (audit H-16) — needed by SAM deploys that manage CloudFront # distributions (meal-order-manager) and SSM parameters # (afterhours / payments / meal-order). Codified 2026-05-29. - cloudfront:* - ssm:* Resource: "*" # WAF (audit M-17) — needed for SAM/CFN-managed WebACL associations # on CloudFront distributions (meal-order-manager orders). Read + # (dis)associate only, not wafv2:*. Added 2026-06-02. - Effect: Allow Action: - wafv2:GetWebACL - wafv2:GetWebACLForResource - wafv2:ListWebACLs - wafv2:AssociateWebACL - wafv2:DisassociateWebACL - wafv2:ListResourcesForWebACL Resource: "*" # --------------------------------------------------------------------------- # SAM deploy roles (4 repos) # --------------------------------------------------------------------------- AfterhoursShiftManagerDeployRole: Type: AWS::IAM::Role Properties: RoleName: githubdeploy-afterhours-shift-manager AssumeRolePolicyDocument: Version: "2012-10-17" Statement: - Effect: Allow Principal: Federated: !Sub arn:aws:iam::${AWS::AccountId}:oidc-provider/token.actions.githubusercontent.com Action: sts:AssumeRoleWithWebIdentity Condition: StringEquals: token.actions.githubusercontent.com:aud: sts.amazonaws.com StringLike: token.actions.githubusercontent.com:sub: !Sub repo:${GitHubOrg}/afterhours-shift-manager:ref:refs/heads/main Policies: - PolicyName: sam-deploy PolicyDocument: Version: "2012-10-17" Statement: - Effect: Allow Action: - cloudformation:CreateChangeSet - cloudformation:DeleteChangeSet - cloudformation:DescribeChangeSet - cloudformation:DescribeStackEvents - cloudformation:DescribeStacks - cloudformation:ExecuteChangeSet - cloudformation:GetTemplate - cloudformation:ListStackResources - cloudformation:UpdateStack - cloudformation:CreateStack - cloudformation:TagResource Resource: - !Sub arn:aws:cloudformation:us-east-1:${AWS::AccountId}:stack/afterhours-shift-manager/* - Effect: Allow Action: - cloudformation:GetTemplateSummary Resource: "*" - Effect: Allow Action: - cloudformation:DescribeStacks - cloudformation:CreateChangeSet - cloudformation:DescribeChangeSet - cloudformation:ExecuteChangeSet - cloudformation:CreateStack Resource: - !Sub arn:aws:cloudformation:us-east-1:${AWS::AccountId}:stack/aws-sam-cli-managed-default/* - Effect: Allow Action: - s3:PutObject - s3:GetObject - s3:ListBucket - s3:GetBucketLocation - s3:CreateBucket - s3:PutBucketPolicy - s3:GetBucketPolicy - s3:PutLifecycleConfiguration - s3:PutBucketVersioning - s3:DeleteObject Resource: - arn:aws:s3:::aws-sam-cli-managed-default-samclisourcebucket-* - arn:aws:s3:::aws-sam-cli-managed-default-samclisourcebucket-*/* - Effect: Allow Action: - iam:PassRole Resource: - !GetAtt SamCfnExecutionRole.Arn FrontIntegrationsDeployRole: Type: AWS::IAM::Role Properties: RoleName: githubdeploy-front-integrations AssumeRolePolicyDocument: Version: "2012-10-17" Statement: - Effect: Allow Principal: Federated: !Sub arn:aws:iam::${AWS::AccountId}:oidc-provider/token.actions.githubusercontent.com Action: sts:AssumeRoleWithWebIdentity Condition: StringEquals: token.actions.githubusercontent.com:aud: sts.amazonaws.com StringLike: token.actions.githubusercontent.com:sub: !Sub repo:${GitHubOrg}/front-integrations:ref:refs/heads/main Policies: - PolicyName: sam-deploy PolicyDocument: Version: "2012-10-17" Statement: - Effect: Allow Action: - cloudformation:CreateChangeSet - cloudformation:DeleteChangeSet - cloudformation:DescribeChangeSet - cloudformation:DescribeStackEvents - cloudformation:DescribeStacks - cloudformation:ExecuteChangeSet - cloudformation:GetTemplate - cloudformation:ListStackResources - cloudformation:UpdateStack - cloudformation:CreateStack - cloudformation:TagResource Resource: - !Sub arn:aws:cloudformation:us-east-1:${AWS::AccountId}:stack/front-integrations/* - Effect: Allow Action: - cloudformation:GetTemplateSummary Resource: "*" - Effect: Allow Action: - cloudformation:DescribeStacks - cloudformation:CreateChangeSet - cloudformation:DescribeChangeSet - cloudformation:ExecuteChangeSet - cloudformation:CreateStack Resource: - !Sub arn:aws:cloudformation:us-east-1:${AWS::AccountId}:stack/aws-sam-cli-managed-default/* - Effect: Allow Action: - s3:PutObject - s3:GetObject - s3:ListBucket - s3:GetBucketLocation - s3:CreateBucket - s3:PutBucketPolicy - s3:GetBucketPolicy - s3:PutLifecycleConfiguration - s3:PutBucketVersioning - s3:DeleteObject Resource: - arn:aws:s3:::aws-sam-cli-managed-default-samclisourcebucket-* - arn:aws:s3:::aws-sam-cli-managed-default-samclisourcebucket-*/* - Effect: Allow Action: - iam:PassRole Resource: - !GetAtt SamCfnExecutionRole.Arn AfiBackupMonitorDeployRole: Type: AWS::IAM::Role Properties: RoleName: githubdeploy-afi-backup-monitor AssumeRolePolicyDocument: Version: "2012-10-17" Statement: - Effect: Allow Principal: Federated: !Sub arn:aws:iam::${AWS::AccountId}:oidc-provider/token.actions.githubusercontent.com Action: sts:AssumeRoleWithWebIdentity Condition: StringEquals: token.actions.githubusercontent.com:aud: sts.amazonaws.com StringLike: token.actions.githubusercontent.com:sub: !Sub repo:${GitHubOrg}/afi-backup-monitor:ref:refs/heads/main Policies: - PolicyName: sam-deploy PolicyDocument: Version: "2012-10-17" Statement: - Effect: Allow Action: - cloudformation:CreateChangeSet - cloudformation:DeleteChangeSet - cloudformation:DescribeChangeSet - cloudformation:DescribeStackEvents - cloudformation:DescribeStacks - cloudformation:ExecuteChangeSet - cloudformation:GetTemplate - cloudformation:ListStackResources - cloudformation:UpdateStack - cloudformation:CreateStack - cloudformation:TagResource Resource: - !Sub arn:aws:cloudformation:us-east-1:${AWS::AccountId}:stack/afi-backup-monitor/* - Effect: Allow Action: - cloudformation:GetTemplateSummary Resource: "*" - Effect: Allow Action: - cloudformation:DescribeStacks - cloudformation:CreateChangeSet - cloudformation:DescribeChangeSet - cloudformation:ExecuteChangeSet - cloudformation:CreateStack Resource: - !Sub arn:aws:cloudformation:us-east-1:${AWS::AccountId}:stack/aws-sam-cli-managed-default/* - Effect: Allow Action: - s3:PutObject - s3:GetObject - s3:ListBucket - s3:GetBucketLocation - s3:CreateBucket - s3:PutBucketPolicy - s3:GetBucketPolicy - s3:PutLifecycleConfiguration - s3:PutBucketVersioning - s3:DeleteObject Resource: - arn:aws:s3:::aws-sam-cli-managed-default-samclisourcebucket-* - arn:aws:s3:::aws-sam-cli-managed-default-samclisourcebucket-*/* - Effect: Allow Action: - iam:PassRole Resource: - !GetAtt SamCfnExecutionRole.Arn PaymentsDashboardDeployRole: Type: AWS::IAM::Role Properties: RoleName: githubdeploy-payments-dashboard AssumeRolePolicyDocument: Version: "2012-10-17" Statement: - Effect: Allow Principal: Federated: !Sub arn:aws:iam::${AWS::AccountId}:oidc-provider/token.actions.githubusercontent.com Action: sts:AssumeRoleWithWebIdentity Condition: StringEquals: token.actions.githubusercontent.com:aud: sts.amazonaws.com StringLike: token.actions.githubusercontent.com:sub: !Sub repo:${GitHubOrg}/payments-dashboard:ref:refs/heads/main Policies: - PolicyName: sam-deploy PolicyDocument: Version: "2012-10-17" Statement: - Effect: Allow Action: - cloudformation:CreateChangeSet - cloudformation:DeleteChangeSet - cloudformation:DescribeChangeSet - cloudformation:DescribeStackEvents - cloudformation:DescribeStacks - cloudformation:ExecuteChangeSet - cloudformation:GetTemplate - cloudformation:ListStackResources - cloudformation:UpdateStack - cloudformation:CreateStack - cloudformation:TagResource Resource: - !Sub arn:aws:cloudformation:us-east-1:${AWS::AccountId}:stack/payments-dashboard/* - Effect: Allow Action: - cloudformation:GetTemplateSummary Resource: "*" - Effect: Allow Action: - cloudformation:DescribeStacks - cloudformation:CreateChangeSet - cloudformation:DescribeChangeSet - cloudformation:ExecuteChangeSet - cloudformation:CreateStack Resource: - !Sub arn:aws:cloudformation:us-east-1:${AWS::AccountId}:stack/aws-sam-cli-managed-default/* - Effect: Allow Action: - s3:PutObject - s3:GetObject - s3:ListBucket - s3:GetBucketLocation - s3:CreateBucket - s3:PutBucketPolicy - s3:GetBucketPolicy - s3:PutLifecycleConfiguration - s3:PutBucketVersioning - s3:DeleteObject Resource: - arn:aws:s3:::aws-sam-cli-managed-default-samclisourcebucket-* - arn:aws:s3:::aws-sam-cli-managed-default-samclisourcebucket-*/* - Effect: Allow Action: - iam:PassRole Resource: - !GetAtt SamCfnExecutionRole.Arn # --------------------------------------------------------------------------- # CDK deploy roles (4 repos) # --------------------------------------------------------------------------- SeahavenSlackBotDeployRole: Type: AWS::IAM::Role Properties: RoleName: githubdeploy-seahaven-slack-bot AssumeRolePolicyDocument: Version: "2012-10-17" Statement: - Effect: Allow Principal: Federated: !Sub arn:aws:iam::${AWS::AccountId}:oidc-provider/token.actions.githubusercontent.com Action: sts:AssumeRoleWithWebIdentity Condition: StringEquals: token.actions.githubusercontent.com:aud: sts.amazonaws.com StringLike: token.actions.githubusercontent.com:sub: !Sub repo:${GitHubOrg}/seahaven-slack-bot:ref:refs/heads/main Policies: - PolicyName: cdk-deploy PolicyDocument: Version: "2012-10-17" Statement: - Effect: Allow Action: - sts:AssumeRole Resource: - !Sub arn:aws:iam::${AWS::AccountId}:role/cdk-hnb659fds-* ExecAideDeployRole: Type: AWS::IAM::Role Properties: RoleName: githubdeploy-exec-aide AssumeRolePolicyDocument: Version: "2012-10-17" Statement: - Effect: Allow Principal: Federated: !Sub arn:aws:iam::${AWS::AccountId}:oidc-provider/token.actions.githubusercontent.com Action: sts:AssumeRoleWithWebIdentity Condition: StringEquals: token.actions.githubusercontent.com:aud: sts.amazonaws.com StringLike: token.actions.githubusercontent.com:sub: !Sub repo:${GitHubOrg}/exec-aide:ref:refs/heads/main Policies: - PolicyName: cdk-deploy PolicyDocument: Version: "2012-10-17" Statement: - Effect: Allow Action: - sts:AssumeRole Resource: - !Sub arn:aws:iam::${AWS::AccountId}:role/cdk-hnb659fds-* SeahavenDoorUnlockApiDeployRole: Type: AWS::IAM::Role Properties: RoleName: githubdeploy-seahaven-door-unlock-api AssumeRolePolicyDocument: Version: "2012-10-17" Statement: - Effect: Allow Principal: Federated: !Sub arn:aws:iam::${AWS::AccountId}:oidc-provider/token.actions.githubusercontent.com Action: sts:AssumeRoleWithWebIdentity Condition: StringEquals: token.actions.githubusercontent.com:aud: sts.amazonaws.com StringLike: token.actions.githubusercontent.com:sub: !Sub repo:${GitHubOrg}/seahaven-door-unlock-api:ref:refs/heads/main Policies: - PolicyName: cdk-deploy PolicyDocument: Version: "2012-10-17" Statement: - Effect: Allow Action: - sts:AssumeRole Resource: - !Sub arn:aws:iam::${AWS::AccountId}:role/cdk-hnb659fds-* ProcurementIngestDeployRole: Type: AWS::IAM::Role Properties: RoleName: githubdeploy-procurement-ingest AssumeRolePolicyDocument: Version: "2012-10-17" Statement: - Effect: Allow Principal: Federated: !Sub arn:aws:iam::${AWS::AccountId}:oidc-provider/token.actions.githubusercontent.com Action: sts:AssumeRoleWithWebIdentity Condition: StringEquals: token.actions.githubusercontent.com:aud: sts.amazonaws.com StringLike: token.actions.githubusercontent.com:sub: !Sub repo:${GitHubOrg}/procurement-ingest:ref:refs/heads/main Policies: - PolicyName: cdk-deploy PolicyDocument: Version: "2012-10-17" Statement: - Effect: Allow Action: - sts:AssumeRole Resource: - !Sub arn:aws:iam::${AWS::AccountId}:role/cdk-hnb659fds-* ApmWoAnalysisDeployRole: Type: AWS::IAM::Role Properties: RoleName: githubdeploy-apm-wo-analysis AssumeRolePolicyDocument: Version: "2012-10-17" Statement: - Effect: Allow Principal: Federated: !Sub arn:aws:iam::${AWS::AccountId}:oidc-provider/token.actions.githubusercontent.com Action: sts:AssumeRoleWithWebIdentity Condition: StringEquals: token.actions.githubusercontent.com:aud: sts.amazonaws.com StringLike: token.actions.githubusercontent.com:sub: !Sub repo:${GitHubOrg}/apm-wo-analysis:ref:refs/heads/main Policies: - PolicyName: cdk-deploy PolicyDocument: Version: "2012-10-17" Statement: - Effect: Allow Action: - sts:AssumeRole Resource: - !Sub arn:aws:iam::${AWS::AccountId}:role/cdk-hnb659fds-* SeahavenAccountBaselineDeployRole: Type: AWS::IAM::Role Properties: RoleName: githubdeploy-seahaven-account-baseline AssumeRolePolicyDocument: Version: "2012-10-17" Statement: - Effect: Allow Principal: Federated: !Sub arn:aws:iam::${AWS::AccountId}:oidc-provider/token.actions.githubusercontent.com Action: sts:AssumeRoleWithWebIdentity Condition: StringEquals: token.actions.githubusercontent.com:aud: sts.amazonaws.com StringLike: token.actions.githubusercontent.com:sub: !Sub repo:${GitHubOrg}/seahaven-account-baseline:ref:refs/heads/main Policies: - PolicyName: cdk-deploy PolicyDocument: Version: "2012-10-17" Statement: - Effect: Allow Action: - sts:AssumeRole Resource: - !Sub arn:aws:iam::${AWS::AccountId}:role/cdk-hnb659fds-* Outputs: LambdaExecutionBoundaryArn: Value: !Ref LambdaExecutionBoundary Description: >- ARN of the Lambda execution permissions boundary. Set this as PermissionsBoundary on Globals.Function in all five SAM stacks. Export: Name: seahaven-lambda-execution-boundary-arn SamCfnExecutionRoleArn: Value: !GetAtt SamCfnExecutionRole.Arn Export: Name: github-cfn-execution-role-arn AfterhoursShiftManagerDeployRoleArn: Value: !GetAtt AfterhoursShiftManagerDeployRole.Arn FrontIntegrationsDeployRoleArn: Value: !GetAtt FrontIntegrationsDeployRole.Arn AfiBackupMonitorDeployRoleArn: Value: !GetAtt AfiBackupMonitorDeployRole.Arn PaymentsDashboardDeployRoleArn: Value: !GetAtt PaymentsDashboardDeployRole.Arn SeahavenSlackBotDeployRoleArn: Value: !GetAtt SeahavenSlackBotDeployRole.Arn ExecAideDeployRoleArn: Value: !GetAtt ExecAideDeployRole.Arn SeahavenDoorUnlockApiDeployRoleArn: Value: !GetAtt SeahavenDoorUnlockApiDeployRole.Arn ProcurementIngestDeployRoleArn: Value: !GetAtt ProcurementIngestDeployRole.Arn ApmWoAnalysisDeployRoleArn: Value: !GetAtt ApmWoAnalysisDeployRole.Arn SeahavenAccountBaselineDeployRoleArn: Value: !GetAtt SeahavenAccountBaselineDeployRole.Arn