AWSTemplateFormatVersion: "2010-09-09" Description: >- GitHub Actions OIDC deploy roles for Sea Haven Industries repos. Each repo gets a scoped IAM role that GitHub Actions assumes via OIDC. Parameters: GitHubOrg: Type: String Default: Sea-Haven-Industries CreateOIDCProvider: Type: String Default: "false" AllowedValues: ["true", "false"] Description: Set to true only if the GitHub OIDC provider does not already exist in this account Conditions: ShouldCreateOIDCProvider: !Equals [!Ref CreateOIDCProvider, "true"] Resources: # --------------------------------------------------------------------------- # OIDC Provider (conditional — already exists for seahaven-site) # --------------------------------------------------------------------------- GitHubOIDCProvider: Type: AWS::IAM::OIDCProvider Condition: ShouldCreateOIDCProvider Properties: Url: https://token.actions.githubusercontent.com ClientIdList: - sts.amazonaws.com ThumbprintList: - 6938fd4d98bab03faadb97b34396831e3780aea1 # --------------------------------------------------------------------------- # Shared CloudFormation execution role (SAM stacks) # --------------------------------------------------------------------------- SamCfnExecutionRole: Type: AWS::IAM::Role Properties: RoleName: github-cfn-execution-role AssumeRolePolicyDocument: Version: "2012-10-17" Statement: - Effect: Allow Principal: Service: cloudformation.amazonaws.com Action: sts:AssumeRole ManagedPolicyArns: - arn:aws:iam::aws:policy/AWSLambda_FullAccess - arn:aws:iam::aws:policy/AmazonAPIGatewayAdministrator - arn:aws:iam::aws:policy/AmazonDynamoDBFullAccess - arn:aws:iam::aws:policy/AmazonS3FullAccess - arn:aws:iam::aws:policy/CloudWatchLogsFullAccess - arn:aws:iam::aws:policy/AmazonEventBridgeFullAccess - arn:aws:iam::aws:policy/AmazonSESFullAccess - arn:aws:iam::aws:policy/IAMFullAccess Policies: - PolicyName: additional-service-permissions PolicyDocument: Version: "2012-10-17" Statement: - Effect: Allow Action: - cloudformation:CreateChangeSet Resource: - arn:aws:cloudformation:us-east-1:aws:transform/* - Effect: Allow Action: - sqs:* - sns:* - ec2:* Resource: "*" # --------------------------------------------------------------------------- # SAM deploy roles (5 repos) # --------------------------------------------------------------------------- AfterhoursShiftManagerDeployRole: Type: AWS::IAM::Role Properties: RoleName: githubdeploy-afterhours-shift-manager AssumeRolePolicyDocument: Version: "2012-10-17" Statement: - Effect: Allow Principal: Federated: !Sub arn:aws:iam::${AWS::AccountId}:oidc-provider/token.actions.githubusercontent.com Action: sts:AssumeRoleWithWebIdentity Condition: StringEquals: token.actions.githubusercontent.com:aud: sts.amazonaws.com StringLike: token.actions.githubusercontent.com:sub: !Sub repo:${GitHubOrg}/afterhours-shift-manager:ref:refs/heads/main Policies: - PolicyName: sam-deploy PolicyDocument: Version: "2012-10-17" Statement: - Effect: Allow Action: - cloudformation:CreateChangeSet - cloudformation:DeleteChangeSet - cloudformation:DescribeChangeSet - cloudformation:DescribeStackEvents - cloudformation:DescribeStacks - cloudformation:ExecuteChangeSet - cloudformation:GetTemplate - cloudformation:ListStackResources - cloudformation:UpdateStack - cloudformation:CreateStack - cloudformation:TagResource Resource: - !Sub arn:aws:cloudformation:us-east-1:${AWS::AccountId}:stack/afterhours-shift-manager/* - Effect: Allow Action: - cloudformation:GetTemplateSummary Resource: "*" - Effect: Allow Action: - cloudformation:DescribeStacks - cloudformation:CreateChangeSet - cloudformation:DescribeChangeSet - cloudformation:ExecuteChangeSet - cloudformation:CreateStack Resource: - !Sub arn:aws:cloudformation:us-east-1:${AWS::AccountId}:stack/aws-sam-cli-managed-default/* - Effect: Allow Action: - s3:PutObject - s3:GetObject - s3:ListBucket - s3:GetBucketLocation - s3:CreateBucket - s3:PutBucketPolicy - s3:GetBucketPolicy - s3:PutLifecycleConfiguration - s3:PutBucketVersioning - s3:DeleteObject Resource: - arn:aws:s3:::aws-sam-cli-managed-default-samclisourcebucket-* - arn:aws:s3:::aws-sam-cli-managed-default-samclisourcebucket-*/* - Effect: Allow Action: - iam:PassRole Resource: - !GetAtt SamCfnExecutionRole.Arn ExpenseApprovalBotDeployRole: Type: AWS::IAM::Role Properties: RoleName: githubdeploy-expense-approval-bot AssumeRolePolicyDocument: Version: "2012-10-17" Statement: - Effect: Allow Principal: Federated: !Sub arn:aws:iam::${AWS::AccountId}:oidc-provider/token.actions.githubusercontent.com Action: sts:AssumeRoleWithWebIdentity Condition: StringEquals: token.actions.githubusercontent.com:aud: sts.amazonaws.com StringLike: token.actions.githubusercontent.com:sub: !Sub repo:${GitHubOrg}/expense-approval-bot:ref:refs/heads/main Policies: - PolicyName: sam-deploy PolicyDocument: Version: "2012-10-17" Statement: - Effect: Allow Action: - cloudformation:CreateChangeSet - cloudformation:DeleteChangeSet - cloudformation:DescribeChangeSet - cloudformation:DescribeStackEvents - cloudformation:DescribeStacks - cloudformation:ExecuteChangeSet - cloudformation:GetTemplate - cloudformation:ListStackResources - cloudformation:UpdateStack - cloudformation:CreateStack - cloudformation:TagResource Resource: - !Sub arn:aws:cloudformation:us-east-1:${AWS::AccountId}:stack/expense-approval-bot/* - Effect: Allow Action: - cloudformation:GetTemplateSummary Resource: "*" - Effect: Allow Action: - cloudformation:DescribeStacks - cloudformation:CreateChangeSet - cloudformation:DescribeChangeSet - cloudformation:ExecuteChangeSet - cloudformation:CreateStack Resource: - !Sub arn:aws:cloudformation:us-east-1:${AWS::AccountId}:stack/aws-sam-cli-managed-default/* - Effect: Allow Action: - s3:PutObject - s3:GetObject - s3:ListBucket - s3:GetBucketLocation - s3:CreateBucket - s3:PutBucketPolicy - s3:GetBucketPolicy - s3:PutLifecycleConfiguration - s3:PutBucketVersioning - s3:DeleteObject Resource: - arn:aws:s3:::aws-sam-cli-managed-default-samclisourcebucket-* - arn:aws:s3:::aws-sam-cli-managed-default-samclisourcebucket-*/* - Effect: Allow Action: - iam:PassRole Resource: - !GetAtt SamCfnExecutionRole.Arn AfiBackupMonitorDeployRole: Type: AWS::IAM::Role Properties: RoleName: githubdeploy-afi-backup-monitor AssumeRolePolicyDocument: Version: "2012-10-17" Statement: - Effect: Allow Principal: Federated: !Sub arn:aws:iam::${AWS::AccountId}:oidc-provider/token.actions.githubusercontent.com Action: sts:AssumeRoleWithWebIdentity Condition: StringEquals: token.actions.githubusercontent.com:aud: sts.amazonaws.com StringLike: token.actions.githubusercontent.com:sub: !Sub repo:${GitHubOrg}/afi-backup-monitor:ref:refs/heads/main Policies: - PolicyName: sam-deploy PolicyDocument: Version: "2012-10-17" Statement: - Effect: Allow Action: - cloudformation:CreateChangeSet - cloudformation:DeleteChangeSet - cloudformation:DescribeChangeSet - cloudformation:DescribeStackEvents - cloudformation:DescribeStacks - cloudformation:ExecuteChangeSet - cloudformation:GetTemplate - cloudformation:ListStackResources - cloudformation:UpdateStack - cloudformation:CreateStack - cloudformation:TagResource Resource: - !Sub arn:aws:cloudformation:us-east-1:${AWS::AccountId}:stack/afi-backup-monitor/* - Effect: Allow Action: - cloudformation:GetTemplateSummary Resource: "*" - Effect: Allow Action: - cloudformation:DescribeStacks - cloudformation:CreateChangeSet - cloudformation:DescribeChangeSet - cloudformation:ExecuteChangeSet - cloudformation:CreateStack Resource: - !Sub arn:aws:cloudformation:us-east-1:${AWS::AccountId}:stack/aws-sam-cli-managed-default/* - Effect: Allow Action: - s3:PutObject - s3:GetObject - s3:ListBucket - s3:GetBucketLocation - s3:CreateBucket - s3:PutBucketPolicy - s3:GetBucketPolicy - s3:PutLifecycleConfiguration - s3:PutBucketVersioning - s3:DeleteObject Resource: - arn:aws:s3:::aws-sam-cli-managed-default-samclisourcebucket-* - arn:aws:s3:::aws-sam-cli-managed-default-samclisourcebucket-*/* - Effect: Allow Action: - iam:PassRole Resource: - !GetAtt SamCfnExecutionRole.Arn RingScheduler3cxDeployRole: Type: AWS::IAM::Role Properties: RoleName: githubdeploy-ring-scheduler-3cx AssumeRolePolicyDocument: Version: "2012-10-17" Statement: - Effect: Allow Principal: Federated: !Sub arn:aws:iam::${AWS::AccountId}:oidc-provider/token.actions.githubusercontent.com Action: sts:AssumeRoleWithWebIdentity Condition: StringEquals: token.actions.githubusercontent.com:aud: sts.amazonaws.com StringLike: token.actions.githubusercontent.com:sub: !Sub repo:${GitHubOrg}/ring-scheduler-3cx:ref:refs/heads/main Policies: - PolicyName: sam-deploy PolicyDocument: Version: "2012-10-17" Statement: - Effect: Allow Action: - cloudformation:CreateChangeSet - cloudformation:DeleteChangeSet - cloudformation:DescribeChangeSet - cloudformation:DescribeStackEvents - cloudformation:DescribeStacks - cloudformation:ExecuteChangeSet - cloudformation:GetTemplate - cloudformation:ListStackResources - cloudformation:UpdateStack - cloudformation:CreateStack - cloudformation:TagResource Resource: - !Sub arn:aws:cloudformation:us-east-1:${AWS::AccountId}:stack/ring-scheduler-3cx/* - Effect: Allow Action: - cloudformation:GetTemplateSummary Resource: "*" - Effect: Allow Action: - cloudformation:DescribeStacks - cloudformation:CreateChangeSet - cloudformation:DescribeChangeSet - cloudformation:ExecuteChangeSet - cloudformation:CreateStack Resource: - !Sub arn:aws:cloudformation:us-east-1:${AWS::AccountId}:stack/aws-sam-cli-managed-default/* - Effect: Allow Action: - s3:PutObject - s3:GetObject - s3:ListBucket - s3:GetBucketLocation - s3:CreateBucket - s3:PutBucketPolicy - s3:GetBucketPolicy - s3:PutLifecycleConfiguration - s3:PutBucketVersioning - s3:DeleteObject Resource: - arn:aws:s3:::aws-sam-cli-managed-default-samclisourcebucket-* - arn:aws:s3:::aws-sam-cli-managed-default-samclisourcebucket-*/* - Effect: Allow Action: - iam:PassRole Resource: - !GetAtt SamCfnExecutionRole.Arn PaymentsDashboardDeployRole: Type: AWS::IAM::Role Properties: RoleName: githubdeploy-payments-dashboard AssumeRolePolicyDocument: Version: "2012-10-17" Statement: - Effect: Allow Principal: Federated: !Sub arn:aws:iam::${AWS::AccountId}:oidc-provider/token.actions.githubusercontent.com Action: sts:AssumeRoleWithWebIdentity Condition: StringEquals: token.actions.githubusercontent.com:aud: sts.amazonaws.com StringLike: token.actions.githubusercontent.com:sub: !Sub repo:${GitHubOrg}/payments-dashboard:ref:refs/heads/main Policies: - PolicyName: sam-deploy PolicyDocument: Version: "2012-10-17" Statement: - Effect: Allow Action: - cloudformation:CreateChangeSet - cloudformation:DeleteChangeSet - cloudformation:DescribeChangeSet - cloudformation:DescribeStackEvents - cloudformation:DescribeStacks - cloudformation:ExecuteChangeSet - cloudformation:GetTemplate - cloudformation:ListStackResources - cloudformation:UpdateStack - cloudformation:CreateStack - cloudformation:TagResource Resource: - !Sub arn:aws:cloudformation:us-east-1:${AWS::AccountId}:stack/payments-dashboard/* - Effect: Allow Action: - cloudformation:GetTemplateSummary Resource: "*" - Effect: Allow Action: - cloudformation:DescribeStacks - cloudformation:CreateChangeSet - cloudformation:DescribeChangeSet - cloudformation:ExecuteChangeSet - cloudformation:CreateStack Resource: - !Sub arn:aws:cloudformation:us-east-1:${AWS::AccountId}:stack/aws-sam-cli-managed-default/* - Effect: Allow Action: - s3:PutObject - s3:GetObject - s3:ListBucket - s3:GetBucketLocation - s3:CreateBucket - s3:PutBucketPolicy - s3:GetBucketPolicy - s3:PutLifecycleConfiguration - s3:PutBucketVersioning - s3:DeleteObject Resource: - arn:aws:s3:::aws-sam-cli-managed-default-samclisourcebucket-* - arn:aws:s3:::aws-sam-cli-managed-default-samclisourcebucket-*/* - Effect: Allow Action: - iam:PassRole Resource: - !GetAtt SamCfnExecutionRole.Arn # --------------------------------------------------------------------------- # CDK deploy roles (5 repos) # --------------------------------------------------------------------------- SeahavenSlackBotDeployRole: Type: AWS::IAM::Role Properties: RoleName: githubdeploy-seahaven-slack-bot AssumeRolePolicyDocument: Version: "2012-10-17" Statement: - Effect: Allow Principal: Federated: !Sub arn:aws:iam::${AWS::AccountId}:oidc-provider/token.actions.githubusercontent.com Action: sts:AssumeRoleWithWebIdentity Condition: StringEquals: token.actions.githubusercontent.com:aud: sts.amazonaws.com StringLike: token.actions.githubusercontent.com:sub: !Sub repo:${GitHubOrg}/seahaven-slack-bot:ref:refs/heads/main Policies: - PolicyName: cdk-deploy PolicyDocument: Version: "2012-10-17" Statement: - Effect: Allow Action: - sts:AssumeRole Resource: - !Sub arn:aws:iam::${AWS::AccountId}:role/cdk-hnb659fds-* ExecAideDeployRole: Type: AWS::IAM::Role Properties: RoleName: githubdeploy-exec-aide AssumeRolePolicyDocument: Version: "2012-10-17" Statement: - Effect: Allow Principal: Federated: !Sub arn:aws:iam::${AWS::AccountId}:oidc-provider/token.actions.githubusercontent.com Action: sts:AssumeRoleWithWebIdentity Condition: StringEquals: token.actions.githubusercontent.com:aud: sts.amazonaws.com StringLike: token.actions.githubusercontent.com:sub: !Sub repo:${GitHubOrg}/exec-aide:ref:refs/heads/main Policies: - PolicyName: cdk-deploy PolicyDocument: Version: "2012-10-17" Statement: - Effect: Allow Action: - sts:AssumeRole Resource: - !Sub arn:aws:iam::${AWS::AccountId}:role/cdk-hnb659fds-* SeahavenDoorUnlockApiDeployRole: Type: AWS::IAM::Role Properties: RoleName: githubdeploy-seahaven-door-unlock-api AssumeRolePolicyDocument: Version: "2012-10-17" Statement: - Effect: Allow Principal: Federated: !Sub arn:aws:iam::${AWS::AccountId}:oidc-provider/token.actions.githubusercontent.com Action: sts:AssumeRoleWithWebIdentity Condition: StringEquals: token.actions.githubusercontent.com:aud: sts.amazonaws.com StringLike: token.actions.githubusercontent.com:sub: !Sub repo:${GitHubOrg}/seahaven-door-unlock-api:ref:refs/heads/main Policies: - PolicyName: cdk-deploy PolicyDocument: Version: "2012-10-17" Statement: - Effect: Allow Action: - sts:AssumeRole Resource: - !Sub arn:aws:iam::${AWS::AccountId}:role/cdk-hnb659fds-* PoIngestDeployRole: Type: AWS::IAM::Role Properties: RoleName: githubdeploy-po-ingest AssumeRolePolicyDocument: Version: "2012-10-17" Statement: - Effect: Allow Principal: Federated: !Sub arn:aws:iam::${AWS::AccountId}:oidc-provider/token.actions.githubusercontent.com Action: sts:AssumeRoleWithWebIdentity Condition: StringEquals: token.actions.githubusercontent.com:aud: sts.amazonaws.com StringLike: token.actions.githubusercontent.com:sub: !Sub repo:${GitHubOrg}/po-ingest:ref:refs/heads/main Policies: - PolicyName: cdk-deploy PolicyDocument: Version: "2012-10-17" Statement: - Effect: Allow Action: - sts:AssumeRole Resource: - !Sub arn:aws:iam::${AWS::AccountId}:role/cdk-hnb659fds-* WorkorderIngestDeployRole: Type: AWS::IAM::Role Properties: RoleName: githubdeploy-workorder-ingest AssumeRolePolicyDocument: Version: "2012-10-17" Statement: - Effect: Allow Principal: Federated: !Sub arn:aws:iam::${AWS::AccountId}:oidc-provider/token.actions.githubusercontent.com Action: sts:AssumeRoleWithWebIdentity Condition: StringEquals: token.actions.githubusercontent.com:aud: sts.amazonaws.com StringLike: token.actions.githubusercontent.com:sub: !Sub repo:${GitHubOrg}/workorder-ingest:ref:refs/heads/main Policies: - PolicyName: cdk-deploy PolicyDocument: Version: "2012-10-17" Statement: - Effect: Allow Action: - sts:AssumeRole Resource: - !Sub arn:aws:iam::${AWS::AccountId}:role/cdk-hnb659fds-* Outputs: SamCfnExecutionRoleArn: Value: !GetAtt SamCfnExecutionRole.Arn Export: Name: github-cfn-execution-role-arn AfterhoursShiftManagerDeployRoleArn: Value: !GetAtt AfterhoursShiftManagerDeployRole.Arn ExpenseApprovalBotDeployRoleArn: Value: !GetAtt ExpenseApprovalBotDeployRole.Arn AfiBackupMonitorDeployRoleArn: Value: !GetAtt AfiBackupMonitorDeployRole.Arn RingScheduler3cxDeployRoleArn: Value: !GetAtt RingScheduler3cxDeployRole.Arn PaymentsDashboardDeployRoleArn: Value: !GetAtt PaymentsDashboardDeployRole.Arn SeahavenSlackBotDeployRoleArn: Value: !GetAtt SeahavenSlackBotDeployRole.Arn ExecAideDeployRoleArn: Value: !GetAtt ExecAideDeployRole.Arn SeahavenDoorUnlockApiDeployRoleArn: Value: !GetAtt SeahavenDoorUnlockApiDeployRole.Arn PoIngestDeployRoleArn: Value: !GetAtt PoIngestDeployRole.Arn WorkorderIngestDeployRoleArn: Value: !GetAtt WorkorderIngestDeployRole.Arn