mirror of
https://github.com/Sea-Haven-Industries/.github.git
synced 2026-09-30 18:43:11 +00:00
- SQS/EC2/SNS as inline policy (managed policy quota is 10) - cd-sam.yaml now accepts optional parameter-overrides input for SAM templates with required parameters
591 lines
23 KiB
YAML
591 lines
23 KiB
YAML
AWSTemplateFormatVersion: "2010-09-09"
|
|
Description: >-
|
|
GitHub Actions OIDC deploy roles for Sea Haven Industries repos.
|
|
Each repo gets a scoped IAM role that GitHub Actions assumes via OIDC.
|
|
|
|
Parameters:
|
|
GitHubOrg:
|
|
Type: String
|
|
Default: Sea-Haven-Industries
|
|
CreateOIDCProvider:
|
|
Type: String
|
|
Default: "false"
|
|
AllowedValues: ["true", "false"]
|
|
Description: Set to true only if the GitHub OIDC provider does not already exist in this account
|
|
|
|
Conditions:
|
|
ShouldCreateOIDCProvider: !Equals [!Ref CreateOIDCProvider, "true"]
|
|
|
|
Resources:
|
|
|
|
# ---------------------------------------------------------------------------
|
|
# OIDC Provider (conditional — already exists for seahaven-site)
|
|
# ---------------------------------------------------------------------------
|
|
GitHubOIDCProvider:
|
|
Type: AWS::IAM::OIDCProvider
|
|
Condition: ShouldCreateOIDCProvider
|
|
Properties:
|
|
Url: https://token.actions.githubusercontent.com
|
|
ClientIdList:
|
|
- sts.amazonaws.com
|
|
ThumbprintList:
|
|
- 6938fd4d98bab03faadb97b34396831e3780aea1
|
|
|
|
# ---------------------------------------------------------------------------
|
|
# Shared CloudFormation execution role (SAM stacks)
|
|
# ---------------------------------------------------------------------------
|
|
SamCfnExecutionRole:
|
|
Type: AWS::IAM::Role
|
|
Properties:
|
|
RoleName: github-cfn-execution-role
|
|
AssumeRolePolicyDocument:
|
|
Version: "2012-10-17"
|
|
Statement:
|
|
- Effect: Allow
|
|
Principal:
|
|
Service: cloudformation.amazonaws.com
|
|
Action: sts:AssumeRole
|
|
ManagedPolicyArns:
|
|
- arn:aws:iam::aws:policy/AWSLambda_FullAccess
|
|
- arn:aws:iam::aws:policy/AmazonAPIGatewayAdministrator
|
|
- arn:aws:iam::aws:policy/AmazonDynamoDBFullAccess
|
|
- arn:aws:iam::aws:policy/AmazonS3FullAccess
|
|
- arn:aws:iam::aws:policy/CloudWatchLogsFullAccess
|
|
- arn:aws:iam::aws:policy/AmazonEventBridgeFullAccess
|
|
- arn:aws:iam::aws:policy/AmazonSESFullAccess
|
|
- arn:aws:iam::aws:policy/IAMFullAccess
|
|
Policies:
|
|
- PolicyName: additional-service-permissions
|
|
PolicyDocument:
|
|
Version: "2012-10-17"
|
|
Statement:
|
|
- Effect: Allow
|
|
Action:
|
|
- cloudformation:CreateChangeSet
|
|
Resource:
|
|
- arn:aws:cloudformation:us-east-1:aws:transform/*
|
|
- Effect: Allow
|
|
Action:
|
|
- sqs:*
|
|
- sns:*
|
|
- ec2:*
|
|
Resource: "*"
|
|
|
|
# ---------------------------------------------------------------------------
|
|
# SAM deploy roles (5 repos)
|
|
# ---------------------------------------------------------------------------
|
|
|
|
AfterhoursShiftManagerDeployRole:
|
|
Type: AWS::IAM::Role
|
|
Properties:
|
|
RoleName: githubdeploy-afterhours-shift-manager
|
|
AssumeRolePolicyDocument:
|
|
Version: "2012-10-17"
|
|
Statement:
|
|
- Effect: Allow
|
|
Principal:
|
|
Federated: !Sub arn:aws:iam::${AWS::AccountId}:oidc-provider/token.actions.githubusercontent.com
|
|
Action: sts:AssumeRoleWithWebIdentity
|
|
Condition:
|
|
StringEquals:
|
|
token.actions.githubusercontent.com:aud: sts.amazonaws.com
|
|
StringLike:
|
|
token.actions.githubusercontent.com:sub: !Sub repo:${GitHubOrg}/afterhours-shift-manager:ref:refs/heads/main
|
|
Policies:
|
|
- PolicyName: sam-deploy
|
|
PolicyDocument:
|
|
Version: "2012-10-17"
|
|
Statement:
|
|
- Effect: Allow
|
|
Action:
|
|
- cloudformation:CreateChangeSet
|
|
- cloudformation:DeleteChangeSet
|
|
- cloudformation:DescribeChangeSet
|
|
- cloudformation:DescribeStackEvents
|
|
- cloudformation:DescribeStacks
|
|
- cloudformation:ExecuteChangeSet
|
|
- cloudformation:GetTemplate
|
|
- cloudformation:ListStackResources
|
|
- cloudformation:UpdateStack
|
|
- cloudformation:CreateStack
|
|
- cloudformation:TagResource
|
|
Resource:
|
|
- !Sub arn:aws:cloudformation:us-east-1:${AWS::AccountId}:stack/afterhours-shift-manager/*
|
|
- Effect: Allow
|
|
Action:
|
|
- cloudformation:GetTemplateSummary
|
|
Resource: "*"
|
|
- Effect: Allow
|
|
Action:
|
|
- cloudformation:DescribeStacks
|
|
- cloudformation:CreateChangeSet
|
|
- cloudformation:DescribeChangeSet
|
|
- cloudformation:ExecuteChangeSet
|
|
- cloudformation:CreateStack
|
|
Resource:
|
|
- !Sub arn:aws:cloudformation:us-east-1:${AWS::AccountId}:stack/aws-sam-cli-managed-default/*
|
|
- Effect: Allow
|
|
Action:
|
|
- s3:PutObject
|
|
- s3:GetObject
|
|
- s3:ListBucket
|
|
- s3:GetBucketLocation
|
|
- s3:CreateBucket
|
|
- s3:PutBucketPolicy
|
|
- s3:GetBucketPolicy
|
|
- s3:PutLifecycleConfiguration
|
|
- s3:PutBucketVersioning
|
|
- s3:DeleteObject
|
|
Resource:
|
|
- arn:aws:s3:::aws-sam-cli-managed-default-samclisourcebucket-*
|
|
- arn:aws:s3:::aws-sam-cli-managed-default-samclisourcebucket-*/*
|
|
- Effect: Allow
|
|
Action:
|
|
- iam:PassRole
|
|
Resource:
|
|
- !GetAtt SamCfnExecutionRole.Arn
|
|
|
|
ExpenseApprovalBotDeployRole:
|
|
Type: AWS::IAM::Role
|
|
Properties:
|
|
RoleName: githubdeploy-expense-approval-bot
|
|
AssumeRolePolicyDocument:
|
|
Version: "2012-10-17"
|
|
Statement:
|
|
- Effect: Allow
|
|
Principal:
|
|
Federated: !Sub arn:aws:iam::${AWS::AccountId}:oidc-provider/token.actions.githubusercontent.com
|
|
Action: sts:AssumeRoleWithWebIdentity
|
|
Condition:
|
|
StringEquals:
|
|
token.actions.githubusercontent.com:aud: sts.amazonaws.com
|
|
StringLike:
|
|
token.actions.githubusercontent.com:sub: !Sub repo:${GitHubOrg}/expense-approval-bot:ref:refs/heads/main
|
|
Policies:
|
|
- PolicyName: sam-deploy
|
|
PolicyDocument:
|
|
Version: "2012-10-17"
|
|
Statement:
|
|
- Effect: Allow
|
|
Action:
|
|
- cloudformation:CreateChangeSet
|
|
- cloudformation:DeleteChangeSet
|
|
- cloudformation:DescribeChangeSet
|
|
- cloudformation:DescribeStackEvents
|
|
- cloudformation:DescribeStacks
|
|
- cloudformation:ExecuteChangeSet
|
|
- cloudformation:GetTemplate
|
|
- cloudformation:ListStackResources
|
|
- cloudformation:UpdateStack
|
|
- cloudformation:CreateStack
|
|
- cloudformation:TagResource
|
|
Resource:
|
|
- !Sub arn:aws:cloudformation:us-east-1:${AWS::AccountId}:stack/expense-approval-bot/*
|
|
- Effect: Allow
|
|
Action:
|
|
- cloudformation:GetTemplateSummary
|
|
Resource: "*"
|
|
- Effect: Allow
|
|
Action:
|
|
- cloudformation:DescribeStacks
|
|
- cloudformation:CreateChangeSet
|
|
- cloudformation:DescribeChangeSet
|
|
- cloudformation:ExecuteChangeSet
|
|
- cloudformation:CreateStack
|
|
Resource:
|
|
- !Sub arn:aws:cloudformation:us-east-1:${AWS::AccountId}:stack/aws-sam-cli-managed-default/*
|
|
- Effect: Allow
|
|
Action:
|
|
- s3:PutObject
|
|
- s3:GetObject
|
|
- s3:ListBucket
|
|
- s3:GetBucketLocation
|
|
- s3:CreateBucket
|
|
- s3:PutBucketPolicy
|
|
- s3:GetBucketPolicy
|
|
- s3:PutLifecycleConfiguration
|
|
- s3:PutBucketVersioning
|
|
- s3:DeleteObject
|
|
Resource:
|
|
- arn:aws:s3:::aws-sam-cli-managed-default-samclisourcebucket-*
|
|
- arn:aws:s3:::aws-sam-cli-managed-default-samclisourcebucket-*/*
|
|
- Effect: Allow
|
|
Action:
|
|
- iam:PassRole
|
|
Resource:
|
|
- !GetAtt SamCfnExecutionRole.Arn
|
|
|
|
AfiBackupMonitorDeployRole:
|
|
Type: AWS::IAM::Role
|
|
Properties:
|
|
RoleName: githubdeploy-afi-backup-monitor
|
|
AssumeRolePolicyDocument:
|
|
Version: "2012-10-17"
|
|
Statement:
|
|
- Effect: Allow
|
|
Principal:
|
|
Federated: !Sub arn:aws:iam::${AWS::AccountId}:oidc-provider/token.actions.githubusercontent.com
|
|
Action: sts:AssumeRoleWithWebIdentity
|
|
Condition:
|
|
StringEquals:
|
|
token.actions.githubusercontent.com:aud: sts.amazonaws.com
|
|
StringLike:
|
|
token.actions.githubusercontent.com:sub: !Sub repo:${GitHubOrg}/afi-backup-monitor:ref:refs/heads/main
|
|
Policies:
|
|
- PolicyName: sam-deploy
|
|
PolicyDocument:
|
|
Version: "2012-10-17"
|
|
Statement:
|
|
- Effect: Allow
|
|
Action:
|
|
- cloudformation:CreateChangeSet
|
|
- cloudformation:DeleteChangeSet
|
|
- cloudformation:DescribeChangeSet
|
|
- cloudformation:DescribeStackEvents
|
|
- cloudformation:DescribeStacks
|
|
- cloudformation:ExecuteChangeSet
|
|
- cloudformation:GetTemplate
|
|
- cloudformation:ListStackResources
|
|
- cloudformation:UpdateStack
|
|
- cloudformation:CreateStack
|
|
- cloudformation:TagResource
|
|
Resource:
|
|
- !Sub arn:aws:cloudformation:us-east-1:${AWS::AccountId}:stack/afi-backup-monitor/*
|
|
- Effect: Allow
|
|
Action:
|
|
- cloudformation:GetTemplateSummary
|
|
Resource: "*"
|
|
- Effect: Allow
|
|
Action:
|
|
- cloudformation:DescribeStacks
|
|
- cloudformation:CreateChangeSet
|
|
- cloudformation:DescribeChangeSet
|
|
- cloudformation:ExecuteChangeSet
|
|
- cloudformation:CreateStack
|
|
Resource:
|
|
- !Sub arn:aws:cloudformation:us-east-1:${AWS::AccountId}:stack/aws-sam-cli-managed-default/*
|
|
- Effect: Allow
|
|
Action:
|
|
- s3:PutObject
|
|
- s3:GetObject
|
|
- s3:ListBucket
|
|
- s3:GetBucketLocation
|
|
- s3:CreateBucket
|
|
- s3:PutBucketPolicy
|
|
- s3:GetBucketPolicy
|
|
- s3:PutLifecycleConfiguration
|
|
- s3:PutBucketVersioning
|
|
- s3:DeleteObject
|
|
Resource:
|
|
- arn:aws:s3:::aws-sam-cli-managed-default-samclisourcebucket-*
|
|
- arn:aws:s3:::aws-sam-cli-managed-default-samclisourcebucket-*/*
|
|
- Effect: Allow
|
|
Action:
|
|
- iam:PassRole
|
|
Resource:
|
|
- !GetAtt SamCfnExecutionRole.Arn
|
|
|
|
RingScheduler3cxDeployRole:
|
|
Type: AWS::IAM::Role
|
|
Properties:
|
|
RoleName: githubdeploy-ring-scheduler-3cx
|
|
AssumeRolePolicyDocument:
|
|
Version: "2012-10-17"
|
|
Statement:
|
|
- Effect: Allow
|
|
Principal:
|
|
Federated: !Sub arn:aws:iam::${AWS::AccountId}:oidc-provider/token.actions.githubusercontent.com
|
|
Action: sts:AssumeRoleWithWebIdentity
|
|
Condition:
|
|
StringEquals:
|
|
token.actions.githubusercontent.com:aud: sts.amazonaws.com
|
|
StringLike:
|
|
token.actions.githubusercontent.com:sub: !Sub repo:${GitHubOrg}/ring-scheduler-3cx:ref:refs/heads/main
|
|
Policies:
|
|
- PolicyName: sam-deploy
|
|
PolicyDocument:
|
|
Version: "2012-10-17"
|
|
Statement:
|
|
- Effect: Allow
|
|
Action:
|
|
- cloudformation:CreateChangeSet
|
|
- cloudformation:DeleteChangeSet
|
|
- cloudformation:DescribeChangeSet
|
|
- cloudformation:DescribeStackEvents
|
|
- cloudformation:DescribeStacks
|
|
- cloudformation:ExecuteChangeSet
|
|
- cloudformation:GetTemplate
|
|
- cloudformation:ListStackResources
|
|
- cloudformation:UpdateStack
|
|
- cloudformation:CreateStack
|
|
- cloudformation:TagResource
|
|
Resource:
|
|
- !Sub arn:aws:cloudformation:us-east-1:${AWS::AccountId}:stack/ring-scheduler-3cx/*
|
|
- Effect: Allow
|
|
Action:
|
|
- cloudformation:GetTemplateSummary
|
|
Resource: "*"
|
|
- Effect: Allow
|
|
Action:
|
|
- cloudformation:DescribeStacks
|
|
- cloudformation:CreateChangeSet
|
|
- cloudformation:DescribeChangeSet
|
|
- cloudformation:ExecuteChangeSet
|
|
- cloudformation:CreateStack
|
|
Resource:
|
|
- !Sub arn:aws:cloudformation:us-east-1:${AWS::AccountId}:stack/aws-sam-cli-managed-default/*
|
|
- Effect: Allow
|
|
Action:
|
|
- s3:PutObject
|
|
- s3:GetObject
|
|
- s3:ListBucket
|
|
- s3:GetBucketLocation
|
|
- s3:CreateBucket
|
|
- s3:PutBucketPolicy
|
|
- s3:GetBucketPolicy
|
|
- s3:PutLifecycleConfiguration
|
|
- s3:PutBucketVersioning
|
|
- s3:DeleteObject
|
|
Resource:
|
|
- arn:aws:s3:::aws-sam-cli-managed-default-samclisourcebucket-*
|
|
- arn:aws:s3:::aws-sam-cli-managed-default-samclisourcebucket-*/*
|
|
- Effect: Allow
|
|
Action:
|
|
- iam:PassRole
|
|
Resource:
|
|
- !GetAtt SamCfnExecutionRole.Arn
|
|
|
|
PaymentsDashboardDeployRole:
|
|
Type: AWS::IAM::Role
|
|
Properties:
|
|
RoleName: githubdeploy-payments-dashboard
|
|
AssumeRolePolicyDocument:
|
|
Version: "2012-10-17"
|
|
Statement:
|
|
- Effect: Allow
|
|
Principal:
|
|
Federated: !Sub arn:aws:iam::${AWS::AccountId}:oidc-provider/token.actions.githubusercontent.com
|
|
Action: sts:AssumeRoleWithWebIdentity
|
|
Condition:
|
|
StringEquals:
|
|
token.actions.githubusercontent.com:aud: sts.amazonaws.com
|
|
StringLike:
|
|
token.actions.githubusercontent.com:sub: !Sub repo:${GitHubOrg}/payments-dashboard:ref:refs/heads/main
|
|
Policies:
|
|
- PolicyName: sam-deploy
|
|
PolicyDocument:
|
|
Version: "2012-10-17"
|
|
Statement:
|
|
- Effect: Allow
|
|
Action:
|
|
- cloudformation:CreateChangeSet
|
|
- cloudformation:DeleteChangeSet
|
|
- cloudformation:DescribeChangeSet
|
|
- cloudformation:DescribeStackEvents
|
|
- cloudformation:DescribeStacks
|
|
- cloudformation:ExecuteChangeSet
|
|
- cloudformation:GetTemplate
|
|
- cloudformation:ListStackResources
|
|
- cloudformation:UpdateStack
|
|
- cloudformation:CreateStack
|
|
- cloudformation:TagResource
|
|
Resource:
|
|
- !Sub arn:aws:cloudformation:us-east-1:${AWS::AccountId}:stack/payments-dashboard/*
|
|
- Effect: Allow
|
|
Action:
|
|
- cloudformation:GetTemplateSummary
|
|
Resource: "*"
|
|
- Effect: Allow
|
|
Action:
|
|
- cloudformation:DescribeStacks
|
|
- cloudformation:CreateChangeSet
|
|
- cloudformation:DescribeChangeSet
|
|
- cloudformation:ExecuteChangeSet
|
|
- cloudformation:CreateStack
|
|
Resource:
|
|
- !Sub arn:aws:cloudformation:us-east-1:${AWS::AccountId}:stack/aws-sam-cli-managed-default/*
|
|
- Effect: Allow
|
|
Action:
|
|
- s3:PutObject
|
|
- s3:GetObject
|
|
- s3:ListBucket
|
|
- s3:GetBucketLocation
|
|
- s3:CreateBucket
|
|
- s3:PutBucketPolicy
|
|
- s3:GetBucketPolicy
|
|
- s3:PutLifecycleConfiguration
|
|
- s3:PutBucketVersioning
|
|
- s3:DeleteObject
|
|
Resource:
|
|
- arn:aws:s3:::aws-sam-cli-managed-default-samclisourcebucket-*
|
|
- arn:aws:s3:::aws-sam-cli-managed-default-samclisourcebucket-*/*
|
|
- Effect: Allow
|
|
Action:
|
|
- iam:PassRole
|
|
Resource:
|
|
- !GetAtt SamCfnExecutionRole.Arn
|
|
|
|
# ---------------------------------------------------------------------------
|
|
# CDK deploy roles (5 repos)
|
|
# ---------------------------------------------------------------------------
|
|
|
|
SeahavenSlackBotDeployRole:
|
|
Type: AWS::IAM::Role
|
|
Properties:
|
|
RoleName: githubdeploy-seahaven-slack-bot
|
|
AssumeRolePolicyDocument:
|
|
Version: "2012-10-17"
|
|
Statement:
|
|
- Effect: Allow
|
|
Principal:
|
|
Federated: !Sub arn:aws:iam::${AWS::AccountId}:oidc-provider/token.actions.githubusercontent.com
|
|
Action: sts:AssumeRoleWithWebIdentity
|
|
Condition:
|
|
StringEquals:
|
|
token.actions.githubusercontent.com:aud: sts.amazonaws.com
|
|
StringLike:
|
|
token.actions.githubusercontent.com:sub: !Sub repo:${GitHubOrg}/seahaven-slack-bot:ref:refs/heads/main
|
|
Policies:
|
|
- PolicyName: cdk-deploy
|
|
PolicyDocument:
|
|
Version: "2012-10-17"
|
|
Statement:
|
|
- Effect: Allow
|
|
Action:
|
|
- sts:AssumeRole
|
|
Resource:
|
|
- !Sub arn:aws:iam::${AWS::AccountId}:role/cdk-hnb659fds-*
|
|
|
|
ExecAideDeployRole:
|
|
Type: AWS::IAM::Role
|
|
Properties:
|
|
RoleName: githubdeploy-exec-aide
|
|
AssumeRolePolicyDocument:
|
|
Version: "2012-10-17"
|
|
Statement:
|
|
- Effect: Allow
|
|
Principal:
|
|
Federated: !Sub arn:aws:iam::${AWS::AccountId}:oidc-provider/token.actions.githubusercontent.com
|
|
Action: sts:AssumeRoleWithWebIdentity
|
|
Condition:
|
|
StringEquals:
|
|
token.actions.githubusercontent.com:aud: sts.amazonaws.com
|
|
StringLike:
|
|
token.actions.githubusercontent.com:sub: !Sub repo:${GitHubOrg}/exec-aide:ref:refs/heads/main
|
|
Policies:
|
|
- PolicyName: cdk-deploy
|
|
PolicyDocument:
|
|
Version: "2012-10-17"
|
|
Statement:
|
|
- Effect: Allow
|
|
Action:
|
|
- sts:AssumeRole
|
|
Resource:
|
|
- !Sub arn:aws:iam::${AWS::AccountId}:role/cdk-hnb659fds-*
|
|
|
|
SeahavenDoorUnlockApiDeployRole:
|
|
Type: AWS::IAM::Role
|
|
Properties:
|
|
RoleName: githubdeploy-seahaven-door-unlock-api
|
|
AssumeRolePolicyDocument:
|
|
Version: "2012-10-17"
|
|
Statement:
|
|
- Effect: Allow
|
|
Principal:
|
|
Federated: !Sub arn:aws:iam::${AWS::AccountId}:oidc-provider/token.actions.githubusercontent.com
|
|
Action: sts:AssumeRoleWithWebIdentity
|
|
Condition:
|
|
StringEquals:
|
|
token.actions.githubusercontent.com:aud: sts.amazonaws.com
|
|
StringLike:
|
|
token.actions.githubusercontent.com:sub: !Sub repo:${GitHubOrg}/seahaven-door-unlock-api:ref:refs/heads/main
|
|
Policies:
|
|
- PolicyName: cdk-deploy
|
|
PolicyDocument:
|
|
Version: "2012-10-17"
|
|
Statement:
|
|
- Effect: Allow
|
|
Action:
|
|
- sts:AssumeRole
|
|
Resource:
|
|
- !Sub arn:aws:iam::${AWS::AccountId}:role/cdk-hnb659fds-*
|
|
|
|
PoIngestDeployRole:
|
|
Type: AWS::IAM::Role
|
|
Properties:
|
|
RoleName: githubdeploy-po-ingest
|
|
AssumeRolePolicyDocument:
|
|
Version: "2012-10-17"
|
|
Statement:
|
|
- Effect: Allow
|
|
Principal:
|
|
Federated: !Sub arn:aws:iam::${AWS::AccountId}:oidc-provider/token.actions.githubusercontent.com
|
|
Action: sts:AssumeRoleWithWebIdentity
|
|
Condition:
|
|
StringEquals:
|
|
token.actions.githubusercontent.com:aud: sts.amazonaws.com
|
|
StringLike:
|
|
token.actions.githubusercontent.com:sub: !Sub repo:${GitHubOrg}/po-ingest:ref:refs/heads/main
|
|
Policies:
|
|
- PolicyName: cdk-deploy
|
|
PolicyDocument:
|
|
Version: "2012-10-17"
|
|
Statement:
|
|
- Effect: Allow
|
|
Action:
|
|
- sts:AssumeRole
|
|
Resource:
|
|
- !Sub arn:aws:iam::${AWS::AccountId}:role/cdk-hnb659fds-*
|
|
|
|
WorkorderIngestDeployRole:
|
|
Type: AWS::IAM::Role
|
|
Properties:
|
|
RoleName: githubdeploy-workorder-ingest
|
|
AssumeRolePolicyDocument:
|
|
Version: "2012-10-17"
|
|
Statement:
|
|
- Effect: Allow
|
|
Principal:
|
|
Federated: !Sub arn:aws:iam::${AWS::AccountId}:oidc-provider/token.actions.githubusercontent.com
|
|
Action: sts:AssumeRoleWithWebIdentity
|
|
Condition:
|
|
StringEquals:
|
|
token.actions.githubusercontent.com:aud: sts.amazonaws.com
|
|
StringLike:
|
|
token.actions.githubusercontent.com:sub: !Sub repo:${GitHubOrg}/workorder-ingest:ref:refs/heads/main
|
|
Policies:
|
|
- PolicyName: cdk-deploy
|
|
PolicyDocument:
|
|
Version: "2012-10-17"
|
|
Statement:
|
|
- Effect: Allow
|
|
Action:
|
|
- sts:AssumeRole
|
|
Resource:
|
|
- !Sub arn:aws:iam::${AWS::AccountId}:role/cdk-hnb659fds-*
|
|
|
|
Outputs:
|
|
SamCfnExecutionRoleArn:
|
|
Value: !GetAtt SamCfnExecutionRole.Arn
|
|
Export:
|
|
Name: github-cfn-execution-role-arn
|
|
AfterhoursShiftManagerDeployRoleArn:
|
|
Value: !GetAtt AfterhoursShiftManagerDeployRole.Arn
|
|
ExpenseApprovalBotDeployRoleArn:
|
|
Value: !GetAtt ExpenseApprovalBotDeployRole.Arn
|
|
AfiBackupMonitorDeployRoleArn:
|
|
Value: !GetAtt AfiBackupMonitorDeployRole.Arn
|
|
RingScheduler3cxDeployRoleArn:
|
|
Value: !GetAtt RingScheduler3cxDeployRole.Arn
|
|
PaymentsDashboardDeployRoleArn:
|
|
Value: !GetAtt PaymentsDashboardDeployRole.Arn
|
|
SeahavenSlackBotDeployRoleArn:
|
|
Value: !GetAtt SeahavenSlackBotDeployRole.Arn
|
|
ExecAideDeployRoleArn:
|
|
Value: !GetAtt ExecAideDeployRole.Arn
|
|
SeahavenDoorUnlockApiDeployRoleArn:
|
|
Value: !GetAtt SeahavenDoorUnlockApiDeployRole.Arn
|
|
PoIngestDeployRoleArn:
|
|
Value: !GetAtt PoIngestDeployRole.Arn
|
|
WorkorderIngestDeployRoleArn:
|
|
Value: !GetAtt WorkorderIngestDeployRole.Arn
|