mirror of
https://github.com/Sea-Haven-Industries/.github.git
synced 2026-09-30 12:53:12 +00:00
Three issues from the mandatory IAM cross-review (BLOCK/FIX): 1. Add KMS statement — PaymentsDashboard DynamoDB table and payments-dashboard CloudWatch log groups use CMKs. Without kms:Decrypt + kms:GenerateDataKey in the boundary, those Lambda calls fail at the KMS layer at runtime. Scoped to account keys only. 2. Add table/*/index/* to DynamoDB resource — dynamodb:Query on a GSI requires the index ARN; covering only table/* silently denied GSI queries at the boundary. 3. Fix EC2 ENI statement — remove AssignPrivateIpAddresses / UnassignPrivateIpAddresses (EFA-only, not part of Lambda ENI lifecycle); add DescribeSubnets + DescribeSecurityGroups + DescribeVpcs which are required by the Lambda service during VPC attachment and are present in AWSLambdaVPCAccessExecutionRole. 4. Add SES configuration-set/* resource — ses:SendRawEmail requires permission on the configuration set if one is passed at send time. Refs: INFRA-103
783 lines
32 KiB
YAML
783 lines
32 KiB
YAML
AWSTemplateFormatVersion: "2010-09-09"
|
|
Description: >-
|
|
GitHub Actions OIDC deploy roles for Sea Haven Industries repos.
|
|
Each repo gets a scoped IAM role that GitHub Actions assumes via OIDC.
|
|
|
|
Parameters:
|
|
GitHubOrg:
|
|
Type: String
|
|
Default: Sea-Haven-Industries
|
|
CreateOIDCProvider:
|
|
Type: String
|
|
Default: "false"
|
|
AllowedValues: ["true", "false"]
|
|
Description: Set to true only if the GitHub OIDC provider does not already exist in this account
|
|
|
|
Conditions:
|
|
ShouldCreateOIDCProvider: !Equals [!Ref CreateOIDCProvider, "true"]
|
|
|
|
Resources:
|
|
|
|
# ---------------------------------------------------------------------------
|
|
# OIDC Provider (conditional — already exists for seahaven-site)
|
|
# ---------------------------------------------------------------------------
|
|
GitHubOIDCProvider:
|
|
Type: AWS::IAM::OIDCProvider
|
|
Condition: ShouldCreateOIDCProvider
|
|
Properties:
|
|
Url: https://token.actions.githubusercontent.com
|
|
ClientIdList:
|
|
- sts.amazonaws.com
|
|
ThumbprintList:
|
|
- 6938fd4d98bab03faadb97b34396831e3780aea1
|
|
|
|
# ---------------------------------------------------------------------------
|
|
# Lambda execution permissions boundary (INFRA-103)
|
|
#
|
|
# This managed policy is the CEILING for every Lambda execution role that the
|
|
# five SAM stacks auto-generate via AWS::Serverless::Function. Applying it as
|
|
# PermissionsBoundary on those roles means the effective permissions are the
|
|
# intersection of the role's own policies and this boundary, so a misconfigured
|
|
# SAM role can never exceed what is listed here.
|
|
#
|
|
# The boundary is intentionally a SUPERSET of the union of all runtime
|
|
# permissions currently granted across the five stacks. Being slightly broad
|
|
# is the correct trade-off at this stage — a boundary that is too tight will
|
|
# break Lambda functions at runtime after deploy, which is worse than a slightly
|
|
# loose boundary that is tightened in a follow-up.
|
|
#
|
|
# Permission sources per stack:
|
|
#
|
|
# afterhours-shift-manager
|
|
# - DynamoDB CRUD (afterhours-shifts table)
|
|
# - secretsmanager:GetSecretValue (afterhours-shift-manager/*)
|
|
# - ses:SendEmail (SES identity)
|
|
# - CloudWatch Logs (all functions)
|
|
#
|
|
# payments-dashboard
|
|
# - DynamoDB CRUD / Read (PaymentsDashboard table)
|
|
# - S3 GetObject (payroll-emails, payments-csv buckets)
|
|
# - secretsmanager:GetSecretValue (payments-dashboard/*)
|
|
# - sqs:SendMessage + sqs:ReceiveMessage + sqs:DeleteMessage etc.
|
|
# (PayrollBatchQueue + DLQs)
|
|
# - lambda:InvokeFunction (ExpenseReceiver → ExpenseProcessor)
|
|
# - ec2:CreateNetworkInterface / DescribeNetworkInterfaces /
|
|
# DeleteNetworkInterface (VPC-attached functions)
|
|
# - CloudWatch Logs
|
|
#
|
|
# meal-order-manager
|
|
# - DynamoDB CRUD / Read (meal-order-manager-orders table)
|
|
# - S3 CRUD (ReportsBucket) + s3:GetObject (ReportsBucket presigned URLs)
|
|
# - secretsmanager:GetSecretValue (meal-order-manager/*)
|
|
# - ssm:GetParameter (/meal-order-manager/*)
|
|
# - lambda:InvokeFunction (submit-order → slack-notifier,
|
|
# close-form → aggregate-orders)
|
|
# - ses:SendRawEmail
|
|
# - CloudWatch Logs
|
|
#
|
|
# front-integrations
|
|
# - DynamoDB CRUD (front-sla-alerts table)
|
|
# - secretsmanager:GetSecretValue (by ARN, various)
|
|
# - CloudWatch Logs
|
|
#
|
|
# afi-backup-monitor
|
|
# - secretsmanager:GetSecretValue (by ARN)
|
|
# - CloudWatch Logs
|
|
#
|
|
# ---------------------------------------------------------------------------
|
|
LambdaExecutionBoundary:
|
|
Type: AWS::IAM::ManagedPolicy
|
|
Properties:
|
|
ManagedPolicyName: seahaven-lambda-execution-boundary
|
|
Description: >-
|
|
Permissions boundary ceiling for all SAM-managed Lambda execution roles.
|
|
Applied via PermissionsBoundary on every Globals.Function in the five
|
|
SAM stacks (INFRA-103). Effective permissions are the intersection of
|
|
this policy and the role's own inline policies.
|
|
PolicyDocument:
|
|
Version: "2012-10-17"
|
|
Statement:
|
|
|
|
# ── CloudWatch Logs (every Lambda) ──────────────────────────────────
|
|
- Sid: CloudWatchLogs
|
|
Effect: Allow
|
|
Action:
|
|
- logs:CreateLogGroup
|
|
- logs:CreateLogStream
|
|
- logs:PutLogEvents
|
|
- logs:DescribeLogGroups
|
|
- logs:DescribeLogStreams
|
|
Resource: "*"
|
|
|
|
# ── X-Ray tracing (standard Lambda execution) ────────────────────
|
|
- Sid: XRay
|
|
Effect: Allow
|
|
Action:
|
|
- xray:PutTraceSegments
|
|
- xray:PutTelemetryRecords
|
|
Resource: "*"
|
|
|
|
# ── VPC / ENI management (payments-dashboard VPC functions) ────────
|
|
# Matches AWSLambdaVPCAccessExecutionRole exactly.
|
|
# AssignPrivateIpAddresses / UnassignPrivateIpAddresses are for EFA
|
|
# and secondary IPs — not part of the Lambda ENI lifecycle — omitted.
|
|
- Sid: Ec2Eni
|
|
Effect: Allow
|
|
Action:
|
|
- ec2:CreateNetworkInterface
|
|
- ec2:DescribeNetworkInterfaces
|
|
- ec2:DeleteNetworkInterface
|
|
- ec2:DescribeSubnets
|
|
- ec2:DescribeSecurityGroups
|
|
- ec2:DescribeVpcs
|
|
Resource: "*"
|
|
|
|
# ── DynamoDB (afterhours, payments, meal-order, front-integrations) ─
|
|
# Table/* covers base-table operations; table/*/index/* is required for
|
|
# Query/Scan on Global Secondary Indexes.
|
|
- Sid: DynamoDB
|
|
Effect: Allow
|
|
Action:
|
|
- dynamodb:GetItem
|
|
- dynamodb:PutItem
|
|
- dynamodb:UpdateItem
|
|
- dynamodb:DeleteItem
|
|
- dynamodb:Query
|
|
- dynamodb:Scan
|
|
- dynamodb:BatchGetItem
|
|
- dynamodb:BatchWriteItem
|
|
- dynamodb:DescribeTable
|
|
- dynamodb:ConditionCheckItem
|
|
Resource:
|
|
- !Sub "arn:aws:dynamodb:us-east-1:${AWS::AccountId}:table/*"
|
|
- !Sub "arn:aws:dynamodb:us-east-1:${AWS::AccountId}:table/*/index/*"
|
|
|
|
# ── S3 (payments-dashboard read, meal-order-manager CRUD) ──────────
|
|
- Sid: S3
|
|
Effect: Allow
|
|
Action:
|
|
- s3:GetObject
|
|
- s3:PutObject
|
|
- s3:DeleteObject
|
|
- s3:ListBucket
|
|
- s3:GetBucketLocation
|
|
- s3:GetObjectVersion
|
|
- s3:GetObjectTagging
|
|
- s3:PutObjectTagging
|
|
Resource:
|
|
- !Sub "arn:aws:s3:::*-${AWS::AccountId}"
|
|
- !Sub "arn:aws:s3:::*-${AWS::AccountId}/*"
|
|
# meal-order-manager ReportsBucket (non-AccountId suffix pattern)
|
|
- !Sub "arn:aws:s3:::meal-order-manager-reports-${AWS::AccountId}"
|
|
- !Sub "arn:aws:s3:::meal-order-manager-reports-${AWS::AccountId}/*"
|
|
- !Sub "arn:aws:s3:::meal-order-manager-form-${AWS::AccountId}"
|
|
- !Sub "arn:aws:s3:::meal-order-manager-form-${AWS::AccountId}/*"
|
|
|
|
# ── Secrets Manager (all stacks) ──────────────────────────────────
|
|
- Sid: SecretsManager
|
|
Effect: Allow
|
|
Action:
|
|
- secretsmanager:GetSecretValue
|
|
- secretsmanager:DescribeSecret
|
|
Resource:
|
|
- !Sub "arn:aws:secretsmanager:us-east-1:${AWS::AccountId}:secret:*"
|
|
|
|
# ── SSM Parameter Store (meal-order-manager, afterhours) ──────────
|
|
- Sid: SSMParameterRead
|
|
Effect: Allow
|
|
Action:
|
|
- ssm:GetParameter
|
|
- ssm:GetParameters
|
|
- ssm:GetParametersByPath
|
|
Resource:
|
|
- !Sub "arn:aws:ssm:us-east-1:${AWS::AccountId}:parameter/*"
|
|
|
|
# ── SQS (payments-dashboard batch queues) ─────────────────────────
|
|
- Sid: SQS
|
|
Effect: Allow
|
|
Action:
|
|
- sqs:SendMessage
|
|
- sqs:ReceiveMessage
|
|
- sqs:DeleteMessage
|
|
- sqs:GetQueueAttributes
|
|
- sqs:GetQueueUrl
|
|
- sqs:ChangeMessageVisibility
|
|
Resource:
|
|
- !Sub "arn:aws:sqs:us-east-1:${AWS::AccountId}:*"
|
|
|
|
# ── Lambda invocation (payments, meal-order inter-function calls) ──
|
|
- Sid: LambdaInvoke
|
|
Effect: Allow
|
|
Action:
|
|
- lambda:InvokeFunction
|
|
Resource:
|
|
- !Sub "arn:aws:lambda:us-east-1:${AWS::AccountId}:function:*"
|
|
|
|
# ── SES (afterhours weekly-post, meal-order email-report) ──────────
|
|
- Sid: SES
|
|
Effect: Allow
|
|
Action:
|
|
- ses:SendEmail
|
|
- ses:SendRawEmail
|
|
Resource:
|
|
- !Sub "arn:aws:ses:us-east-1:${AWS::AccountId}:identity/*"
|
|
- !Sub "arn:aws:ses:us-east-1:${AWS::AccountId}:configuration-set/*"
|
|
|
|
# ── KMS (CMK-encrypted resources) ─────────────────────────────────
|
|
# Required for Lambda functions that read/write CMK-encrypted AWS
|
|
# resources. Verified live state:
|
|
# - PaymentsDashboard DynamoDB table: CMK key/0b660af3 (KMS:ENABLED)
|
|
# - payments-dashboard CloudWatch log groups: CMK key/b748750c
|
|
# Secrets Manager + SQS queues in these stacks use AWS-managed keys
|
|
# (aws/secretsmanager, aws/sqs) which do not require explicit kms:*
|
|
# actions in the execution role policy. The CMK keys are scoped to
|
|
# this account to prevent cross-account KMS calls.
|
|
- Sid: KMS
|
|
Effect: Allow
|
|
Action:
|
|
- kms:Decrypt
|
|
- kms:GenerateDataKey
|
|
- kms:DescribeKey
|
|
Resource:
|
|
- !Sub "arn:aws:kms:us-east-1:${AWS::AccountId}:key/*"
|
|
|
|
# ---------------------------------------------------------------------------
|
|
# Shared CloudFormation execution role (SAM stacks)
|
|
# ---------------------------------------------------------------------------
|
|
SamCfnExecutionRole:
|
|
Type: AWS::IAM::Role
|
|
Properties:
|
|
RoleName: github-cfn-execution-role
|
|
AssumeRolePolicyDocument:
|
|
Version: "2012-10-17"
|
|
Statement:
|
|
- Effect: Allow
|
|
Principal:
|
|
Service: cloudformation.amazonaws.com
|
|
Action: sts:AssumeRole
|
|
ManagedPolicyArns:
|
|
- arn:aws:iam::aws:policy/AWSLambda_FullAccess
|
|
- arn:aws:iam::aws:policy/AmazonAPIGatewayAdministrator
|
|
- arn:aws:iam::aws:policy/AmazonDynamoDBFullAccess
|
|
- arn:aws:iam::aws:policy/AmazonS3FullAccess
|
|
- arn:aws:iam::aws:policy/CloudWatchLogsFullAccess
|
|
- arn:aws:iam::aws:policy/AmazonEventBridgeFullAccess
|
|
- arn:aws:iam::aws:policy/AmazonSESFullAccess
|
|
- arn:aws:iam::aws:policy/IAMFullAccess
|
|
Policies:
|
|
- PolicyName: additional-service-permissions
|
|
PolicyDocument:
|
|
Version: "2012-10-17"
|
|
Statement:
|
|
- Effect: Allow
|
|
Action:
|
|
- cloudformation:CreateChangeSet
|
|
Resource:
|
|
- arn:aws:cloudformation:us-east-1:aws:transform/*
|
|
- Effect: Allow
|
|
Action:
|
|
- sqs:*
|
|
- sns:*
|
|
- ec2:*
|
|
# cloudfront:* and ssm:* reconciled from out-of-band drift
|
|
# (audit H-16) — needed by SAM deploys that manage CloudFront
|
|
# distributions (meal-order-manager) and SSM parameters
|
|
# (afterhours / payments / meal-order). Codified 2026-05-29.
|
|
- cloudfront:*
|
|
- ssm:*
|
|
Resource: "*"
|
|
# WAF (audit M-17) — needed for SAM/CFN-managed WebACL associations
|
|
# on CloudFront distributions (meal-order-manager orders). Read +
|
|
# (dis)associate only, not wafv2:*. Added 2026-06-02.
|
|
- Effect: Allow
|
|
Action:
|
|
- wafv2:GetWebACL
|
|
- wafv2:GetWebACLForResource
|
|
- wafv2:ListWebACLs
|
|
- wafv2:AssociateWebACL
|
|
- wafv2:DisassociateWebACL
|
|
- wafv2:ListResourcesForWebACL
|
|
Resource: "*"
|
|
|
|
# ---------------------------------------------------------------------------
|
|
# SAM deploy roles (4 repos)
|
|
# ---------------------------------------------------------------------------
|
|
|
|
AfterhoursShiftManagerDeployRole:
|
|
Type: AWS::IAM::Role
|
|
Properties:
|
|
RoleName: githubdeploy-afterhours-shift-manager
|
|
AssumeRolePolicyDocument:
|
|
Version: "2012-10-17"
|
|
Statement:
|
|
- Effect: Allow
|
|
Principal:
|
|
Federated: !Sub arn:aws:iam::${AWS::AccountId}:oidc-provider/token.actions.githubusercontent.com
|
|
Action: sts:AssumeRoleWithWebIdentity
|
|
Condition:
|
|
StringEquals:
|
|
token.actions.githubusercontent.com:aud: sts.amazonaws.com
|
|
StringLike:
|
|
token.actions.githubusercontent.com:sub: !Sub repo:${GitHubOrg}/afterhours-shift-manager:ref:refs/heads/main
|
|
Policies:
|
|
- PolicyName: sam-deploy
|
|
PolicyDocument:
|
|
Version: "2012-10-17"
|
|
Statement:
|
|
- Effect: Allow
|
|
Action:
|
|
- cloudformation:CreateChangeSet
|
|
- cloudformation:DeleteChangeSet
|
|
- cloudformation:DescribeChangeSet
|
|
- cloudformation:DescribeStackEvents
|
|
- cloudformation:DescribeStacks
|
|
- cloudformation:ExecuteChangeSet
|
|
- cloudformation:GetTemplate
|
|
- cloudformation:ListStackResources
|
|
- cloudformation:UpdateStack
|
|
- cloudformation:CreateStack
|
|
- cloudformation:TagResource
|
|
Resource:
|
|
- !Sub arn:aws:cloudformation:us-east-1:${AWS::AccountId}:stack/afterhours-shift-manager/*
|
|
- Effect: Allow
|
|
Action:
|
|
- cloudformation:GetTemplateSummary
|
|
Resource: "*"
|
|
- Effect: Allow
|
|
Action:
|
|
- cloudformation:DescribeStacks
|
|
- cloudformation:CreateChangeSet
|
|
- cloudformation:DescribeChangeSet
|
|
- cloudformation:ExecuteChangeSet
|
|
- cloudformation:CreateStack
|
|
Resource:
|
|
- !Sub arn:aws:cloudformation:us-east-1:${AWS::AccountId}:stack/aws-sam-cli-managed-default/*
|
|
- Effect: Allow
|
|
Action:
|
|
- s3:PutObject
|
|
- s3:GetObject
|
|
- s3:ListBucket
|
|
- s3:GetBucketLocation
|
|
- s3:CreateBucket
|
|
- s3:PutBucketPolicy
|
|
- s3:GetBucketPolicy
|
|
- s3:PutLifecycleConfiguration
|
|
- s3:PutBucketVersioning
|
|
- s3:DeleteObject
|
|
Resource:
|
|
- arn:aws:s3:::aws-sam-cli-managed-default-samclisourcebucket-*
|
|
- arn:aws:s3:::aws-sam-cli-managed-default-samclisourcebucket-*/*
|
|
- Effect: Allow
|
|
Action:
|
|
- iam:PassRole
|
|
Resource:
|
|
- !GetAtt SamCfnExecutionRole.Arn
|
|
|
|
FrontIntegrationsDeployRole:
|
|
Type: AWS::IAM::Role
|
|
Properties:
|
|
RoleName: githubdeploy-front-integrations
|
|
AssumeRolePolicyDocument:
|
|
Version: "2012-10-17"
|
|
Statement:
|
|
- Effect: Allow
|
|
Principal:
|
|
Federated: !Sub arn:aws:iam::${AWS::AccountId}:oidc-provider/token.actions.githubusercontent.com
|
|
Action: sts:AssumeRoleWithWebIdentity
|
|
Condition:
|
|
StringEquals:
|
|
token.actions.githubusercontent.com:aud: sts.amazonaws.com
|
|
StringLike:
|
|
token.actions.githubusercontent.com:sub: !Sub repo:${GitHubOrg}/front-integrations:ref:refs/heads/main
|
|
Policies:
|
|
- PolicyName: sam-deploy
|
|
PolicyDocument:
|
|
Version: "2012-10-17"
|
|
Statement:
|
|
- Effect: Allow
|
|
Action:
|
|
- cloudformation:CreateChangeSet
|
|
- cloudformation:DeleteChangeSet
|
|
- cloudformation:DescribeChangeSet
|
|
- cloudformation:DescribeStackEvents
|
|
- cloudformation:DescribeStacks
|
|
- cloudformation:ExecuteChangeSet
|
|
- cloudformation:GetTemplate
|
|
- cloudformation:ListStackResources
|
|
- cloudformation:UpdateStack
|
|
- cloudformation:CreateStack
|
|
- cloudformation:TagResource
|
|
Resource:
|
|
- !Sub arn:aws:cloudformation:us-east-1:${AWS::AccountId}:stack/front-integrations/*
|
|
- Effect: Allow
|
|
Action:
|
|
- cloudformation:GetTemplateSummary
|
|
Resource: "*"
|
|
- Effect: Allow
|
|
Action:
|
|
- cloudformation:DescribeStacks
|
|
- cloudformation:CreateChangeSet
|
|
- cloudformation:DescribeChangeSet
|
|
- cloudformation:ExecuteChangeSet
|
|
- cloudformation:CreateStack
|
|
Resource:
|
|
- !Sub arn:aws:cloudformation:us-east-1:${AWS::AccountId}:stack/aws-sam-cli-managed-default/*
|
|
- Effect: Allow
|
|
Action:
|
|
- s3:PutObject
|
|
- s3:GetObject
|
|
- s3:ListBucket
|
|
- s3:GetBucketLocation
|
|
- s3:CreateBucket
|
|
- s3:PutBucketPolicy
|
|
- s3:GetBucketPolicy
|
|
- s3:PutLifecycleConfiguration
|
|
- s3:PutBucketVersioning
|
|
- s3:DeleteObject
|
|
Resource:
|
|
- arn:aws:s3:::aws-sam-cli-managed-default-samclisourcebucket-*
|
|
- arn:aws:s3:::aws-sam-cli-managed-default-samclisourcebucket-*/*
|
|
- Effect: Allow
|
|
Action:
|
|
- iam:PassRole
|
|
Resource:
|
|
- !GetAtt SamCfnExecutionRole.Arn
|
|
|
|
AfiBackupMonitorDeployRole:
|
|
Type: AWS::IAM::Role
|
|
Properties:
|
|
RoleName: githubdeploy-afi-backup-monitor
|
|
AssumeRolePolicyDocument:
|
|
Version: "2012-10-17"
|
|
Statement:
|
|
- Effect: Allow
|
|
Principal:
|
|
Federated: !Sub arn:aws:iam::${AWS::AccountId}:oidc-provider/token.actions.githubusercontent.com
|
|
Action: sts:AssumeRoleWithWebIdentity
|
|
Condition:
|
|
StringEquals:
|
|
token.actions.githubusercontent.com:aud: sts.amazonaws.com
|
|
StringLike:
|
|
token.actions.githubusercontent.com:sub: !Sub repo:${GitHubOrg}/afi-backup-monitor:ref:refs/heads/main
|
|
Policies:
|
|
- PolicyName: sam-deploy
|
|
PolicyDocument:
|
|
Version: "2012-10-17"
|
|
Statement:
|
|
- Effect: Allow
|
|
Action:
|
|
- cloudformation:CreateChangeSet
|
|
- cloudformation:DeleteChangeSet
|
|
- cloudformation:DescribeChangeSet
|
|
- cloudformation:DescribeStackEvents
|
|
- cloudformation:DescribeStacks
|
|
- cloudformation:ExecuteChangeSet
|
|
- cloudformation:GetTemplate
|
|
- cloudformation:ListStackResources
|
|
- cloudformation:UpdateStack
|
|
- cloudformation:CreateStack
|
|
- cloudformation:TagResource
|
|
Resource:
|
|
- !Sub arn:aws:cloudformation:us-east-1:${AWS::AccountId}:stack/afi-backup-monitor/*
|
|
- Effect: Allow
|
|
Action:
|
|
- cloudformation:GetTemplateSummary
|
|
Resource: "*"
|
|
- Effect: Allow
|
|
Action:
|
|
- cloudformation:DescribeStacks
|
|
- cloudformation:CreateChangeSet
|
|
- cloudformation:DescribeChangeSet
|
|
- cloudformation:ExecuteChangeSet
|
|
- cloudformation:CreateStack
|
|
Resource:
|
|
- !Sub arn:aws:cloudformation:us-east-1:${AWS::AccountId}:stack/aws-sam-cli-managed-default/*
|
|
- Effect: Allow
|
|
Action:
|
|
- s3:PutObject
|
|
- s3:GetObject
|
|
- s3:ListBucket
|
|
- s3:GetBucketLocation
|
|
- s3:CreateBucket
|
|
- s3:PutBucketPolicy
|
|
- s3:GetBucketPolicy
|
|
- s3:PutLifecycleConfiguration
|
|
- s3:PutBucketVersioning
|
|
- s3:DeleteObject
|
|
Resource:
|
|
- arn:aws:s3:::aws-sam-cli-managed-default-samclisourcebucket-*
|
|
- arn:aws:s3:::aws-sam-cli-managed-default-samclisourcebucket-*/*
|
|
- Effect: Allow
|
|
Action:
|
|
- iam:PassRole
|
|
Resource:
|
|
- !GetAtt SamCfnExecutionRole.Arn
|
|
|
|
PaymentsDashboardDeployRole:
|
|
Type: AWS::IAM::Role
|
|
Properties:
|
|
RoleName: githubdeploy-payments-dashboard
|
|
AssumeRolePolicyDocument:
|
|
Version: "2012-10-17"
|
|
Statement:
|
|
- Effect: Allow
|
|
Principal:
|
|
Federated: !Sub arn:aws:iam::${AWS::AccountId}:oidc-provider/token.actions.githubusercontent.com
|
|
Action: sts:AssumeRoleWithWebIdentity
|
|
Condition:
|
|
StringEquals:
|
|
token.actions.githubusercontent.com:aud: sts.amazonaws.com
|
|
StringLike:
|
|
token.actions.githubusercontent.com:sub: !Sub repo:${GitHubOrg}/payments-dashboard:ref:refs/heads/main
|
|
Policies:
|
|
- PolicyName: sam-deploy
|
|
PolicyDocument:
|
|
Version: "2012-10-17"
|
|
Statement:
|
|
- Effect: Allow
|
|
Action:
|
|
- cloudformation:CreateChangeSet
|
|
- cloudformation:DeleteChangeSet
|
|
- cloudformation:DescribeChangeSet
|
|
- cloudformation:DescribeStackEvents
|
|
- cloudformation:DescribeStacks
|
|
- cloudformation:ExecuteChangeSet
|
|
- cloudformation:GetTemplate
|
|
- cloudformation:ListStackResources
|
|
- cloudformation:UpdateStack
|
|
- cloudformation:CreateStack
|
|
- cloudformation:TagResource
|
|
Resource:
|
|
- !Sub arn:aws:cloudformation:us-east-1:${AWS::AccountId}:stack/payments-dashboard/*
|
|
- Effect: Allow
|
|
Action:
|
|
- cloudformation:GetTemplateSummary
|
|
Resource: "*"
|
|
- Effect: Allow
|
|
Action:
|
|
- cloudformation:DescribeStacks
|
|
- cloudformation:CreateChangeSet
|
|
- cloudformation:DescribeChangeSet
|
|
- cloudformation:ExecuteChangeSet
|
|
- cloudformation:CreateStack
|
|
Resource:
|
|
- !Sub arn:aws:cloudformation:us-east-1:${AWS::AccountId}:stack/aws-sam-cli-managed-default/*
|
|
- Effect: Allow
|
|
Action:
|
|
- s3:PutObject
|
|
- s3:GetObject
|
|
- s3:ListBucket
|
|
- s3:GetBucketLocation
|
|
- s3:CreateBucket
|
|
- s3:PutBucketPolicy
|
|
- s3:GetBucketPolicy
|
|
- s3:PutLifecycleConfiguration
|
|
- s3:PutBucketVersioning
|
|
- s3:DeleteObject
|
|
Resource:
|
|
- arn:aws:s3:::aws-sam-cli-managed-default-samclisourcebucket-*
|
|
- arn:aws:s3:::aws-sam-cli-managed-default-samclisourcebucket-*/*
|
|
- Effect: Allow
|
|
Action:
|
|
- iam:PassRole
|
|
Resource:
|
|
- !GetAtt SamCfnExecutionRole.Arn
|
|
|
|
# ---------------------------------------------------------------------------
|
|
# CDK deploy roles (4 repos)
|
|
# ---------------------------------------------------------------------------
|
|
|
|
SeahavenSlackBotDeployRole:
|
|
Type: AWS::IAM::Role
|
|
Properties:
|
|
RoleName: githubdeploy-seahaven-slack-bot
|
|
AssumeRolePolicyDocument:
|
|
Version: "2012-10-17"
|
|
Statement:
|
|
- Effect: Allow
|
|
Principal:
|
|
Federated: !Sub arn:aws:iam::${AWS::AccountId}:oidc-provider/token.actions.githubusercontent.com
|
|
Action: sts:AssumeRoleWithWebIdentity
|
|
Condition:
|
|
StringEquals:
|
|
token.actions.githubusercontent.com:aud: sts.amazonaws.com
|
|
StringLike:
|
|
token.actions.githubusercontent.com:sub: !Sub repo:${GitHubOrg}/seahaven-slack-bot:ref:refs/heads/main
|
|
Policies:
|
|
- PolicyName: cdk-deploy
|
|
PolicyDocument:
|
|
Version: "2012-10-17"
|
|
Statement:
|
|
- Effect: Allow
|
|
Action:
|
|
- sts:AssumeRole
|
|
Resource:
|
|
- !Sub arn:aws:iam::${AWS::AccountId}:role/cdk-hnb659fds-*
|
|
|
|
ExecAideDeployRole:
|
|
Type: AWS::IAM::Role
|
|
Properties:
|
|
RoleName: githubdeploy-exec-aide
|
|
AssumeRolePolicyDocument:
|
|
Version: "2012-10-17"
|
|
Statement:
|
|
- Effect: Allow
|
|
Principal:
|
|
Federated: !Sub arn:aws:iam::${AWS::AccountId}:oidc-provider/token.actions.githubusercontent.com
|
|
Action: sts:AssumeRoleWithWebIdentity
|
|
Condition:
|
|
StringEquals:
|
|
token.actions.githubusercontent.com:aud: sts.amazonaws.com
|
|
StringLike:
|
|
token.actions.githubusercontent.com:sub: !Sub repo:${GitHubOrg}/exec-aide:ref:refs/heads/main
|
|
Policies:
|
|
- PolicyName: cdk-deploy
|
|
PolicyDocument:
|
|
Version: "2012-10-17"
|
|
Statement:
|
|
- Effect: Allow
|
|
Action:
|
|
- sts:AssumeRole
|
|
Resource:
|
|
- !Sub arn:aws:iam::${AWS::AccountId}:role/cdk-hnb659fds-*
|
|
|
|
SeahavenDoorUnlockApiDeployRole:
|
|
Type: AWS::IAM::Role
|
|
Properties:
|
|
RoleName: githubdeploy-seahaven-door-unlock-api
|
|
AssumeRolePolicyDocument:
|
|
Version: "2012-10-17"
|
|
Statement:
|
|
- Effect: Allow
|
|
Principal:
|
|
Federated: !Sub arn:aws:iam::${AWS::AccountId}:oidc-provider/token.actions.githubusercontent.com
|
|
Action: sts:AssumeRoleWithWebIdentity
|
|
Condition:
|
|
StringEquals:
|
|
token.actions.githubusercontent.com:aud: sts.amazonaws.com
|
|
StringLike:
|
|
token.actions.githubusercontent.com:sub: !Sub repo:${GitHubOrg}/seahaven-door-unlock-api:ref:refs/heads/main
|
|
Policies:
|
|
- PolicyName: cdk-deploy
|
|
PolicyDocument:
|
|
Version: "2012-10-17"
|
|
Statement:
|
|
- Effect: Allow
|
|
Action:
|
|
- sts:AssumeRole
|
|
Resource:
|
|
- !Sub arn:aws:iam::${AWS::AccountId}:role/cdk-hnb659fds-*
|
|
|
|
ProcurementIngestDeployRole:
|
|
Type: AWS::IAM::Role
|
|
Properties:
|
|
RoleName: githubdeploy-procurement-ingest
|
|
AssumeRolePolicyDocument:
|
|
Version: "2012-10-17"
|
|
Statement:
|
|
- Effect: Allow
|
|
Principal:
|
|
Federated: !Sub arn:aws:iam::${AWS::AccountId}:oidc-provider/token.actions.githubusercontent.com
|
|
Action: sts:AssumeRoleWithWebIdentity
|
|
Condition:
|
|
StringEquals:
|
|
token.actions.githubusercontent.com:aud: sts.amazonaws.com
|
|
StringLike:
|
|
token.actions.githubusercontent.com:sub: !Sub repo:${GitHubOrg}/procurement-ingest:ref:refs/heads/main
|
|
Policies:
|
|
- PolicyName: cdk-deploy
|
|
PolicyDocument:
|
|
Version: "2012-10-17"
|
|
Statement:
|
|
- Effect: Allow
|
|
Action:
|
|
- sts:AssumeRole
|
|
Resource:
|
|
- !Sub arn:aws:iam::${AWS::AccountId}:role/cdk-hnb659fds-*
|
|
|
|
ApmWoAnalysisDeployRole:
|
|
Type: AWS::IAM::Role
|
|
Properties:
|
|
RoleName: githubdeploy-apm-wo-analysis
|
|
AssumeRolePolicyDocument:
|
|
Version: "2012-10-17"
|
|
Statement:
|
|
- Effect: Allow
|
|
Principal:
|
|
Federated: !Sub arn:aws:iam::${AWS::AccountId}:oidc-provider/token.actions.githubusercontent.com
|
|
Action: sts:AssumeRoleWithWebIdentity
|
|
Condition:
|
|
StringEquals:
|
|
token.actions.githubusercontent.com:aud: sts.amazonaws.com
|
|
StringLike:
|
|
token.actions.githubusercontent.com:sub: !Sub repo:${GitHubOrg}/apm-wo-analysis:ref:refs/heads/main
|
|
Policies:
|
|
- PolicyName: cdk-deploy
|
|
PolicyDocument:
|
|
Version: "2012-10-17"
|
|
Statement:
|
|
- Effect: Allow
|
|
Action:
|
|
- sts:AssumeRole
|
|
Resource:
|
|
- !Sub arn:aws:iam::${AWS::AccountId}:role/cdk-hnb659fds-*
|
|
|
|
SeahavenAccountBaselineDeployRole:
|
|
Type: AWS::IAM::Role
|
|
Properties:
|
|
RoleName: githubdeploy-seahaven-account-baseline
|
|
AssumeRolePolicyDocument:
|
|
Version: "2012-10-17"
|
|
Statement:
|
|
- Effect: Allow
|
|
Principal:
|
|
Federated: !Sub arn:aws:iam::${AWS::AccountId}:oidc-provider/token.actions.githubusercontent.com
|
|
Action: sts:AssumeRoleWithWebIdentity
|
|
Condition:
|
|
StringEquals:
|
|
token.actions.githubusercontent.com:aud: sts.amazonaws.com
|
|
StringLike:
|
|
token.actions.githubusercontent.com:sub: !Sub repo:${GitHubOrg}/seahaven-account-baseline:ref:refs/heads/main
|
|
Policies:
|
|
- PolicyName: cdk-deploy
|
|
PolicyDocument:
|
|
Version: "2012-10-17"
|
|
Statement:
|
|
- Effect: Allow
|
|
Action:
|
|
- sts:AssumeRole
|
|
Resource:
|
|
- !Sub arn:aws:iam::${AWS::AccountId}:role/cdk-hnb659fds-*
|
|
|
|
Outputs:
|
|
LambdaExecutionBoundaryArn:
|
|
Value: !Ref LambdaExecutionBoundary
|
|
Description: >-
|
|
ARN of the Lambda execution permissions boundary. Set this as
|
|
PermissionsBoundary on Globals.Function in all five SAM stacks.
|
|
Export:
|
|
Name: seahaven-lambda-execution-boundary-arn
|
|
SamCfnExecutionRoleArn:
|
|
Value: !GetAtt SamCfnExecutionRole.Arn
|
|
Export:
|
|
Name: github-cfn-execution-role-arn
|
|
AfterhoursShiftManagerDeployRoleArn:
|
|
Value: !GetAtt AfterhoursShiftManagerDeployRole.Arn
|
|
FrontIntegrationsDeployRoleArn:
|
|
Value: !GetAtt FrontIntegrationsDeployRole.Arn
|
|
AfiBackupMonitorDeployRoleArn:
|
|
Value: !GetAtt AfiBackupMonitorDeployRole.Arn
|
|
PaymentsDashboardDeployRoleArn:
|
|
Value: !GetAtt PaymentsDashboardDeployRole.Arn
|
|
SeahavenSlackBotDeployRoleArn:
|
|
Value: !GetAtt SeahavenSlackBotDeployRole.Arn
|
|
ExecAideDeployRoleArn:
|
|
Value: !GetAtt ExecAideDeployRole.Arn
|
|
SeahavenDoorUnlockApiDeployRoleArn:
|
|
Value: !GetAtt SeahavenDoorUnlockApiDeployRole.Arn
|
|
ProcurementIngestDeployRoleArn:
|
|
Value: !GetAtt ProcurementIngestDeployRole.Arn
|
|
ApmWoAnalysisDeployRoleArn:
|
|
Value: !GetAtt ApmWoAnalysisDeployRole.Arn
|
|
SeahavenAccountBaselineDeployRoleArn:
|
|
Value: !GetAtt SeahavenAccountBaselineDeployRole.Arn
|