fix(iam): replace deprecated managed_policy_arns (PLAT-146)

Keep exclusive attachment control so the apply role stays empty and the plan role keeps ViewOnlyAccess.
This commit is contained in:
Adam Moussa 2026-09-02 12:26:00 -04:00
parent 7fbff09f66
commit d2b7857e3a
No known key found for this signature in database

View file

@ -37,6 +37,21 @@ import {
id = "hcptf-afi-backup-monitor-plan:afi-backup-monitor-plan-refresh"
}
import {
to = aws_iam_role_policy_attachments_exclusive.hcptf_apply
id = "hcptf-afi-backup-monitor"
}
import {
to = aws_iam_role_policy_attachment.hcptf_plan_viewonly
id = "hcptf-afi-backup-monitor-plan/arn:aws:iam::aws:policy/job-function/ViewOnlyAccess"
}
import {
to = aws_iam_role_policy_attachments_exclusive.hcptf_plan
id = "hcptf-afi-backup-monitor-plan"
}
data "aws_iam_policy_document" "hcptf_apply_trust" {
statement {
sid = "HcpApply"
@ -358,7 +373,6 @@ resource "aws_iam_role" "hcptf_apply" {
name = "hcptf-afi-backup-monitor"
assume_role_policy = data.aws_iam_policy_document.hcptf_apply_trust.json
max_session_duration = 3600
managed_policy_arns = []
tags = {
Project = "afi-backup-monitor"
@ -367,11 +381,16 @@ resource "aws_iam_role" "hcptf_apply" {
}
}
# Empty exclusive set keeps seahaven-hcptf-iam-management detached.
resource "aws_iam_role_policy_attachments_exclusive" "hcptf_apply" {
role_name = aws_iam_role.hcptf_apply.name
policy_arns = []
}
resource "aws_iam_role" "hcptf_plan" {
name = "hcptf-afi-backup-monitor-plan"
assume_role_policy = data.aws_iam_policy_document.hcptf_plan_trust.json
max_session_duration = 3600
managed_policy_arns = ["arn:aws:iam::aws:policy/job-function/ViewOnlyAccess"]
tags = {
Project = "afi-backup-monitor"
@ -380,6 +399,18 @@ resource "aws_iam_role" "hcptf_plan" {
}
}
resource "aws_iam_role_policy_attachment" "hcptf_plan_viewonly" {
role = aws_iam_role.hcptf_plan.name
policy_arn = "arn:aws:iam::aws:policy/job-function/ViewOnlyAccess"
}
resource "aws_iam_role_policy_attachments_exclusive" "hcptf_plan" {
role_name = aws_iam_role.hcptf_plan.name
policy_arns = [
aws_iam_role_policy_attachment.hcptf_plan_viewonly.policy_arn,
]
}
resource "aws_iam_role_policy" "hcptf_scoped_iam" {
name = "scoped-iam-management"
role = aws_iam_role.hcptf_apply.id