From d2b7857e3ac5cef89b6b40d535313c31f6fa8c0a Mon Sep 17 00:00:00 2001 From: Adam Moussa Date: Wed, 2 Sep 2026 12:26:00 -0400 Subject: [PATCH] fix(iam): replace deprecated managed_policy_arns (PLAT-146) Keep exclusive attachment control so the apply role stays empty and the plan role keeps ViewOnlyAccess. --- terraform/hcp_iam.tf | 35 +++++++++++++++++++++++++++++++++-- 1 file changed, 33 insertions(+), 2 deletions(-) diff --git a/terraform/hcp_iam.tf b/terraform/hcp_iam.tf index 040d56b..79e2c10 100644 --- a/terraform/hcp_iam.tf +++ b/terraform/hcp_iam.tf @@ -37,6 +37,21 @@ import { id = "hcptf-afi-backup-monitor-plan:afi-backup-monitor-plan-refresh" } +import { + to = aws_iam_role_policy_attachments_exclusive.hcptf_apply + id = "hcptf-afi-backup-monitor" +} + +import { + to = aws_iam_role_policy_attachment.hcptf_plan_viewonly + id = "hcptf-afi-backup-monitor-plan/arn:aws:iam::aws:policy/job-function/ViewOnlyAccess" +} + +import { + to = aws_iam_role_policy_attachments_exclusive.hcptf_plan + id = "hcptf-afi-backup-monitor-plan" +} + data "aws_iam_policy_document" "hcptf_apply_trust" { statement { sid = "HcpApply" @@ -358,7 +373,6 @@ resource "aws_iam_role" "hcptf_apply" { name = "hcptf-afi-backup-monitor" assume_role_policy = data.aws_iam_policy_document.hcptf_apply_trust.json max_session_duration = 3600 - managed_policy_arns = [] tags = { Project = "afi-backup-monitor" @@ -367,11 +381,16 @@ resource "aws_iam_role" "hcptf_apply" { } } +# Empty exclusive set keeps seahaven-hcptf-iam-management detached. +resource "aws_iam_role_policy_attachments_exclusive" "hcptf_apply" { + role_name = aws_iam_role.hcptf_apply.name + policy_arns = [] +} + resource "aws_iam_role" "hcptf_plan" { name = "hcptf-afi-backup-monitor-plan" assume_role_policy = data.aws_iam_policy_document.hcptf_plan_trust.json max_session_duration = 3600 - managed_policy_arns = ["arn:aws:iam::aws:policy/job-function/ViewOnlyAccess"] tags = { Project = "afi-backup-monitor" @@ -380,6 +399,18 @@ resource "aws_iam_role" "hcptf_plan" { } } +resource "aws_iam_role_policy_attachment" "hcptf_plan_viewonly" { + role = aws_iam_role.hcptf_plan.name + policy_arn = "arn:aws:iam::aws:policy/job-function/ViewOnlyAccess" +} + +resource "aws_iam_role_policy_attachments_exclusive" "hcptf_plan" { + role_name = aws_iam_role.hcptf_plan.name + policy_arns = [ + aws_iam_role_policy_attachment.hcptf_plan_viewonly.policy_arn, + ] +} + resource "aws_iam_role_policy" "hcptf_scoped_iam" { name = "scoped-iam-management" role = aws_iam_role.hcptf_apply.id