From 1d97d644ee2346be52b359c187c3bf12e38223ad Mon Sep 17 00:00:00 2001 From: Adam Moussa Date: Fri, 12 Jun 2026 11:18:24 -0400 Subject: [PATCH] Point release-notify invoke role trust at deploy.yaml The release job moved from release.yaml into deploy.yaml to clear CodeQL's workflow_run findings, but the OIDC invoke role's trust still pinned job_workflow_ref to release.yaml. That denied the AssumeRole at the release job's Configure-AWS step, so the v1.10.0 announcement never fired. Point the condition at deploy.yaml (the inline release job's top-level workflow) so the token's job_workflow_ref matches. --- template.yaml | 7 ++++--- 1 file changed, 4 insertions(+), 3 deletions(-) diff --git a/template.yaml b/template.yaml index fa0b5d4..c2bb6f6 100644 --- a/template.yaml +++ b/template.yaml @@ -300,9 +300,10 @@ Resources: token.actions.githubusercontent.com:aud: sts.amazonaws.com StringLike: token.actions.githubusercontent.com:sub: "repo:Sea-Haven-Industries/afterhours-shift-manager:ref:refs/heads/main" - # Defense-in-depth: only the release workflow may assume this role, - # not any workflow running on main. - token.actions.githubusercontent.com:job_workflow_ref: "Sea-Haven-Industries/afterhours-shift-manager/.github/workflows/release.yaml@refs/heads/main" + # Defense-in-depth: only the Deploy workflow's release job may assume + # this role, not any workflow running on main. (The release job lives + # in deploy.yaml; this must match that workflow's path.) + token.actions.githubusercontent.com:job_workflow_ref: "Sea-Haven-Industries/afterhours-shift-manager/.github/workflows/deploy.yaml@refs/heads/main" Policies: - PolicyName: invoke-release-notifier PolicyDocument: