mirror of
https://github.com/Sea-Haven-Industries/afterhours-shift-manager.git
synced 2026-09-30 07:53:11 +00:00
Point release-notify invoke role trust at deploy.yaml
The release job moved from release.yaml into deploy.yaml to clear CodeQL's workflow_run findings, but the OIDC invoke role's trust still pinned job_workflow_ref to release.yaml. That denied the AssumeRole at the release job's Configure-AWS step, so the v1.10.0 announcement never fired. Point the condition at deploy.yaml (the inline release job's top-level workflow) so the token's job_workflow_ref matches.
This commit is contained in:
parent
53c85f7eed
commit
1d97d644ee
1 changed files with 4 additions and 3 deletions
|
|
@ -300,9 +300,10 @@ Resources:
|
||||||
token.actions.githubusercontent.com:aud: sts.amazonaws.com
|
token.actions.githubusercontent.com:aud: sts.amazonaws.com
|
||||||
StringLike:
|
StringLike:
|
||||||
token.actions.githubusercontent.com:sub: "repo:Sea-Haven-Industries/afterhours-shift-manager:ref:refs/heads/main"
|
token.actions.githubusercontent.com:sub: "repo:Sea-Haven-Industries/afterhours-shift-manager:ref:refs/heads/main"
|
||||||
# Defense-in-depth: only the release workflow may assume this role,
|
# Defense-in-depth: only the Deploy workflow's release job may assume
|
||||||
# not any workflow running on main.
|
# this role, not any workflow running on main. (The release job lives
|
||||||
token.actions.githubusercontent.com:job_workflow_ref: "Sea-Haven-Industries/afterhours-shift-manager/.github/workflows/release.yaml@refs/heads/main"
|
# in deploy.yaml; this must match that workflow's path.)
|
||||||
|
token.actions.githubusercontent.com:job_workflow_ref: "Sea-Haven-Industries/afterhours-shift-manager/.github/workflows/deploy.yaml@refs/heads/main"
|
||||||
Policies:
|
Policies:
|
||||||
- PolicyName: invoke-release-notifier
|
- PolicyName: invoke-release-notifier
|
||||||
PolicyDocument:
|
PolicyDocument:
|
||||||
|
|
|
||||||
Loading…
Add table
Reference in a new issue