Point release-notify invoke role trust at deploy.yaml

The release job moved from release.yaml into deploy.yaml to clear
CodeQL's workflow_run findings, but the OIDC invoke role's trust still
pinned job_workflow_ref to release.yaml. That denied the AssumeRole at
the release job's Configure-AWS step, so the v1.10.0 announcement never
fired. Point the condition at deploy.yaml (the inline release job's
top-level workflow) so the token's job_workflow_ref matches.
This commit is contained in:
Adam Moussa 2026-06-12 11:18:24 -04:00
parent 53c85f7eed
commit 1d97d644ee

View file

@ -300,9 +300,10 @@ Resources:
token.actions.githubusercontent.com:aud: sts.amazonaws.com token.actions.githubusercontent.com:aud: sts.amazonaws.com
StringLike: StringLike:
token.actions.githubusercontent.com:sub: "repo:Sea-Haven-Industries/afterhours-shift-manager:ref:refs/heads/main" token.actions.githubusercontent.com:sub: "repo:Sea-Haven-Industries/afterhours-shift-manager:ref:refs/heads/main"
# Defense-in-depth: only the release workflow may assume this role, # Defense-in-depth: only the Deploy workflow's release job may assume
# not any workflow running on main. # this role, not any workflow running on main. (The release job lives
token.actions.githubusercontent.com:job_workflow_ref: "Sea-Haven-Industries/afterhours-shift-manager/.github/workflows/release.yaml@refs/heads/main" # in deploy.yaml; this must match that workflow's path.)
token.actions.githubusercontent.com:job_workflow_ref: "Sea-Haven-Industries/afterhours-shift-manager/.github/workflows/deploy.yaml@refs/heads/main"
Policies: Policies:
- PolicyName: invoke-release-notifier - PolicyName: invoke-release-notifier
PolicyDocument: PolicyDocument: