fix(infra): move hcptf ECS apply perms to a managed policy (PLAT-216)

PutRolePolicy cannot add a third inline on the prod apply role; CreatePolicy of /tf-managed/afterhours-shift-manager-ecs still needs the bootstrap window.
This commit is contained in:
Adam Moussa 2026-09-21 16:42:09 -04:00
parent 1362a6cd90
commit 2e0588278d
No known key found for this signature in database
3 changed files with 16 additions and 7 deletions

View file

@ -1086,10 +1086,14 @@ resource "aws_iam_role_policy" "hcptf_apply_services" {
policy = data.aws_iam_policy_document.hcptf_apply_services.json
}
resource "aws_iam_role_policy" "hcptf_apply_ecs" {
name = "afterhours-shift-manager-ecs"
role = aws_iam_role.hcptf_apply.id
policy = data.aws_iam_policy_document.hcptf_apply_ecs.json
# Customer-managed: the apply role already has two inlines (scoped-iam +
# services). A third PutRolePolicy exceeds the 10KB combined inline limit
# in seahaven-prod. CreatePolicy still needs the hcptf-bootstrap window.
resource "aws_iam_policy" "hcptf_apply_ecs" {
name = "afterhours-shift-manager-ecs"
path = "/tf-managed/"
description = "ECS, ALB, ECR, SQS, and VPC permissions for hcptf-afterhours-shift-manager"
policy = data.aws_iam_policy_document.hcptf_apply_ecs.json
}
resource "aws_iam_role_policy" "hcptf_plan_refresh" {
@ -1104,8 +1108,10 @@ resource "aws_iam_role_policy_attachment" "hcptf_plan_view_only" {
}
resource "aws_iam_role_policy_attachments_exclusive" "hcptf_apply" {
role_name = aws_iam_role.hcptf_apply.name
policy_arns = []
role_name = aws_iam_role.hcptf_apply.name
policy_arns = [
aws_iam_policy.hcptf_apply_ecs.arn,
]
}
resource "aws_iam_role_policy_attachments_exclusive" "hcptf_plan" {

View file

@ -14,7 +14,7 @@ resource "aws_vpc" "this" {
# First apply updates the live hcptf apply role before CreateVpc.
depends_on = [
aws_iam_role_policy.hcptf_apply_services,
aws_iam_role_policy.hcptf_apply_ecs,
aws_iam_role_policy_attachments_exclusive.hcptf_apply,
]
}

View file

@ -83,6 +83,9 @@ def test_stack_owns_a_vpc_instead_of_looking_up_default():
assert "sid = \"RefreshVpc\"" in HCP_IAM
assert "afterhours-shift-manager-ecs" in HCP_IAM
assert "hcptf_apply_ecs" in HCP_IAM
assert 'resource "aws_iam_policy" "hcptf_apply_ecs"' in HCP_IAM
assert 'resource "aws_iam_role_policy" "hcptf_apply_ecs"' not in HCP_IAM
assert "aws_iam_policy.hcptf_apply_ecs.arn" in HCP_IAM
def test_ecs_task_boundary_uses_static_arns():