fix(infra): move hcptf ECS apply perms to a managed policy (PLAT-216) (#263)
Some checks failed
Deploy API / Resolve target (push) Waiting to run
Deploy API / Deploy API to (push) Blocked by required conditions
Deploy / Deploy to prod (push) Has been cancelled

PutRolePolicy cannot add a third inline on the prod apply role; CreatePolicy of /tf-managed/afterhours-shift-manager-ecs still needs the bootstrap window.
This commit is contained in:
Adam Moussa 2026-09-21 20:47:25 +00:00 • committed by GitHub
parent 1362a6cd90
commit 6c4018d6b8
No known key found for this signature in database
GPG key ID: B5690EEEBB952194
3 changed files with 16 additions and 7 deletions

View file

@ -1086,10 +1086,14 @@ resource "aws_iam_role_policy" "hcptf_apply_services" {
policy = data.aws_iam_policy_document.hcptf_apply_services.json
}
resource "aws_iam_role_policy" "hcptf_apply_ecs" {
name = "afterhours-shift-manager-ecs"
role = aws_iam_role.hcptf_apply.id
policy = data.aws_iam_policy_document.hcptf_apply_ecs.json
# Customer-managed: the apply role already has two inlines (scoped-iam +
# services). A third PutRolePolicy exceeds the 10KB combined inline limit
# in seahaven-prod. CreatePolicy still needs the hcptf-bootstrap window.
resource "aws_iam_policy" "hcptf_apply_ecs" {
name = "afterhours-shift-manager-ecs"
path = "/tf-managed/"
description = "ECS, ALB, ECR, SQS, and VPC permissions for hcptf-afterhours-shift-manager"
policy = data.aws_iam_policy_document.hcptf_apply_ecs.json
}
resource "aws_iam_role_policy" "hcptf_plan_refresh" {
@ -1104,8 +1108,10 @@ resource "aws_iam_role_policy_attachment" "hcptf_plan_view_only" {
}
resource "aws_iam_role_policy_attachments_exclusive" "hcptf_apply" {
role_name = aws_iam_role.hcptf_apply.name
policy_arns = []
role_name = aws_iam_role.hcptf_apply.name
policy_arns = [
aws_iam_policy.hcptf_apply_ecs.arn,
]
}
resource "aws_iam_role_policy_attachments_exclusive" "hcptf_plan" {

View file

@ -14,7 +14,7 @@ resource "aws_vpc" "this" {
# First apply updates the live hcptf apply role before CreateVpc.
depends_on = [
aws_iam_role_policy.hcptf_apply_services,
aws_iam_role_policy.hcptf_apply_ecs,
aws_iam_role_policy_attachments_exclusive.hcptf_apply,
]
}

View file

@ -83,6 +83,9 @@ def test_stack_owns_a_vpc_instead_of_looking_up_default():
assert "sid = \"RefreshVpc\"" in HCP_IAM
assert "afterhours-shift-manager-ecs" in HCP_IAM
assert "hcptf_apply_ecs" in HCP_IAM
assert 'resource "aws_iam_policy" "hcptf_apply_ecs"' in HCP_IAM
assert 'resource "aws_iam_role_policy" "hcptf_apply_ecs"' not in HCP_IAM
assert "aws_iam_policy.hcptf_apply_ecs.arn" in HCP_IAM
def test_ecs_task_boundary_uses_static_arns():