fix(infra): move hcptf ECS apply perms to a managed policy (PLAT-216) (#263)
Some checks failed
Deploy API / Resolve target (push) Waiting to run
Deploy API / Deploy API to (push) Blocked by required conditions
Deploy / Deploy to prod (push) Has been cancelled

PutRolePolicy cannot add a third inline on the prod apply role; CreatePolicy of /tf-managed/afterhours-shift-manager-ecs still needs the bootstrap window.
This commit is contained in:
Adam Moussa 2026-09-21 20:47:25 +00:00 • committed by GitHub
parent 1362a6cd90
commit 6c4018d6b8
No known key found for this signature in database
GPG key ID: B5690EEEBB952194
3 changed files with 16 additions and 7 deletions

View file

@ -1086,10 +1086,14 @@ resource "aws_iam_role_policy" "hcptf_apply_services" {
policy = data.aws_iam_policy_document.hcptf_apply_services.json policy = data.aws_iam_policy_document.hcptf_apply_services.json
} }
resource "aws_iam_role_policy" "hcptf_apply_ecs" { # Customer-managed: the apply role already has two inlines (scoped-iam +
name = "afterhours-shift-manager-ecs" # services). A third PutRolePolicy exceeds the 10KB combined inline limit
role = aws_iam_role.hcptf_apply.id # in seahaven-prod. CreatePolicy still needs the hcptf-bootstrap window.
policy = data.aws_iam_policy_document.hcptf_apply_ecs.json resource "aws_iam_policy" "hcptf_apply_ecs" {
name = "afterhours-shift-manager-ecs"
path = "/tf-managed/"
description = "ECS, ALB, ECR, SQS, and VPC permissions for hcptf-afterhours-shift-manager"
policy = data.aws_iam_policy_document.hcptf_apply_ecs.json
} }
resource "aws_iam_role_policy" "hcptf_plan_refresh" { resource "aws_iam_role_policy" "hcptf_plan_refresh" {
@ -1104,8 +1108,10 @@ resource "aws_iam_role_policy_attachment" "hcptf_plan_view_only" {
} }
resource "aws_iam_role_policy_attachments_exclusive" "hcptf_apply" { resource "aws_iam_role_policy_attachments_exclusive" "hcptf_apply" {
role_name = aws_iam_role.hcptf_apply.name role_name = aws_iam_role.hcptf_apply.name
policy_arns = [] policy_arns = [
aws_iam_policy.hcptf_apply_ecs.arn,
]
} }
resource "aws_iam_role_policy_attachments_exclusive" "hcptf_plan" { resource "aws_iam_role_policy_attachments_exclusive" "hcptf_plan" {

View file

@ -14,7 +14,7 @@ resource "aws_vpc" "this" {
# First apply updates the live hcptf apply role before CreateVpc. # First apply updates the live hcptf apply role before CreateVpc.
depends_on = [ depends_on = [
aws_iam_role_policy.hcptf_apply_services, aws_iam_role_policy.hcptf_apply_services,
aws_iam_role_policy.hcptf_apply_ecs, aws_iam_role_policy_attachments_exclusive.hcptf_apply,
] ]
} }

View file

@ -83,6 +83,9 @@ def test_stack_owns_a_vpc_instead_of_looking_up_default():
assert "sid = \"RefreshVpc\"" in HCP_IAM assert "sid = \"RefreshVpc\"" in HCP_IAM
assert "afterhours-shift-manager-ecs" in HCP_IAM assert "afterhours-shift-manager-ecs" in HCP_IAM
assert "hcptf_apply_ecs" in HCP_IAM assert "hcptf_apply_ecs" in HCP_IAM
assert 'resource "aws_iam_policy" "hcptf_apply_ecs"' in HCP_IAM
assert 'resource "aws_iam_role_policy" "hcptf_apply_ecs"' not in HCP_IAM
assert "aws_iam_policy.hcptf_apply_ecs.arn" in HCP_IAM
def test_ecs_task_boundary_uses_static_arns(): def test_ecs_task_boundary_uses_static_arns():