fix(infra): match live githubdeploy OIDC and plan-role S3 Gets (PLAT-74) (#253)
Some checks are pending
Deploy / Deploy to prod (push) Waiting to run

* fix(infra): match live githubdeploy OIDC and plan-role S3 Gets (PLAT-74)

* fix(infra): pin githubdeploy job_workflow_ref to main (PLAT-74)
This commit is contained in:
Adam Moussa 2026-09-16 00:48:37 +00:00 • committed by GitHub
parent 13350b72d0
commit 7a513b30ca
No known key found for this signature in database
GPG key ID: B5690EEEBB952194
3 changed files with 37 additions and 19 deletions

View file

@ -622,26 +622,33 @@ data "aws_iam_policy_document" "hcptf_plan_refresh" {
sid = "RefreshBuckets"
effect = "Allow"
actions = [
"s3:GetBucketLocation",
"s3:GetAccelerateConfiguration",
"s3:GetAnalyticsConfiguration",
"s3:GetBucketAcl",
"s3:GetBucketPolicy",
"s3:GetBucketPolicyStatus",
"s3:GetBucketPublicAccessBlock",
"s3:GetBucketVersioning",
"s3:GetBucketLifecycleConfiguration",
"s3:GetBucketTagging",
"s3:GetBucketOwnershipControls",
"s3:GetEncryptionConfiguration",
"s3:GetBucketCORS",
"s3:GetBucketLifecycleConfiguration",
"s3:GetBucketLocation",
"s3:GetBucketLogging",
"s3:GetBucketNotification",
"s3:GetBucketObjectLockConfiguration",
"s3:GetBucketOwnershipControls",
"s3:GetBucketPolicy",
"s3:GetBucketPolicyStatus",
"s3:GetBucketPublicAccessBlock",
"s3:GetBucketReplication",
"s3:GetBucketRequestPayment",
"s3:GetBucketTagging",
"s3:GetBucketVersioning",
"s3:GetBucketWebsite",
"s3:GetAccelerateConfiguration",
"s3:GetEncryptionConfiguration",
"s3:GetIntelligentTieringConfiguration",
"s3:GetInventoryConfiguration",
"s3:GetLifecycleConfiguration",
"s3:GetMetricsConfiguration",
"s3:GetObject",
"s3:GetObjectVersion",
"s3:GetObjectTagging",
"s3:GetObjectVersion",
"s3:GetReplicationConfiguration",
"s3:ListBucket",
]
resources = [

View file

@ -1,9 +1,10 @@
# GitHub Actions OIDC role for .github/workflows/deploy.yaml.
#
# Trust is pinned three ways: aud, sub to Environment prod (immutable subject
# form), and job_workflow_ref to deploy.yaml at refs/heads/main only. No v*
# tags until a later release ticket. A job with environment: does not present
# ref:refs/heads/main.
# Trust is pinned three ways: aud, sub to Environment prod (immutable and
# classic subject forms), and job_workflow_ref to deploy.yaml at
# refs/heads/main only. Live GitHub Actions presented the classic sub; both
# forms are listed. No v* tags until a later release ticket. A job with
# environment: does not present ref:refs/heads/main.
#
# Not a Lambda execution role: no permissions_boundary. Path /tf-managed/ so
# seahaven-hcptf-iam-management DenySelfMutation (role/githubdeploy-*) does not
@ -29,7 +30,10 @@ data "aws_iam_policy_document" "github_deploy_assume" {
condition {
test = "StringEquals"
variable = "token.actions.githubusercontent.com:sub"
values = [local.github_oidc_sub]
values = [
local.github_oidc_sub,
"repo:${var.github_repo}:environment:prod",
]
}
condition {

View file

@ -85,8 +85,15 @@ def test_weekly_post_role_is_tf_managed_name():
assert 'role_name = "afterhours-shift-manager-weekly-post"' in LOCALS
def test_github_deploy_trust_is_main_only():
def test_github_deploy_trust_is_environment_prod():
iam = (TERRAFORM / "iam_github_deploy.tf").read_text()
assert "refs/heads/${var.github_deploy_branch}" in iam
assert "refs/tags/v*" not in iam
assert "environment:prod" in iam or "environment:prod" in LOCALS
assert "deploy.yaml@refs/heads/${var.github_deploy_branch}" in iam
assert "deploy.yaml@*" not in iam
assert "refs/tags/v*" not in iam
def test_plan_refresh_includes_provider6_s3_gets():
assert "s3:GetLifecycleConfiguration" in HCP_IAM
assert "s3:GetReplicationConfiguration" in HCP_IAM
assert "s3:GetBucketReplication" in HCP_IAM