mirror of
https://github.com/Sea-Haven-Industries/afterhours-shift-manager.git
synced 2026-09-30 03:23:12 +00:00
fix(infra): match live githubdeploy OIDC and plan-role S3 Gets (PLAT-74) (#253)
Some checks are pending
Deploy / Deploy to prod (push) Waiting to run
Some checks are pending
Deploy / Deploy to prod (push) Waiting to run
* fix(infra): match live githubdeploy OIDC and plan-role S3 Gets (PLAT-74) * fix(infra): pin githubdeploy job_workflow_ref to main (PLAT-74)
This commit is contained in:
parent
13350b72d0
commit
7a513b30ca
3 changed files with 37 additions and 19 deletions
|
|
@ -622,26 +622,33 @@ data "aws_iam_policy_document" "hcptf_plan_refresh" {
|
|||
sid = "RefreshBuckets"
|
||||
effect = "Allow"
|
||||
actions = [
|
||||
"s3:GetBucketLocation",
|
||||
"s3:GetAccelerateConfiguration",
|
||||
"s3:GetAnalyticsConfiguration",
|
||||
"s3:GetBucketAcl",
|
||||
"s3:GetBucketPolicy",
|
||||
"s3:GetBucketPolicyStatus",
|
||||
"s3:GetBucketPublicAccessBlock",
|
||||
"s3:GetBucketVersioning",
|
||||
"s3:GetBucketLifecycleConfiguration",
|
||||
"s3:GetBucketTagging",
|
||||
"s3:GetBucketOwnershipControls",
|
||||
"s3:GetEncryptionConfiguration",
|
||||
"s3:GetBucketCORS",
|
||||
"s3:GetBucketLifecycleConfiguration",
|
||||
"s3:GetBucketLocation",
|
||||
"s3:GetBucketLogging",
|
||||
"s3:GetBucketNotification",
|
||||
"s3:GetBucketObjectLockConfiguration",
|
||||
"s3:GetBucketOwnershipControls",
|
||||
"s3:GetBucketPolicy",
|
||||
"s3:GetBucketPolicyStatus",
|
||||
"s3:GetBucketPublicAccessBlock",
|
||||
"s3:GetBucketReplication",
|
||||
"s3:GetBucketRequestPayment",
|
||||
"s3:GetBucketTagging",
|
||||
"s3:GetBucketVersioning",
|
||||
"s3:GetBucketWebsite",
|
||||
"s3:GetAccelerateConfiguration",
|
||||
"s3:GetEncryptionConfiguration",
|
||||
"s3:GetIntelligentTieringConfiguration",
|
||||
"s3:GetInventoryConfiguration",
|
||||
"s3:GetLifecycleConfiguration",
|
||||
"s3:GetMetricsConfiguration",
|
||||
"s3:GetObject",
|
||||
"s3:GetObjectVersion",
|
||||
"s3:GetObjectTagging",
|
||||
"s3:GetObjectVersion",
|
||||
"s3:GetReplicationConfiguration",
|
||||
"s3:ListBucket",
|
||||
]
|
||||
resources = [
|
||||
|
|
|
|||
|
|
@ -1,9 +1,10 @@
|
|||
# GitHub Actions OIDC role for .github/workflows/deploy.yaml.
|
||||
#
|
||||
# Trust is pinned three ways: aud, sub to Environment prod (immutable subject
|
||||
# form), and job_workflow_ref to deploy.yaml at refs/heads/main only. No v*
|
||||
# tags until a later release ticket. A job with environment: does not present
|
||||
# ref:refs/heads/main.
|
||||
# Trust is pinned three ways: aud, sub to Environment prod (immutable and
|
||||
# classic subject forms), and job_workflow_ref to deploy.yaml at
|
||||
# refs/heads/main only. Live GitHub Actions presented the classic sub; both
|
||||
# forms are listed. No v* tags until a later release ticket. A job with
|
||||
# environment: does not present ref:refs/heads/main.
|
||||
#
|
||||
# Not a Lambda execution role: no permissions_boundary. Path /tf-managed/ so
|
||||
# seahaven-hcptf-iam-management DenySelfMutation (role/githubdeploy-*) does not
|
||||
|
|
@ -29,7 +30,10 @@ data "aws_iam_policy_document" "github_deploy_assume" {
|
|||
condition {
|
||||
test = "StringEquals"
|
||||
variable = "token.actions.githubusercontent.com:sub"
|
||||
values = [local.github_oidc_sub]
|
||||
values = [
|
||||
local.github_oidc_sub,
|
||||
"repo:${var.github_repo}:environment:prod",
|
||||
]
|
||||
}
|
||||
|
||||
condition {
|
||||
|
|
|
|||
|
|
@ -85,8 +85,15 @@ def test_weekly_post_role_is_tf_managed_name():
|
|||
assert 'role_name = "afterhours-shift-manager-weekly-post"' in LOCALS
|
||||
|
||||
|
||||
def test_github_deploy_trust_is_main_only():
|
||||
def test_github_deploy_trust_is_environment_prod():
|
||||
iam = (TERRAFORM / "iam_github_deploy.tf").read_text()
|
||||
assert "refs/heads/${var.github_deploy_branch}" in iam
|
||||
assert "refs/tags/v*" not in iam
|
||||
assert "environment:prod" in iam or "environment:prod" in LOCALS
|
||||
assert "deploy.yaml@refs/heads/${var.github_deploy_branch}" in iam
|
||||
assert "deploy.yaml@*" not in iam
|
||||
assert "refs/tags/v*" not in iam
|
||||
|
||||
|
||||
def test_plan_refresh_includes_provider6_s3_gets():
|
||||
assert "s3:GetLifecycleConfiguration" in HCP_IAM
|
||||
assert "s3:GetReplicationConfiguration" in HCP_IAM
|
||||
assert "s3:GetBucketReplication" in HCP_IAM
|
||||
|
|
|
|||
Loading…
Add table
Reference in a new issue