mirror of
https://github.com/Sea-Haven-Industries/afterhours-shift-manager.git
synced 2026-09-30 05:33:12 +00:00
Point release-notify invoke role trust at deploy.yaml (#113)
The release job moved from release.yaml into deploy.yaml to clear CodeQL's workflow_run findings, but the OIDC invoke role's trust still pinned job_workflow_ref to release.yaml. That denied the AssumeRole at the release job's Configure-AWS step, so the v1.10.0 announcement never fired. Point the condition at deploy.yaml (the inline release job's top-level workflow) so the token's job_workflow_ref matches.
This commit is contained in:
parent
53c85f7eed
commit
8e90d41b6c
1 changed files with 4 additions and 3 deletions
|
|
@ -300,9 +300,10 @@ Resources:
|
|||
token.actions.githubusercontent.com:aud: sts.amazonaws.com
|
||||
StringLike:
|
||||
token.actions.githubusercontent.com:sub: "repo:Sea-Haven-Industries/afterhours-shift-manager:ref:refs/heads/main"
|
||||
# Defense-in-depth: only the release workflow may assume this role,
|
||||
# not any workflow running on main.
|
||||
token.actions.githubusercontent.com:job_workflow_ref: "Sea-Haven-Industries/afterhours-shift-manager/.github/workflows/release.yaml@refs/heads/main"
|
||||
# Defense-in-depth: only the Deploy workflow's release job may assume
|
||||
# this role, not any workflow running on main. (The release job lives
|
||||
# in deploy.yaml; this must match that workflow's path.)
|
||||
token.actions.githubusercontent.com:job_workflow_ref: "Sea-Haven-Industries/afterhours-shift-manager/.github/workflows/deploy.yaml@refs/heads/main"
|
||||
Policies:
|
||||
- PolicyName: invoke-release-notifier
|
||||
PolicyDocument:
|
||||
|
|
|
|||
Loading…
Add table
Reference in a new issue