mirror of
https://github.com/Sea-Haven-Industries/afterhours-shift-manager.git
synced 2026-09-30 07:53:11 +00:00
fix(infra): pin githubdeploy job_workflow_ref to main (PLAT-74)
This commit is contained in:
parent
d65d399c12
commit
b4aa4dbb13
2 changed files with 9 additions and 8 deletions
|
|
@ -1,10 +1,10 @@
|
|||
# GitHub Actions OIDC role for .github/workflows/deploy.yaml.
|
||||
#
|
||||
# Trust is pinned three ways: aud, sub to Environment prod (immutable and
|
||||
# classic subject forms), and job_workflow_ref to deploy.yaml. Live GitHub
|
||||
# Actions OIDC presented the classic sub and a job_workflow_ref that did not
|
||||
# match StringEquals on refs/heads/main, so sub is StringLike for both forms
|
||||
# and job_workflow_ref is StringLike deploy.yaml@*.
|
||||
# classic subject forms), and job_workflow_ref to deploy.yaml at
|
||||
# refs/heads/main only. Live GitHub Actions presented the classic sub; both
|
||||
# forms are listed. No v* tags until a later release ticket. A job with
|
||||
# environment: does not present ref:refs/heads/main.
|
||||
#
|
||||
# Not a Lambda execution role: no permissions_boundary. Path /tf-managed/ so
|
||||
# seahaven-hcptf-iam-management DenySelfMutation (role/githubdeploy-*) does not
|
||||
|
|
@ -28,7 +28,7 @@ data "aws_iam_policy_document" "github_deploy_assume" {
|
|||
}
|
||||
|
||||
condition {
|
||||
test = "StringLike"
|
||||
test = "StringEquals"
|
||||
variable = "token.actions.githubusercontent.com:sub"
|
||||
values = [
|
||||
local.github_oidc_sub,
|
||||
|
|
@ -37,10 +37,10 @@ data "aws_iam_policy_document" "github_deploy_assume" {
|
|||
}
|
||||
|
||||
condition {
|
||||
test = "StringLike"
|
||||
test = "StringEquals"
|
||||
variable = "token.actions.githubusercontent.com:job_workflow_ref"
|
||||
values = [
|
||||
"${var.github_repo}/.github/workflows/deploy.yaml@*",
|
||||
"${var.github_repo}/.github/workflows/deploy.yaml@refs/heads/${var.github_deploy_branch}",
|
||||
]
|
||||
}
|
||||
}
|
||||
|
|
|
|||
|
|
@ -88,7 +88,8 @@ def test_weekly_post_role_is_tf_managed_name():
|
|||
def test_github_deploy_trust_is_environment_prod():
|
||||
iam = (TERRAFORM / "iam_github_deploy.tf").read_text()
|
||||
assert "environment:prod" in iam or "environment:prod" in LOCALS
|
||||
assert "deploy.yaml@*" in iam
|
||||
assert "deploy.yaml@refs/heads/${var.github_deploy_branch}" in iam
|
||||
assert "deploy.yaml@*" not in iam
|
||||
assert "refs/tags/v*" not in iam
|
||||
|
||||
|
||||
|
|
|
|||
Loading…
Add table
Reference in a new issue