diff --git a/terraform/iam_github_deploy.tf b/terraform/iam_github_deploy.tf index 0e90025..c255e83 100644 --- a/terraform/iam_github_deploy.tf +++ b/terraform/iam_github_deploy.tf @@ -1,10 +1,10 @@ # GitHub Actions OIDC role for .github/workflows/deploy.yaml. # # Trust is pinned three ways: aud, sub to Environment prod (immutable and -# classic subject forms), and job_workflow_ref to deploy.yaml. Live GitHub -# Actions OIDC presented the classic sub and a job_workflow_ref that did not -# match StringEquals on refs/heads/main, so sub is StringLike for both forms -# and job_workflow_ref is StringLike deploy.yaml@*. +# classic subject forms), and job_workflow_ref to deploy.yaml at +# refs/heads/main only. Live GitHub Actions presented the classic sub; both +# forms are listed. No v* tags until a later release ticket. A job with +# environment: does not present ref:refs/heads/main. # # Not a Lambda execution role: no permissions_boundary. Path /tf-managed/ so # seahaven-hcptf-iam-management DenySelfMutation (role/githubdeploy-*) does not @@ -28,7 +28,7 @@ data "aws_iam_policy_document" "github_deploy_assume" { } condition { - test = "StringLike" + test = "StringEquals" variable = "token.actions.githubusercontent.com:sub" values = [ local.github_oidc_sub, @@ -37,10 +37,10 @@ data "aws_iam_policy_document" "github_deploy_assume" { } condition { - test = "StringLike" + test = "StringEquals" variable = "token.actions.githubusercontent.com:job_workflow_ref" values = [ - "${var.github_repo}/.github/workflows/deploy.yaml@*", + "${var.github_repo}/.github/workflows/deploy.yaml@refs/heads/${var.github_deploy_branch}", ] } } diff --git a/tests/infra/test_hcp_contract.py b/tests/infra/test_hcp_contract.py index 26363d8..5f5cb9b 100644 --- a/tests/infra/test_hcp_contract.py +++ b/tests/infra/test_hcp_contract.py @@ -88,7 +88,8 @@ def test_weekly_post_role_is_tf_managed_name(): def test_github_deploy_trust_is_environment_prod(): iam = (TERRAFORM / "iam_github_deploy.tf").read_text() assert "environment:prod" in iam or "environment:prod" in LOCALS - assert "deploy.yaml@*" in iam + assert "deploy.yaml@refs/heads/${var.github_deploy_branch}" in iam + assert "deploy.yaml@*" not in iam assert "refs/tags/v*" not in iam