mirror of
https://github.com/Sea-Haven-Industries/afterhours-shift-manager.git
synced 2026-10-05 20:02:04 +00:00
fix(infra): pin githubdeploy job_workflow_ref to main (PLAT-74)
This commit is contained in:
parent
d65d399c12
commit
b4aa4dbb13
2 changed files with 9 additions and 8 deletions
|
|
@ -1,10 +1,10 @@
|
||||||
# GitHub Actions OIDC role for .github/workflows/deploy.yaml.
|
# GitHub Actions OIDC role for .github/workflows/deploy.yaml.
|
||||||
#
|
#
|
||||||
# Trust is pinned three ways: aud, sub to Environment prod (immutable and
|
# Trust is pinned three ways: aud, sub to Environment prod (immutable and
|
||||||
# classic subject forms), and job_workflow_ref to deploy.yaml. Live GitHub
|
# classic subject forms), and job_workflow_ref to deploy.yaml at
|
||||||
# Actions OIDC presented the classic sub and a job_workflow_ref that did not
|
# refs/heads/main only. Live GitHub Actions presented the classic sub; both
|
||||||
# match StringEquals on refs/heads/main, so sub is StringLike for both forms
|
# forms are listed. No v* tags until a later release ticket. A job with
|
||||||
# and job_workflow_ref is StringLike deploy.yaml@*.
|
# environment: does not present ref:refs/heads/main.
|
||||||
#
|
#
|
||||||
# Not a Lambda execution role: no permissions_boundary. Path /tf-managed/ so
|
# Not a Lambda execution role: no permissions_boundary. Path /tf-managed/ so
|
||||||
# seahaven-hcptf-iam-management DenySelfMutation (role/githubdeploy-*) does not
|
# seahaven-hcptf-iam-management DenySelfMutation (role/githubdeploy-*) does not
|
||||||
|
|
@ -28,7 +28,7 @@ data "aws_iam_policy_document" "github_deploy_assume" {
|
||||||
}
|
}
|
||||||
|
|
||||||
condition {
|
condition {
|
||||||
test = "StringLike"
|
test = "StringEquals"
|
||||||
variable = "token.actions.githubusercontent.com:sub"
|
variable = "token.actions.githubusercontent.com:sub"
|
||||||
values = [
|
values = [
|
||||||
local.github_oidc_sub,
|
local.github_oidc_sub,
|
||||||
|
|
@ -37,10 +37,10 @@ data "aws_iam_policy_document" "github_deploy_assume" {
|
||||||
}
|
}
|
||||||
|
|
||||||
condition {
|
condition {
|
||||||
test = "StringLike"
|
test = "StringEquals"
|
||||||
variable = "token.actions.githubusercontent.com:job_workflow_ref"
|
variable = "token.actions.githubusercontent.com:job_workflow_ref"
|
||||||
values = [
|
values = [
|
||||||
"${var.github_repo}/.github/workflows/deploy.yaml@*",
|
"${var.github_repo}/.github/workflows/deploy.yaml@refs/heads/${var.github_deploy_branch}",
|
||||||
]
|
]
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
|
||||||
|
|
@ -88,7 +88,8 @@ def test_weekly_post_role_is_tf_managed_name():
|
||||||
def test_github_deploy_trust_is_environment_prod():
|
def test_github_deploy_trust_is_environment_prod():
|
||||||
iam = (TERRAFORM / "iam_github_deploy.tf").read_text()
|
iam = (TERRAFORM / "iam_github_deploy.tf").read_text()
|
||||||
assert "environment:prod" in iam or "environment:prod" in LOCALS
|
assert "environment:prod" in iam or "environment:prod" in LOCALS
|
||||||
assert "deploy.yaml@*" in iam
|
assert "deploy.yaml@refs/heads/${var.github_deploy_branch}" in iam
|
||||||
|
assert "deploy.yaml@*" not in iam
|
||||||
assert "refs/tags/v*" not in iam
|
assert "refs/tags/v*" not in iam
|
||||||
|
|
||||||
|
|
||||||
|
|
|
||||||
Loading…
Add table
Reference in a new issue