diff --git a/terraform/hcp_iam.tf b/terraform/hcp_iam.tf new file mode 100644 index 0000000..5b323d9 --- /dev/null +++ b/terraform/hcp_iam.tf @@ -0,0 +1,510 @@ +# HCP plan/apply roles imported from seahaven-terraform-substrate (PLAT-146). +# Import, do not recreate. Role names stay hcptf-front-integrations / hcptf-front-integrations-plan. +# +# Live seahaven-hcptf-iam-management DenySelfMutation blocks DetachRolePolicy +# and PutRolePolicy on hcptf-* (including this role). Import apply sequence: +# 1. seahaven-org-baseline scripts/create-hcptf-bootstrap-roles.sh +# --account prod --allow-workspace front-integrations-prod +# 2. Point this workspace's TFC_AWS_* at hcptf-bootstrap / +# hcptf-bootstrap-plan (workspace vars, never a project set). +# 3. One Manual apply (import + detach seahaven-hcptf-iam-management + +# put scoped inline). +# 4. Point TFC_AWS_* back at hcptf-front-integrations / hcptf-front-integrations-plan. +# 5. Re-run the script without --allow-workspace to pin trust back to +# iam-bootstrap-prod only. +# seahaven-lambda-execution-boundary remains seahaven-lambda-execution-boundary-front-integrations. + +import { + to = aws_iam_role.hcptf_apply + id = "hcptf-front-integrations" +} + +import { + to = aws_iam_role.hcptf_plan + id = "hcptf-front-integrations-plan" +} + +import { + to = aws_iam_role_policy.hcptf_apply_services + id = "hcptf-front-integrations:front-integrations-services" +} + +import { + to = aws_iam_role_policy.hcptf_plan_refresh + id = "hcptf-front-integrations-plan:front-integrations-plan-refresh" +} + +import { + to = aws_iam_role_policy_attachments_exclusive.hcptf_apply + id = "hcptf-front-integrations" +} + +import { + to = aws_iam_role_policy_attachment.hcptf_plan_viewonly + id = "hcptf-front-integrations-plan/arn:aws:iam::aws:policy/job-function/ViewOnlyAccess" +} + +import { + to = aws_iam_role_policy_attachments_exclusive.hcptf_plan + id = "hcptf-front-integrations-plan" +} + +data "aws_iam_policy_document" "hcptf_apply_trust" { + statement { + sid = "HcpApply" + effect = "Allow" + actions = ["sts:AssumeRoleWithWebIdentity"] + + principals { + type = "Federated" + identifiers = ["arn:aws:iam::${local.account_id}:oidc-provider/app.terraform.io"] + } + + condition { + test = "StringEquals" + variable = "app.terraform.io:aud" + values = ["aws.workload.identity"] + } + + condition { + test = "StringEquals" + variable = "app.terraform.io:sub" + values = [ + "organization:seahaven:project:seahaven-prod:workspace:front-integrations-prod:run_phase:apply", + ] + } + } +} + +data "aws_iam_policy_document" "hcptf_plan_trust" { + statement { + sid = "HcpPlan" + effect = "Allow" + actions = ["sts:AssumeRoleWithWebIdentity"] + + principals { + type = "Federated" + identifiers = ["arn:aws:iam::${local.account_id}:oidc-provider/app.terraform.io"] + } + + condition { + test = "StringEquals" + variable = "app.terraform.io:aud" + values = ["aws.workload.identity"] + } + + condition { + test = "StringEquals" + variable = "app.terraform.io:sub" + values = [ + "organization:seahaven:project:seahaven-prod:workspace:front-integrations-prod:run_phase:plan", + ] + } + } +} + +data "aws_iam_policy_document" "hcptf_scoped_iam" { + statement { + sid = "DenyCreatePolicy" + effect = "Deny" + actions = ["iam:CreatePolicy", "iam:CreatePolicyVersion"] + resources = ["*"] + } + + statement { + sid = "CreateExecRoleWithBoundary" + effect = "Allow" + actions = ["iam:CreateRole"] + resources = ["arn:aws:iam::${local.account_id}:role/tf-managed/front-*"] + + condition { + test = "StringLike" + variable = "iam:PermissionsBoundary" + values = [ + "arn:aws:iam::${local.account_id}:policy/tf-managed/front-*", + "arn:aws:iam::${local.account_id}:policy/seahaven-lambda-execution-boundary-front-integrations" + ] + } + } + + statement { + sid = "MutateExecRoleWithBoundary" + effect = "Allow" + actions = [ + "iam:AttachRolePolicy", + "iam:PutRolePolicy", + "iam:PutRolePermissionsBoundary", + ] + resources = ["arn:aws:iam::${local.account_id}:role/tf-managed/front-*"] + + condition { + test = "StringLike" + variable = "iam:PermissionsBoundary" + values = [ + "arn:aws:iam::${local.account_id}:policy/tf-managed/front-*", + "arn:aws:iam::${local.account_id}:policy/seahaven-lambda-execution-boundary-front-integrations" + ] + } + } + + statement { + sid = "WriteExecRoles" + effect = "Allow" + actions = [ + "iam:DeleteRole", + "iam:DeleteRolePolicy", + "iam:DetachRolePolicy", + "iam:TagRole", + "iam:UntagRole", + "iam:UpdateAssumeRolePolicy", + "iam:UpdateRole", + "iam:UpdateRoleDescription", + ] + resources = ["arn:aws:iam::${local.account_id}:role/tf-managed/front-*"] + } + + statement { + sid = "PassExecRolesToLambda" + effect = "Allow" + actions = ["iam:PassRole"] + resources = ["arn:aws:iam::${local.account_id}:role/tf-managed/front-*"] + + condition { + test = "StringEquals" + variable = "iam:PassedToService" + values = ["lambda.amazonaws.com"] + } + } + + statement { + sid = "IamReadOnly" + effect = "Allow" + actions = [ + "iam:GetPolicy", + "iam:GetPolicyVersion", + "iam:GetRole", + "iam:GetRolePolicy", + "iam:ListAttachedRolePolicies", + "iam:ListPolicies", + "iam:ListPolicyVersions", + "iam:ListRolePolicies", + "iam:ListRoles", + ] + resources = ["*"] + } + + statement { + sid = "DenySelfMutation" + effect = "Deny" + actions = [ + "iam:AttachRolePolicy", + "iam:DeleteRole", + "iam:DeleteRolePolicy", + "iam:DeleteRolePermissionsBoundary", + "iam:DetachRolePolicy", + "iam:PutRolePolicy", + "iam:PutRolePermissionsBoundary", + "iam:UpdateAssumeRolePolicy", + "iam:UpdateRole", + "iam:UpdateRoleDescription", + ] + resources = [ + "arn:aws:iam::${local.account_id}:role/hcptf-*", + "arn:aws:iam::${local.account_id}:role/github-cfn-execution-role", + "arn:aws:iam::${local.account_id}:role/githubdeploy-*", + "arn:aws:iam::${local.account_id}:role/cdk-hnb659fds-*", + "arn:aws:iam::${local.account_id}:role/OrganizationAccountAccessRole", + "arn:aws:iam::${local.account_id}:role/seahaven-*", + ] + } + + statement { + sid = "DenyBoundaryTampering" + effect = "Deny" + actions = [ + "iam:DeleteRolePermissionsBoundary", + "iam:DeleteUserPermissionsBoundary", + ] + resources = [ + "arn:aws:iam::${local.account_id}:role/*", + "arn:aws:iam::${local.account_id}:user/*", + ] + } + + statement { + sid = "DenyBoundaryPolicyEdit" + effect = "Deny" + actions = [ + "iam:CreatePolicyVersion", + "iam:DeletePolicy", + "iam:DeletePolicyVersion", + "iam:SetDefaultPolicyVersion", + ] + resources = ["arn:aws:iam::${local.account_id}:policy/seahaven-*"] + } +} + +resource "aws_iam_role_policy" "hcptf_apply_services" { + name = "front-integrations-services" + role = aws_iam_role.hcptf_apply.id + policy = jsonencode({ + Version = "2012-10-17" + Statement = [ + { + Action = [ + "lambda:*", + ] + Resource = [ + "arn:aws:lambda:us-east-1:${local.account_id}:function:front-*", + ] + Effect = "Allow" + Sid = "LambdaAll" + }, + { + Action = [ + "lambda:ListFunctions", + "lambda:ListLayers", + "lambda:GetAccountSettings", + ] + Resource = "*" + Effect = "Allow" + Sid = "LambdaList" + }, + { + Action = [ + "events:*", + ] + Resource = [ + "arn:aws:events:us-east-1:${local.account_id}:rule/front-*", + ] + Effect = "Allow" + Sid = "EventBridgeRules" + }, + { + Action = [ + "logs:CreateLogGroup", + "logs:DeleteLogGroup", + "logs:PutRetentionPolicy", + "logs:DeleteRetentionPolicy", + "logs:TagResource", + "logs:UntagResource", + "logs:ListTagsForResource", + ] + Resource = [ + "arn:aws:logs:us-east-1:${local.account_id}:log-group:/aws/lambda/front-*", + ] + Effect = "Allow" + Sid = "CloudWatchLogs" + }, + { + Action = [ + "logs:DescribeLogGroups", + ] + Resource = "*" + Effect = "Allow" + Sid = "CloudWatchLogsDescribe" + }, + { + Action = [ + "s3:*", + ] + Resource = [ + "arn:aws:s3:::front-integrations-artifacts-${local.account_id}", + "arn:aws:s3:::front-integrations-artifacts-${local.account_id}/*", + ] + Effect = "Allow" + Sid = "LambdaArtifactsBucket" + }, + { + Action = [ + "dynamodb:*", + ] + Resource = [ + "arn:aws:dynamodb:us-east-1:${local.account_id}:table/front-sla-alerts", + "arn:aws:dynamodb:us-east-1:${local.account_id}:table/front-sla-alerts/index/*", + ] + Effect = "Allow" + Sid = "DynamoDBTable" + }, + { + Action = [ + "dynamodb:ListTables", + ] + Resource = "*" + Effect = "Allow" + Sid = "DynamoDBList" + }, + { + Action = [ + "cloudwatch:*", + ] + Resource = [ + "arn:aws:cloudwatch:us-east-1:${local.account_id}:alarm:front-*", + ] + Effect = "Allow" + Sid = "CloudWatchAlarms" + }, + { + Action = [ + "sns:Publish", + "sns:GetTopicAttributes", + ] + Resource = [ + "arn:aws:sns:us-east-1:${local.account_id}:site-alerts", + ] + Effect = "Allow" + Sid = "SiteAlertsSns" + }, + ] + }) +} + +resource "aws_iam_role_policy" "hcptf_plan_refresh" { + name = "front-integrations-plan-refresh" + role = aws_iam_role.hcptf_plan.id + policy = jsonencode({ + Version = "2012-10-17" + Statement = [ + { + Action = [ + "iam:GetRole", + "iam:GetRolePolicy", + "iam:ListRolePolicies", + "iam:ListAttachedRolePolicies", + ] + Resource = [ + "arn:aws:iam::${local.account_id}:role/tf-managed/front-*", + "arn:aws:iam::${local.account_id}:role/hcptf-front-integrations", + "arn:aws:iam::${local.account_id}:role/hcptf-front-integrations-plan", + ] + Effect = "Allow" + Sid = "RefreshIamRoles" + }, + { + Action = [ + "iam:GetPolicy", + "iam:GetPolicyVersion", + ] + Resource = "*" + Effect = "Allow" + Sid = "RefreshManagedPolicies" + }, + { + Action = [ + "events:DescribeRule", + "events:ListTargetsByRule", + "events:ListTagsForResource", + ] + Resource = [ + "arn:aws:events:us-east-1:${local.account_id}:rule/front-*", + ] + Effect = "Allow" + Sid = "RefreshEventBridge" + }, + { + Action = [ + "lambda:Get*", + "lambda:List*", + ] + Resource = [ + "arn:aws:lambda:us-east-1:${local.account_id}:function:front-*", + ] + Effect = "Allow" + Sid = "RefreshLambda" + }, + { + Action = [ + "s3:Get*", + "s3:ListBucket", + ] + Resource = [ + "arn:aws:s3:::front-integrations-artifacts-${local.account_id}", + "arn:aws:s3:::front-integrations-artifacts-${local.account_id}/*", + ] + Effect = "Allow" + Sid = "RefreshArtifactsBucket" + }, + { + Action = [ + "dynamodb:DescribeTable", + "dynamodb:DescribeTimeToLive", + "dynamodb:DescribeContinuousBackups", + "dynamodb:ListTagsOfResource", + ] + Resource = [ + "arn:aws:dynamodb:us-east-1:${local.account_id}:table/front-sla-alerts", + ] + Effect = "Allow" + Sid = "RefreshDynamoDB" + }, + { + Action = [ + "cloudwatch:DescribeAlarms", + "cloudwatch:ListTagsForResource", + ] + Resource = [ + "arn:aws:cloudwatch:us-east-1:${local.account_id}:alarm:front-*", + ] + Effect = "Allow" + Sid = "RefreshCloudWatchAlarms" + }, + { + Action = [ + "logs:DescribeLogGroups", + "logs:ListTagsForResource", + ] + Resource = "*" + Effect = "Allow" + Sid = "RefreshLogs" + }, + ] + }) +} + +resource "aws_iam_role" "hcptf_apply" { + name = "hcptf-front-integrations" + assume_role_policy = data.aws_iam_policy_document.hcptf_apply_trust.json + max_session_duration = 3600 + + tags = { + Project = "front-integrations" + Owner = "adam@seahavenind.com" + ManagedBy = "terraform" + } +} + +# Empty exclusive set keeps seahaven-hcptf-iam-management detached. +resource "aws_iam_role_policy_attachments_exclusive" "hcptf_apply" { + role_name = aws_iam_role.hcptf_apply.name + policy_arns = [] +} + +resource "aws_iam_role" "hcptf_plan" { + name = "hcptf-front-integrations-plan" + assume_role_policy = data.aws_iam_policy_document.hcptf_plan_trust.json + max_session_duration = 3600 + + tags = { + Project = "front-integrations" + Owner = "adam@seahavenind.com" + ManagedBy = "terraform" + } +} + +resource "aws_iam_role_policy_attachment" "hcptf_plan_viewonly" { + role = aws_iam_role.hcptf_plan.name + policy_arn = "arn:aws:iam::aws:policy/job-function/ViewOnlyAccess" +} + +resource "aws_iam_role_policy_attachments_exclusive" "hcptf_plan" { + role_name = aws_iam_role.hcptf_plan.name + policy_arns = [ + aws_iam_role_policy_attachment.hcptf_plan_viewonly.policy_arn, + ] +} + +resource "aws_iam_role_policy" "hcptf_scoped_iam" { + name = "scoped-iam-management" + role = aws_iam_role.hcptf_apply.id + policy = data.aws_iam_policy_document.hcptf_scoped_iam.json +}