fix(iam): use literal GitHub OIDC provider ARN for weekly-menu role

This commit is contained in:
Adam Moussa 2026-08-10 16:12:40 -04:00
parent 8fb1f51969
commit 1519264da1
No known key found for this signature in database

View file

@ -4,9 +4,12 @@
# weekly-menu workflow at main) so no other workflow in the repo can assume it.
# Permissions mirror the mgmt github-oidc-deploy-roles weekly-menu role, retargeted
# to prod resources and without form-api-key (SigV4 publish path).
#
# OIDC provider ARN is literal (not a data source): hcptf-meal-order-manager-plan
# lacks iam:GetOpenIDConnectProvider, and the provider is account-stable.
data "aws_iam_openid_connect_provider" "github" {
url = "https://token.actions.githubusercontent.com"
locals {
github_oidc_provider_arn = "arn:aws:iam::${local.account_id}:oidc-provider/token.actions.githubusercontent.com"
}
data "aws_iam_policy_document" "weekly_menu_assume" {
@ -16,7 +19,7 @@ data "aws_iam_policy_document" "weekly_menu_assume" {
principals {
type = "Federated"
identifiers = [data.aws_iam_openid_connect_provider.github.arn]
identifiers = [local.github_oidc_provider_arn]
}
condition {