Merge pull request #135 from Sea-Haven-Industries/fix/weekly-menu-oidc-arn-literal

fix(iam): literal GitHub OIDC ARN for weekly-menu role (PLAT-100)
This commit is contained in:
Adam Moussa 2026-08-10 16:15:08 -04:00 • committed by GitHub
commit 24b2aaa70f
No known key found for this signature in database
GPG key ID: B5690EEEBB952194

View file

@ -4,9 +4,12 @@
# weekly-menu workflow at main) so no other workflow in the repo can assume it.
# Permissions mirror the mgmt github-oidc-deploy-roles weekly-menu role, retargeted
# to prod resources and without form-api-key (SigV4 publish path).
#
# OIDC provider ARN is literal (not a data source): hcptf-meal-order-manager-plan
# lacks iam:GetOpenIDConnectProvider, and the provider is account-stable.
data "aws_iam_openid_connect_provider" "github" {
url = "https://token.actions.githubusercontent.com"
locals {
github_oidc_provider_arn = "arn:aws:iam::${local.account_id}:oidc-provider/token.actions.githubusercontent.com"
}
data "aws_iam_policy_document" "weekly_menu_assume" {
@ -16,7 +19,7 @@ data "aws_iam_policy_document" "weekly_menu_assume" {
principals {
type = "Federated"
identifiers = [data.aws_iam_openid_connect_provider.github.arn]
identifiers = [local.github_oidc_provider_arn]
}
condition {