From 1519264da15ceb9c5e637f3f17de78114c902fd3 Mon Sep 17 00:00:00 2001 From: Adam Moussa Date: Mon, 10 Aug 2026 16:12:40 -0400 Subject: [PATCH] fix(iam): use literal GitHub OIDC provider ARN for weekly-menu role --- terraform/iam_github_weekly_menu.tf | 9 ++++++--- 1 file changed, 6 insertions(+), 3 deletions(-) diff --git a/terraform/iam_github_weekly_menu.tf b/terraform/iam_github_weekly_menu.tf index dd2cefc..21001f2 100644 --- a/terraform/iam_github_weekly_menu.tf +++ b/terraform/iam_github_weekly_menu.tf @@ -4,9 +4,12 @@ # weekly-menu workflow at main) so no other workflow in the repo can assume it. # Permissions mirror the mgmt github-oidc-deploy-roles weekly-menu role, retargeted # to prod resources and without form-api-key (SigV4 publish path). +# +# OIDC provider ARN is literal (not a data source): hcptf-meal-order-manager-plan +# lacks iam:GetOpenIDConnectProvider, and the provider is account-stable. -data "aws_iam_openid_connect_provider" "github" { - url = "https://token.actions.githubusercontent.com" +locals { + github_oidc_provider_arn = "arn:aws:iam::${local.account_id}:oidc-provider/token.actions.githubusercontent.com" } data "aws_iam_policy_document" "weekly_menu_assume" { @@ -16,7 +19,7 @@ data "aws_iam_policy_document" "weekly_menu_assume" { principals { type = "Federated" - identifiers = [data.aws_iam_openid_connect_provider.github.arn] + identifiers = [local.github_oidc_provider_arn] } condition {