mirror of
https://github.com/Sea-Haven-Industries/meal-order-manager.git
synced 2026-10-05 07:11:59 +00:00
Merge pull request #135 from Sea-Haven-Industries/fix/weekly-menu-oidc-arn-literal
fix(iam): literal GitHub OIDC ARN for weekly-menu role (PLAT-100)
This commit is contained in:
commit
24b2aaa70f
1 changed files with 6 additions and 3 deletions
|
|
@ -4,9 +4,12 @@
|
||||||
# weekly-menu workflow at main) so no other workflow in the repo can assume it.
|
# weekly-menu workflow at main) so no other workflow in the repo can assume it.
|
||||||
# Permissions mirror the mgmt github-oidc-deploy-roles weekly-menu role, retargeted
|
# Permissions mirror the mgmt github-oidc-deploy-roles weekly-menu role, retargeted
|
||||||
# to prod resources and without form-api-key (SigV4 publish path).
|
# to prod resources and without form-api-key (SigV4 publish path).
|
||||||
|
#
|
||||||
|
# OIDC provider ARN is literal (not a data source): hcptf-meal-order-manager-plan
|
||||||
|
# lacks iam:GetOpenIDConnectProvider, and the provider is account-stable.
|
||||||
|
|
||||||
data "aws_iam_openid_connect_provider" "github" {
|
locals {
|
||||||
url = "https://token.actions.githubusercontent.com"
|
github_oidc_provider_arn = "arn:aws:iam::${local.account_id}:oidc-provider/token.actions.githubusercontent.com"
|
||||||
}
|
}
|
||||||
|
|
||||||
data "aws_iam_policy_document" "weekly_menu_assume" {
|
data "aws_iam_policy_document" "weekly_menu_assume" {
|
||||||
|
|
@ -16,7 +19,7 @@ data "aws_iam_policy_document" "weekly_menu_assume" {
|
||||||
|
|
||||||
principals {
|
principals {
|
||||||
type = "Federated"
|
type = "Federated"
|
||||||
identifiers = [data.aws_iam_openid_connect_provider.github.arn]
|
identifiers = [local.github_oidc_provider_arn]
|
||||||
}
|
}
|
||||||
|
|
||||||
condition {
|
condition {
|
||||||
|
|
|
||||||
Loading…
Add table
Reference in a new issue