mirror of
https://github.com/Sea-Haven-Industries/meal-order-manager.git
synced 2026-09-30 12:23:13 +00:00
fix(iam): skip boundary delete on weekly-menu role (PLAT-52)
This commit is contained in:
parent
b91d7f3745
commit
5af7a3b0dd
1 changed files with 14 additions and 6 deletions
|
|
@ -43,14 +43,22 @@ data "aws_iam_policy_document" "weekly_menu_assume" {
|
|||
}
|
||||
|
||||
resource "aws_iam_role" "weekly_menu" {
|
||||
name = "githubdeploy-meal-order-manager-weekly-menu"
|
||||
path = "/tf-managed/"
|
||||
description = "GitHub Actions weekly-menu scrape/publish for meal-order-manager"
|
||||
# Not a Lambda execution role. Do not attach seahaven-lambda-execution-boundary
|
||||
# (PLAT-52). HCP apply cannot DeleteRolePermissionsBoundary (DenyBoundaryTampering);
|
||||
# stripping the live attachment is an administrator action after this apply.
|
||||
name = "githubdeploy-meal-order-manager-weekly-menu"
|
||||
path = "/tf-managed/"
|
||||
description = "GitHub Actions weekly-menu scrape/publish for meal-order-manager"
|
||||
assume_role_policy = data.aws_iam_policy_document.weekly_menu_assume.json
|
||||
max_session_duration = 3600
|
||||
|
||||
# Not a Lambda execution role. Config omits permissions_boundary so a later
|
||||
# apply will not PutRolePermissionsBoundary the Lambda ceiling back. Live still
|
||||
# has seahaven-lambda-execution-boundary; omitting without ignore_changes would
|
||||
# plan DeleteRolePermissionsBoundary, which hcptf-meal-order-manager is denied
|
||||
# (DenyBoundaryTampering). Ignore the attribute so this apply does not touch
|
||||
# the ceiling. An administrator deletes the live attachment, then a follow-up
|
||||
# drops this lifecycle after refresh-only updates state to null.
|
||||
lifecycle {
|
||||
ignore_changes = [permissions_boundary]
|
||||
}
|
||||
}
|
||||
|
||||
data "aws_iam_policy_document" "weekly_menu" {
|
||||
|
|
|
|||
Loading…
Add table
Reference in a new issue