diff --git a/terraform/iam_github_weekly_menu.tf b/terraform/iam_github_weekly_menu.tf index ce2b122..4596b22 100644 --- a/terraform/iam_github_weekly_menu.tf +++ b/terraform/iam_github_weekly_menu.tf @@ -43,14 +43,22 @@ data "aws_iam_policy_document" "weekly_menu_assume" { } resource "aws_iam_role" "weekly_menu" { - name = "githubdeploy-meal-order-manager-weekly-menu" - path = "/tf-managed/" - description = "GitHub Actions weekly-menu scrape/publish for meal-order-manager" - # Not a Lambda execution role. Do not attach seahaven-lambda-execution-boundary - # (PLAT-52). HCP apply cannot DeleteRolePermissionsBoundary (DenyBoundaryTampering); - # stripping the live attachment is an administrator action after this apply. + name = "githubdeploy-meal-order-manager-weekly-menu" + path = "/tf-managed/" + description = "GitHub Actions weekly-menu scrape/publish for meal-order-manager" assume_role_policy = data.aws_iam_policy_document.weekly_menu_assume.json max_session_duration = 3600 + + # Not a Lambda execution role. Config omits permissions_boundary so a later + # apply will not PutRolePermissionsBoundary the Lambda ceiling back. Live still + # has seahaven-lambda-execution-boundary; omitting without ignore_changes would + # plan DeleteRolePermissionsBoundary, which hcptf-meal-order-manager is denied + # (DenyBoundaryTampering). Ignore the attribute so this apply does not touch + # the ceiling. An administrator deletes the live attachment, then a follow-up + # drops this lifecycle after refresh-only updates state to null. + lifecycle { + ignore_changes = [permissions_boundary] + } } data "aws_iam_policy_document" "weekly_menu" {