diff --git a/.security-review/suppressions.json b/.security-review/suppressions.json index 3410db8..151c05b 100644 --- a/.security-review/suppressions.json +++ b/.security-review/suppressions.json @@ -9,8 +9,8 @@ "justification": "The meals API ALB is the CloudFront HTTP origin for orders.seahaven.com. TLS and WAF terminate at CloudFront. Restricting the security group to the CloudFront managed prefix list would block GitHub-hosted weekly-menu HMAC publish, which must call the origin with X-Meals-Publish-Key. Application gates are HMAC on /api/publish, Cognito or Google Bearer on admin, and public submit only. Accepted as the HTTP-origin design for PLAT-215; TLS on the ALB is a follow-up." }, { - "id": "checkov-CKV_AWS_111-49", - "justification": "LINE SHIFT ONLY: the OIDC dual-claim change adds a workflow_ref condition and retargets job_workflow_ref, shifting github_deploy from 40 to 49. The permission document is unchanged. Original justification: githubdeploy-meal-order-manager needs ecr:GetAuthorizationToken and ecs:RegisterTaskDefinition, both of which AWS documents as Resource *. Trust is pinned to environment:dev or environment:prod, job_workflow_ref on org cd-hcp-fargate.yaml@*, and workflow_ref on the thin deploy-api.yaml caller at refs/heads/main or refs/tags/v*. iam:PassRole is limited to the ECS task and execution roles. ECR push and SSM parameter reads are already resource-scoped." + "id": "checkov-CKV_AWS_111-42", + "justification": "LINE SHIFT ONLY: dropping the workflow_ref trust condition shifts github_deploy from 49 to 42. The permission document is unchanged. Original justification: githubdeploy-meal-order-manager needs ecr:GetAuthorizationToken and ecs:RegisterTaskDefinition, both of which AWS documents as Resource *. Trust is pinned to environment:dev or environment:prod and job_workflow_ref on org cd-hcp-fargate.yaml@*. iam:PassRole is limited to the ECS task and execution roles. ECR push and SSM parameter reads are already resource-scoped." } ] } diff --git a/terraform/iam_github_deploy.tf b/terraform/iam_github_deploy.tf index 08e08d2..52ae70c 100644 --- a/terraform/iam_github_deploy.tf +++ b/terraform/iam_github_deploy.tf @@ -27,6 +27,8 @@ data "aws_iam_policy_document" "github_deploy_assume" { ] } + # AWS STS GitHub condition keys include job_workflow_ref, not workflow_ref. + # A workflow_ref condition fail-closes AssumeRoleWithWebIdentity. condition { test = "StringLike" variable = "token.actions.githubusercontent.com:job_workflow_ref" @@ -34,15 +36,6 @@ data "aws_iam_policy_document" "github_deploy_assume" { "Sea-Haven-Industries/.github/.github/workflows/cd-hcp-fargate.yaml@*", ] } - - condition { - test = "StringLike" - variable = "token.actions.githubusercontent.com:workflow_ref" - values = [ - "Sea-Haven-Industries/meal-order-manager/.github/workflows/deploy-api.yaml@refs/heads/main", - "Sea-Haven-Industries/meal-order-manager/.github/workflows/deploy-api.yaml@refs/tags/v*", - ] - } } } diff --git a/tests/test_terraform_github_deploy.py b/tests/test_terraform_github_deploy.py index e0491d9..0571527 100644 --- a/tests/test_terraform_github_deploy.py +++ b/tests/test_terraform_github_deploy.py @@ -1,4 +1,4 @@ -"""githubdeploy OIDC trust pins the org reusable and the thin caller.""" +"""githubdeploy OIDC trust pins the org reusable with AWS-supported claims.""" from pathlib import Path @@ -13,23 +13,6 @@ def test_github_deploy_trust_uses_org_reusable_and_caller(): assert ( "Sea-Haven-Industries/.github/.github/workflows/cd-hcp-fargate.yaml@*" in text ) - assert "token.actions.githubusercontent.com:workflow_ref" in text - assert ( - "Sea-Haven-Industries/meal-order-manager/.github/workflows/deploy-api.yaml@refs/heads/main" - in text - ) - assert ( - "Sea-Haven-Industries/meal-order-manager/.github/workflows/deploy-api.yaml@refs/tags/v*" - in text - ) - assert "cd-hcp-spa.yaml" not in text - assert "token.actions.githubusercontent.com:workflow_ref" in text - assert ( - "Sea-Haven-Industries/meal-order-manager/.github/workflows/deploy-api.yaml@refs/heads/main" - in text - ) - assert ( - "Sea-Haven-Industries/meal-order-manager/.github/workflows/deploy-api.yaml@refs/tags/v*" - in text - ) + assert "token.actions.githubusercontent.com:job_workflow_ref" in text + assert "token.actions.githubusercontent.com:workflow_ref" not in text assert "cd-hcp-spa.yaml" not in text