mirror of
https://github.com/Sea-Haven-Industries/meal-order-manager.git
synced 2026-09-30 03:03:12 +00:00
fix(iam): drop githubdeploy workflow_ref OIDC condition (PLAT-222) (#215)
* fix(iam): drop githubdeploy workflow_ref OIDC condition AWS STS does not evaluate GitHub workflow_ref, so that trust condition fail-closes AssumeRoleWithWebIdentity. * chore(security): retarget githubdeploy Checkov suppression Dropping the workflow_ref trust condition shifted CKV_AWS_111 from line 49 to 42. Permissions are unchanged. * style: apply formatter --------- Co-authored-by: sea-haven-auto-fix[bot] <5037331+sea-haven-auto-fix[bot]@users.noreply.github.com>
This commit is contained in:
parent
f632020b20
commit
f7957436bd
3 changed files with 7 additions and 31 deletions
|
|
@ -9,8 +9,8 @@
|
|||
"justification": "The meals API ALB is the CloudFront HTTP origin for orders.seahaven.com. TLS and WAF terminate at CloudFront. Restricting the security group to the CloudFront managed prefix list would block GitHub-hosted weekly-menu HMAC publish, which must call the origin with X-Meals-Publish-Key. Application gates are HMAC on /api/publish, Cognito or Google Bearer on admin, and public submit only. Accepted as the HTTP-origin design for PLAT-215; TLS on the ALB is a follow-up."
|
||||
},
|
||||
{
|
||||
"id": "checkov-CKV_AWS_111-49",
|
||||
"justification": "LINE SHIFT ONLY: the OIDC dual-claim change adds a workflow_ref condition and retargets job_workflow_ref, shifting github_deploy from 40 to 49. The permission document is unchanged. Original justification: githubdeploy-meal-order-manager needs ecr:GetAuthorizationToken and ecs:RegisterTaskDefinition, both of which AWS documents as Resource *. Trust is pinned to environment:dev or environment:prod, job_workflow_ref on org cd-hcp-fargate.yaml@*, and workflow_ref on the thin deploy-api.yaml caller at refs/heads/main or refs/tags/v*. iam:PassRole is limited to the ECS task and execution roles. ECR push and SSM parameter reads are already resource-scoped."
|
||||
"id": "checkov-CKV_AWS_111-42",
|
||||
"justification": "LINE SHIFT ONLY: dropping the workflow_ref trust condition shifts github_deploy from 49 to 42. The permission document is unchanged. Original justification: githubdeploy-meal-order-manager needs ecr:GetAuthorizationToken and ecs:RegisterTaskDefinition, both of which AWS documents as Resource *. Trust is pinned to environment:dev or environment:prod and job_workflow_ref on org cd-hcp-fargate.yaml@*. iam:PassRole is limited to the ECS task and execution roles. ECR push and SSM parameter reads are already resource-scoped."
|
||||
}
|
||||
]
|
||||
}
|
||||
|
|
|
|||
|
|
@ -27,6 +27,8 @@ data "aws_iam_policy_document" "github_deploy_assume" {
|
|||
]
|
||||
}
|
||||
|
||||
# AWS STS GitHub condition keys include job_workflow_ref, not workflow_ref.
|
||||
# A workflow_ref condition fail-closes AssumeRoleWithWebIdentity.
|
||||
condition {
|
||||
test = "StringLike"
|
||||
variable = "token.actions.githubusercontent.com:job_workflow_ref"
|
||||
|
|
@ -34,15 +36,6 @@ data "aws_iam_policy_document" "github_deploy_assume" {
|
|||
"Sea-Haven-Industries/.github/.github/workflows/cd-hcp-fargate.yaml@*",
|
||||
]
|
||||
}
|
||||
|
||||
condition {
|
||||
test = "StringLike"
|
||||
variable = "token.actions.githubusercontent.com:workflow_ref"
|
||||
values = [
|
||||
"Sea-Haven-Industries/meal-order-manager/.github/workflows/deploy-api.yaml@refs/heads/main",
|
||||
"Sea-Haven-Industries/meal-order-manager/.github/workflows/deploy-api.yaml@refs/tags/v*",
|
||||
]
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
|
|
|
|||
|
|
@ -1,4 +1,4 @@
|
|||
"""githubdeploy OIDC trust pins the org reusable and the thin caller."""
|
||||
"""githubdeploy OIDC trust pins the org reusable with AWS-supported claims."""
|
||||
|
||||
from pathlib import Path
|
||||
|
||||
|
|
@ -13,23 +13,6 @@ def test_github_deploy_trust_uses_org_reusable_and_caller():
|
|||
assert (
|
||||
"Sea-Haven-Industries/.github/.github/workflows/cd-hcp-fargate.yaml@*" in text
|
||||
)
|
||||
assert "token.actions.githubusercontent.com:workflow_ref" in text
|
||||
assert (
|
||||
"Sea-Haven-Industries/meal-order-manager/.github/workflows/deploy-api.yaml@refs/heads/main"
|
||||
in text
|
||||
)
|
||||
assert (
|
||||
"Sea-Haven-Industries/meal-order-manager/.github/workflows/deploy-api.yaml@refs/tags/v*"
|
||||
in text
|
||||
)
|
||||
assert "cd-hcp-spa.yaml" not in text
|
||||
assert "token.actions.githubusercontent.com:workflow_ref" in text
|
||||
assert (
|
||||
"Sea-Haven-Industries/meal-order-manager/.github/workflows/deploy-api.yaml@refs/heads/main"
|
||||
in text
|
||||
)
|
||||
assert (
|
||||
"Sea-Haven-Industries/meal-order-manager/.github/workflows/deploy-api.yaml@refs/tags/v*"
|
||||
in text
|
||||
)
|
||||
assert "token.actions.githubusercontent.com:job_workflow_ref" in text
|
||||
assert "token.actions.githubusercontent.com:workflow_ref" not in text
|
||||
assert "cd-hcp-spa.yaml" not in text
|
||||
|
|
|
|||
Loading…
Add table
Reference in a new issue