# github-meal-order-manager-layer-artifacts **Not provisioned, and not currently needed.** Kept as the reference definition in case S3-mediated layer artifacts are reintroduced. Terraform now owns Lambda packaging. `terraform/artifacts.tf` runs `terraform/build_packages.sh` during plan and carries the layer and function zips into the plan as `content_base64`, uploading them to `meal-order-manager-artifacts-011934824531` at apply time under the HCP Terraform workspace's own credentials. No GitHub Actions job writes to that bucket, so `.github/workflows/build-layer.yml` holds no AWS credentials and runs as build verification only. Account and bucket references in `trust-policy.json` and `permissions-policy.json` are updated to prod (`011934824531`) so the definition stays usable as-is. ## Scope, if it is ever created An OIDC role for the `upload` job of `.github/workflows/build-layer.yml`, writing and reading objects under the `layers/` prefix of one bucket and nothing else. The `DenyEverythingElse` statement uses `NotAction` so any future Allow — added here or inherited — cannot widen the role beyond those three S3 actions. `s3:ListBucket` is required because `head-object` on a missing key returns 403 instead of 404 without it, which would make the "already present" check indistinguishable from a permissions failure; it is prefix-conditioned to `layers/*`. ## Trust Pinned three ways: `sub` to `refs/heads/main`, `job_workflow_ref` to the build-layer workflow file at main, and `aud` to `sts.amazonaws.com`. The `job_workflow_ref` pin is what stops any other workflow in the repo — including a future one added by a PR — from assuming it. Deliberately **not** trusted for `pull_request`. A PR-triggered run executes the PR's own copy of the workflow, so a credentialed PR job could overwrite an artifact that a later apply publishes, without the PR ever merging. Both mandatory gates (cross-family review and `/sh-security-review`) must pass on these exact JSONs before the role lands in the `github-oidc-deploy-roles` stack. Repo secret would be `AWS_LAYER_ARTIFACTS_ROLE_ARN`.