# GitHub Actions OIDC role for .github/workflows/deploy-api.yaml. data "aws_iam_policy_document" "github_deploy_assume" { statement { sid = "GithubDeployOidc" effect = "Allow" actions = ["sts:AssumeRoleWithWebIdentity"] principals { type = "Federated" identifiers = [local.github_oidc_provider_arn] } condition { test = "StringEquals" variable = "token.actions.githubusercontent.com:aud" values = ["sts.amazonaws.com"] } condition { test = "StringEquals" variable = "token.actions.githubusercontent.com:sub" values = [ "repo:Sea-Haven-Industries/meal-order-manager:environment:dev", "repo:Sea-Haven-Industries/meal-order-manager:environment:prod", ] } condition { test = "StringLike" variable = "token.actions.githubusercontent.com:job_workflow_ref" values = [ "Sea-Haven-Industries/meal-order-manager/.github/workflows/deploy-api.yaml@refs/heads/main", "Sea-Haven-Industries/meal-order-manager/.github/workflows/deploy-api.yaml@refs/tags/v*", ] } } } data "aws_iam_policy_document" "github_deploy" { statement { sid = "EcrAuth" effect = "Allow" actions = [ "ecr:GetAuthorizationToken", ] resources = ["*"] } statement { sid = "EcrPush" effect = "Allow" actions = [ "ecr:BatchCheckLayerAvailability", "ecr:BatchGetImage", "ecr:CompleteLayerUpload", "ecr:GetDownloadUrlForLayer", "ecr:InitiateLayerUpload", "ecr:PutImage", "ecr:UploadLayerPart", "ecr:DescribeRepositories", "ecr:DescribeImages", ] resources = [aws_ecr_repository.api.arn] } statement { sid = "EcsDeploy" effect = "Allow" actions = [ "ecs:DescribeServices", "ecs:DescribeTaskDefinition", "ecs:DescribeTasks", "ecs:ListTasks", "ecs:RegisterTaskDefinition", "ecs:UpdateService", ] resources = ["*"] } statement { sid = "PassTaskRoles" effect = "Allow" actions = ["iam:PassRole"] resources = [ aws_iam_role.ecs_task.arn, aws_iam_role.ecs_execution.arn, ] } statement { sid = "DeployParams" effect = "Allow" actions = [ "ssm:GetParameter", ] resources = [ aws_ssm_parameter.deploy_cluster.arn, aws_ssm_parameter.deploy_service.arn, aws_ssm_parameter.deploy_task_family.arn, aws_ssm_parameter.deploy_ecr_repository.arn, aws_ssm_parameter.deploy_container_name.arn, aws_ssm_parameter.deploy_form_url.arn, aws_ssm_parameter.deploy_api_url.arn, ] } } resource "aws_iam_policy" "github_deploy_boundary" { name = "${local.project}-githubdeploy-boundary" path = "/tf-managed/" description = "Permissions boundary for githubdeploy-meal-order-manager" policy = data.aws_iam_policy_document.github_deploy.json } resource "aws_iam_role" "github_deploy" { name = "githubdeploy-meal-order-manager" path = "/tf-managed/" description = "GitHub Actions API image deploy for meal-order-manager" assume_role_policy = data.aws_iam_policy_document.github_deploy_assume.json permissions_boundary = aws_iam_policy.github_deploy_boundary.arn max_session_duration = 3600 } resource "aws_iam_role_policy" "github_deploy" { name = "api-image-deploy" role = aws_iam_role.github_deploy.id policy = data.aws_iam_policy_document.github_deploy.json }