meal-order-manager/infra/layer-artifacts-role/README.md
Adam Moussa 40ea4ed898
feat(infra): migrate meal-order-manager to HCP Terraform
Freeze SAM CD and add greenfield Terraform for seahaven-prod so HCP is the sole stack deploy path.
2026-08-07 19:19:51 -04:00

39 lines
2.1 KiB
Markdown

# github-meal-order-manager-layer-artifacts
**Not provisioned, and not currently needed.** Kept as the reference definition in case
S3-mediated layer artifacts are reintroduced.
Terraform now owns Lambda packaging. `terraform/artifacts.tf` runs
`terraform/build_packages.sh` during plan and carries the layer and function zips into the
plan as `content_base64`, uploading them to `meal-order-manager-artifacts-011934824531` at
apply time under the HCP Terraform workspace's own credentials. No GitHub Actions job
writes to that bucket, so `.github/workflows/build-layer.yml` holds no AWS credentials and
runs as build verification only.
Account and bucket references in `trust-policy.json` and `permissions-policy.json` are
updated to prod (`011934824531`) so the definition stays usable as-is.
## Scope, if it is ever created
An OIDC role for the `upload` job of `.github/workflows/build-layer.yml`, writing and
reading objects under the `layers/` prefix of one bucket and nothing else. The
`DenyEverythingElse` statement uses `NotAction` so any future Allow — added here or
inherited — cannot widen the role beyond those three S3 actions. `s3:ListBucket` is
required because `head-object` on a missing key returns 403 instead of 404 without it,
which would make the "already present" check indistinguishable from a permissions failure;
it is prefix-conditioned to `layers/*`.
## Trust
Pinned three ways: `sub` to `refs/heads/main`, `job_workflow_ref` to the build-layer
workflow file at main, and `aud` to `sts.amazonaws.com`. The `job_workflow_ref` pin is what
stops any other workflow in the repo — including a future one added by a PR — from
assuming it.
Deliberately **not** trusted for `pull_request`. A PR-triggered run executes the PR's own
copy of the workflow, so a credentialed PR job could overwrite an artifact that a later
apply publishes, without the PR ever merging.
Both mandatory gates (cross-family review and `/sh-security-review`) must pass on these
exact JSONs before the role lands in the `github-oidc-deploy-roles` stack. Repo secret
would be `AWS_LAYER_ARTIFACTS_ROLE_ARN`.