mirror of
https://github.com/Sea-Haven-Industries/meal-order-manager.git
synced 2026-09-30 04:13:12 +00:00
Freeze SAM CD and add greenfield Terraform for seahaven-prod so HCP is the sole stack deploy path.
39 lines
2.1 KiB
Markdown
39 lines
2.1 KiB
Markdown
# github-meal-order-manager-layer-artifacts
|
|
|
|
**Not provisioned, and not currently needed.** Kept as the reference definition in case
|
|
S3-mediated layer artifacts are reintroduced.
|
|
|
|
Terraform now owns Lambda packaging. `terraform/artifacts.tf` runs
|
|
`terraform/build_packages.sh` during plan and carries the layer and function zips into the
|
|
plan as `content_base64`, uploading them to `meal-order-manager-artifacts-011934824531` at
|
|
apply time under the HCP Terraform workspace's own credentials. No GitHub Actions job
|
|
writes to that bucket, so `.github/workflows/build-layer.yml` holds no AWS credentials and
|
|
runs as build verification only.
|
|
|
|
Account and bucket references in `trust-policy.json` and `permissions-policy.json` are
|
|
updated to prod (`011934824531`) so the definition stays usable as-is.
|
|
|
|
## Scope, if it is ever created
|
|
|
|
An OIDC role for the `upload` job of `.github/workflows/build-layer.yml`, writing and
|
|
reading objects under the `layers/` prefix of one bucket and nothing else. The
|
|
`DenyEverythingElse` statement uses `NotAction` so any future Allow — added here or
|
|
inherited — cannot widen the role beyond those three S3 actions. `s3:ListBucket` is
|
|
required because `head-object` on a missing key returns 403 instead of 404 without it,
|
|
which would make the "already present" check indistinguishable from a permissions failure;
|
|
it is prefix-conditioned to `layers/*`.
|
|
|
|
## Trust
|
|
|
|
Pinned three ways: `sub` to `refs/heads/main`, `job_workflow_ref` to the build-layer
|
|
workflow file at main, and `aud` to `sts.amazonaws.com`. The `job_workflow_ref` pin is what
|
|
stops any other workflow in the repo — including a future one added by a PR — from
|
|
assuming it.
|
|
|
|
Deliberately **not** trusted for `pull_request`. A PR-triggered run executes the PR's own
|
|
copy of the workflow, so a credentialed PR job could overwrite an artifact that a later
|
|
apply publishes, without the PR ever merging.
|
|
|
|
Both mandatory gates (cross-family review and `/sh-security-review`) must pass on these
|
|
exact JSONs before the role lands in the `github-oidc-deploy-roles` stack. Repo secret
|
|
would be `AWS_LAYER_ARTIFACTS_ROLE_ARN`.
|