Freeze SAM CD and add greenfield Terraform for seahaven-prod so HCP is the sole stack deploy path.
2.1 KiB
github-meal-order-manager-layer-artifacts
Not provisioned, and not currently needed. Kept as the reference definition in case S3-mediated layer artifacts are reintroduced.
Terraform now owns Lambda packaging. terraform/artifacts.tf runs
terraform/build_packages.sh during plan and carries the layer and function zips into the
plan as content_base64, uploading them to meal-order-manager-artifacts-011934824531 at
apply time under the HCP Terraform workspace's own credentials. No GitHub Actions job
writes to that bucket, so .github/workflows/build-layer.yml holds no AWS credentials and
runs as build verification only.
Account and bucket references in trust-policy.json and permissions-policy.json are
updated to prod (011934824531) so the definition stays usable as-is.
Scope, if it is ever created
An OIDC role for the upload job of .github/workflows/build-layer.yml, writing and
reading objects under the layers/ prefix of one bucket and nothing else. The
DenyEverythingElse statement uses NotAction so any future Allow — added here or
inherited — cannot widen the role beyond those three S3 actions. s3:ListBucket is
required because head-object on a missing key returns 403 instead of 404 without it,
which would make the "already present" check indistinguishable from a permissions failure;
it is prefix-conditioned to layers/*.
Trust
Pinned three ways: sub to refs/heads/main, job_workflow_ref to the build-layer
workflow file at main, and aud to sts.amazonaws.com. The job_workflow_ref pin is what
stops any other workflow in the repo — including a future one added by a PR — from
assuming it.
Deliberately not trusted for pull_request. A PR-triggered run executes the PR's own
copy of the workflow, so a credentialed PR job could overwrite an artifact that a later
apply publishes, without the PR ever merging.
Both mandatory gates (cross-family review and /sh-security-review) must pass on these
exact JSONs before the role lands in the github-oidc-deploy-roles stack. Repo secret
would be AWS_LAYER_ARTIFACTS_ROLE_ARN.