meal-order-manager/infra/layer-artifacts-role/README.md
Adam Moussa 40ea4ed898
feat(infra): migrate meal-order-manager to HCP Terraform
Freeze SAM CD and add greenfield Terraform for seahaven-prod so HCP is the sole stack deploy path.
2026-08-07 19:19:51 -04:00

2.1 KiB

github-meal-order-manager-layer-artifacts

Not provisioned, and not currently needed. Kept as the reference definition in case S3-mediated layer artifacts are reintroduced.

Terraform now owns Lambda packaging. terraform/artifacts.tf runs terraform/build_packages.sh during plan and carries the layer and function zips into the plan as content_base64, uploading them to meal-order-manager-artifacts-011934824531 at apply time under the HCP Terraform workspace's own credentials. No GitHub Actions job writes to that bucket, so .github/workflows/build-layer.yml holds no AWS credentials and runs as build verification only.

Account and bucket references in trust-policy.json and permissions-policy.json are updated to prod (011934824531) so the definition stays usable as-is.

Scope, if it is ever created

An OIDC role for the upload job of .github/workflows/build-layer.yml, writing and reading objects under the layers/ prefix of one bucket and nothing else. The DenyEverythingElse statement uses NotAction so any future Allow — added here or inherited — cannot widen the role beyond those three S3 actions. s3:ListBucket is required because head-object on a missing key returns 403 instead of 404 without it, which would make the "already present" check indistinguishable from a permissions failure; it is prefix-conditioned to layers/*.

Trust

Pinned three ways: sub to refs/heads/main, job_workflow_ref to the build-layer workflow file at main, and aud to sts.amazonaws.com. The job_workflow_ref pin is what stops any other workflow in the repo — including a future one added by a PR — from assuming it.

Deliberately not trusted for pull_request. A PR-triggered run executes the PR's own copy of the workflow, so a credentialed PR job could overwrite an artifact that a later apply publishes, without the PR ever merging.

Both mandatory gates (cross-family review and /sh-security-review) must pass on these exact JSONs before the role lands in the github-oidc-deploy-roles stack. Repo secret would be AWS_LAYER_ARTIFACTS_ROLE_ARN.