mirror of
https://github.com/Sea-Haven-Industries/meal-order-manager.git
synced 2026-09-30 21:43:13 +00:00
* fix(iam): drop githubdeploy workflow_ref OIDC condition AWS STS does not evaluate GitHub workflow_ref, so that trust condition fail-closes AssumeRoleWithWebIdentity. * chore(security): retarget githubdeploy Checkov suppression Dropping the workflow_ref trust condition shifted CKV_AWS_111 from line 49 to 42. Permissions are unchanged. * style: apply formatter --------- Co-authored-by: sea-haven-auto-fix[bot] <5037331+sea-haven-auto-fix[bot]@users.noreply.github.com>
18 lines
798 B
Python
18 lines
798 B
Python
"""githubdeploy OIDC trust pins the org reusable with AWS-supported claims."""
|
|
|
|
from pathlib import Path
|
|
|
|
IAM = Path(__file__).resolve().parents[1] / "terraform" / "iam_github_deploy.tf"
|
|
|
|
|
|
def test_github_deploy_trust_uses_org_reusable_and_caller():
|
|
text = IAM.read_text()
|
|
assert "token.actions.githubusercontent.com:sub" in text
|
|
assert "repo:Sea-Haven-Industries/meal-order-manager:environment:dev" in text
|
|
assert "repo:Sea-Haven-Industries/meal-order-manager:environment:prod" in text
|
|
assert (
|
|
"Sea-Haven-Industries/.github/.github/workflows/cd-hcp-fargate.yaml@*" in text
|
|
)
|
|
assert "token.actions.githubusercontent.com:job_workflow_ref" in text
|
|
assert "token.actions.githubusercontent.com:workflow_ref" not in text
|
|
assert "cd-hcp-spa.yaml" not in text
|