open-swe/infra/test/bootstrap-qualifier.test.ts

56 lines
2 KiB
TypeScript
Raw Normal View History

import * as cdk from "aws-cdk-lib";
import { Match, Template } from "aws-cdk-lib/assertions";
import { OpenSweIamStack } from "../lib/open-swe-iam-stack";
import { bootstrapQualifier } from "../lib/config";
const ENV = { account: "328440206208", region: "us-east-1" };
// B-1 / OSWE-IAC-01: each env's infra deploy role may assume ONLY its own
// bootstrap qualifier's roles. Dev runs on `oswedev`, so a dev-branch token can
// no longer assume the default `hnb659fds` bootstrap roles whose admin
// cfn-exec-role deploys prod. Prod stays on the default qualifier.
describe("Per-env CDK bootstrap qualifier isolation (B-1/OSWE-IAC-01)", () => {
it("maps dev -> oswedev and prod -> hnb659fds", () => {
expect(bootstrapQualifier("dev")).toBe("oswedev");
expect(bootstrapQualifier("prod")).toBe("hnb659fds");
});
it("dev infra deploy role assumes only cdk-oswedev-* bootstrap roles", () => {
const app = new cdk.App();
const stack = new OpenSweIamStack(app, "OpenSweIamStack", {
stackName: "open-swe-iam",
env: ENV,
});
Template.fromStack(stack).hasResourceProperties("AWS::IAM::Policy", {
PolicyDocument: Match.objectLike({
Statement: Match.arrayWith([
Match.objectLike({
Sid: "AssumeCdkBootstrapRoles",
Action: "sts:AssumeRole",
Resource: "arn:aws:iam::328440206208:role/cdk-oswedev-*",
}),
]),
}),
});
});
it("prod infra deploy role stays on the default cdk-hnb659fds-* bootstrap roles", () => {
const app = new cdk.App();
const stack = new OpenSweIamStack(app, "OpenSweIamStack", {
stackName: "open-swe-iam",
env: ENV,
});
Template.fromStack(stack).hasResourceProperties("AWS::IAM::Policy", {
PolicyDocument: Match.objectLike({
Statement: Match.arrayWith([
Match.objectLike({
Sid: "AssumeCdkBootstrapRoles",
Action: "sts:AssumeRole",
Resource: "arn:aws:iam::328440206208:role/cdk-hnb659fds-*",
}),
]),
}),
});
});
});