open-swe/infra/lib/config.ts

48 lines
2.2 KiB
TypeScript
Raw Normal View History

/**
* Shared, non-sensitive constants for the open-swe infra app.
* Account / region are locked per the migration spec (TODO.md "Architecture (locked)").
*/
export const ACCOUNT = "328440206208";
export const REGION = "us-east-1";
export const GITHUB_ORG = "Sea-Haven-Industries";
export const GITHUB_REPO = "open-swe";
export type EnvName = "dev" | "prod";
/** `open-swe-dev` / `open-swe-prod` — kebab-case stack + resource prefix. */
export const prefix = (env: EnvName): string => `open-swe-${env}`;
/**
* Per-ENV GitHub OIDC trust subject for the deploy roles (T5 OSWE-IAC-01/02 fix:
* the dev/prod boundary is enforced in the IAM trust, not by convention).
*
* - `dev` → the `dev` integration branch ref (auto-deploy on push to dev).
* - `prod` → the **GitHub `prod` Environment** subject. A workflow can only mint
* a token with sub `…:environment:prod` by declaring `environment: prod`,
* which triggers the Environment's manual-approval gate (Adam, T18). So the
* prod approval is now expressed at the IAM layer: a dev-branch token can
* never assume a prod deploy role.
*
* Each env gets its OWN infra + app role (githubdeploy-open-swe-{infra,app}-<env>)
* so a dev token cannot reach prod. Exact subject → StringEquals (no `*`).
*
* Residual (documented): CDK's single account-wide `cfn-exec-role` means the dev
* INFRA role can still technically `cdk deploy open-swe-prod`; the workflow only
* ever targets its own env stack, and prod's environment-gated role is the
* approved path. Per-env bootstrap qualifiers would close this fully (future).
*/
export const oidcSubject = (env: EnvName): string =>
env === "prod"
? `repo:${GITHUB_ORG}/${GITHUB_REPO}:environment:prod`
: `repo:${GITHUB_ORG}/${GITHUB_REPO}:ref:refs/heads/dev`;
/**
* The GitHub Actions OIDC provider already exists account-wide (created for
* seahaven-site; see .github/oidc-deploy-roles.yaml `CreateOIDCProvider=false`).
* Reference it by ARN — never create a duplicate `AWS::IAM::OIDCProvider`
* (CloudFormation rejects a second provider for the same URL).
*/
export const GITHUB_OIDC_PROVIDER_ARN = `arn:aws:iam::${ACCOUNT}:oidc-provider/token.actions.githubusercontent.com`;