/** * Shared, non-sensitive constants for the open-swe infra app. * Account / region are locked per the migration spec (TODO.md "Architecture (locked)"). */ export const ACCOUNT = "328440206208"; export const REGION = "us-east-1"; export const GITHUB_ORG = "Sea-Haven-Industries"; export const GITHUB_REPO = "open-swe"; export type EnvName = "dev" | "prod"; /** `open-swe-dev` / `open-swe-prod` — kebab-case stack + resource prefix. */ export const prefix = (env: EnvName): string => `open-swe-${env}`; /** * Per-ENV GitHub OIDC trust subject for the deploy roles (T5 OSWE-IAC-01/02 fix: * the dev/prod boundary is enforced in the IAM trust, not by convention). * * - `dev` → the `dev` integration branch ref (auto-deploy on push to dev). * - `prod` → the **GitHub `prod` Environment** subject. A workflow can only mint * a token with sub `…:environment:prod` by declaring `environment: prod`, * which triggers the Environment's manual-approval gate (Adam, T18). So the * prod approval is now expressed at the IAM layer: a dev-branch token can * never assume a prod deploy role. * * Each env gets its OWN infra + app role (githubdeploy-open-swe-{infra,app}-) * so a dev token cannot reach prod. Exact subject → StringEquals (no `*`). * * Cross-env deploy isolation is enforced at the bootstrap layer too — see * `bootstrapQualifier`: dev runs on its own qualifier so the dev infra role * cannot assume the bootstrap roles that deploy prod. */ export const oidcSubject = (env: EnvName): string => env === "prod" ? `repo:${GITHUB_ORG}/${GITHUB_REPO}:environment:prod` : `repo:${GITHUB_ORG}/${GITHUB_REPO}:ref:refs/heads/dev`; /** * Per-env CDK bootstrap qualifier (B-1 / OSWE-IAC-01 fix). Dev runs on its OWN * qualifier `oswedev` (bootstrapped into the `CDKToolkit-oswedev` stack), so the * dev infra deploy role only assumes `cdk-oswedev-*` and can NO LONGER assume the * default `cdk-hnb659fds-*` set whose admin `cfn-exec-role` deploys prod. Prod * stays on the default qualifier. This closes the cross-env escalation where a * dev-branch token could `cdk deploy open-swe-prod` via the shared bootstrap * roles, bypassing prod's Environment approval gate. */ export const DEFAULT_BOOTSTRAP_QUALIFIER = "hnb659fds"; export const bootstrapQualifier = (env: EnvName): string => env === "dev" ? "oswedev" : DEFAULT_BOOTSTRAP_QUALIFIER; /** * The GitHub Actions OIDC provider already exists account-wide (created for * seahaven-site; see .github/oidc-deploy-roles.yaml `CreateOIDCProvider=false`). * Reference it by ARN — never create a duplicate `AWS::IAM::OIDCProvider` * (CloudFormation rejects a second provider for the same URL). */ export const GITHUB_OIDC_PROVIDER_ARN = `arn:aws:iam::${ACCOUNT}:oidc-provider/token.actions.githubusercontent.com`;