/** * Shared, non-sensitive constants for the open-swe infra app. * Account / region are locked per the migration spec (TODO.md "Architecture (locked)"). */ export const ACCOUNT = "328440206208"; export const REGION = "us-east-1"; export const GITHUB_ORG = "Sea-Haven-Industries"; export const GITHUB_REPO = "open-swe"; export type EnvName = "dev" | "prod"; /** `open-swe-dev` / `open-swe-prod` — kebab-case stack + resource prefix. */ export const prefix = (env: EnvName): string => `open-swe-${env}`; /** * Per-ENV GitHub OIDC trust subject for the deploy roles (T5 OSWE-IAC-01/02 fix: * the dev/prod boundary is enforced in the IAM trust, not by convention). * * - `dev` → the `dev` integration branch ref (auto-deploy on push to dev). * - `prod` → the **GitHub `prod` Environment** subject. A workflow can only mint * a token with sub `…:environment:prod` by declaring `environment: prod`, * which triggers the Environment's manual-approval gate (Adam, T18). So the * prod approval is now expressed at the IAM layer: a dev-branch token can * never assume a prod deploy role. * * Each env gets its OWN infra + app role (githubdeploy-open-swe-{infra,app}-) * so a dev token cannot reach prod. Exact subject → StringEquals (no `*`). * * Residual (documented): CDK's single account-wide `cfn-exec-role` means the dev * INFRA role can still technically `cdk deploy open-swe-prod`; the workflow only * ever targets its own env stack, and prod's environment-gated role is the * approved path. Per-env bootstrap qualifiers would close this fully (future). */ export const oidcSubject = (env: EnvName): string => env === "prod" ? `repo:${GITHUB_ORG}/${GITHUB_REPO}:environment:prod` : `repo:${GITHUB_ORG}/${GITHUB_REPO}:ref:refs/heads/dev`; /** * The GitHub Actions OIDC provider already exists account-wide (created for * seahaven-site; see .github/oidc-deploy-roles.yaml `CreateOIDCProvider=false`). * Reference it by ARN — never create a duplicate `AWS::IAM::OIDCProvider` * (CloudFormation rejects a second provider for the same URL). */ export const GITHUB_OIDC_PROVIDER_ARN = `arn:aws:iam::${ACCOUNT}:oidc-provider/token.actions.githubusercontent.com`;