mirror of
https://github.com/Sea-Haven-Industries/open-swe.git
synced 2026-09-30 13:53:15 +00:00
PR#1 of the AWS migration. CDK TypeScript app under /infra: stacks open-swe-iam (four per-env GitHub-OIDC deploy roles) + open-swe-dev/-prod (per-env EC2 instance role + AMI cache). aws-cdk-lib pinned exact 2.260.0; kebab naming Aspect + 15 tests. IAM is synth-only (NOT deployed). Cleared the Phase-1 security gates: - T4 GPT-4.1 IAM cross-review (StringEquals trust; cdk-hnb659fds-* wildcard kept as org convention; AWS-RunShellScript timeboxed to T19). - T5 /sh-security-review: deploy roles split PER-ENV with env-scoped OIDC trust (dev=branch ref+tag dev, prod=environment:prod+tag prod) so a dev token cannot reach prod; re-verified block:false.
47 lines
2.2 KiB
TypeScript
47 lines
2.2 KiB
TypeScript
/**
|
|
* Shared, non-sensitive constants for the open-swe infra app.
|
|
* Account / region are locked per the migration spec (TODO.md "Architecture (locked)").
|
|
*/
|
|
|
|
export const ACCOUNT = "328440206208";
|
|
export const REGION = "us-east-1";
|
|
|
|
export const GITHUB_ORG = "Sea-Haven-Industries";
|
|
export const GITHUB_REPO = "open-swe";
|
|
|
|
export type EnvName = "dev" | "prod";
|
|
|
|
/** `open-swe-dev` / `open-swe-prod` — kebab-case stack + resource prefix. */
|
|
export const prefix = (env: EnvName): string => `open-swe-${env}`;
|
|
|
|
/**
|
|
* Per-ENV GitHub OIDC trust subject for the deploy roles (T5 OSWE-IAC-01/02 fix:
|
|
* the dev/prod boundary is enforced in the IAM trust, not by convention).
|
|
*
|
|
* - `dev` → the `dev` integration branch ref (auto-deploy on push to dev).
|
|
* - `prod` → the **GitHub `prod` Environment** subject. A workflow can only mint
|
|
* a token with sub `…:environment:prod` by declaring `environment: prod`,
|
|
* which triggers the Environment's manual-approval gate (Adam, T18). So the
|
|
* prod approval is now expressed at the IAM layer: a dev-branch token can
|
|
* never assume a prod deploy role.
|
|
*
|
|
* Each env gets its OWN infra + app role (githubdeploy-open-swe-{infra,app}-<env>)
|
|
* so a dev token cannot reach prod. Exact subject → StringEquals (no `*`).
|
|
*
|
|
* Residual (documented): CDK's single account-wide `cfn-exec-role` means the dev
|
|
* INFRA role can still technically `cdk deploy open-swe-prod`; the workflow only
|
|
* ever targets its own env stack, and prod's environment-gated role is the
|
|
* approved path. Per-env bootstrap qualifiers would close this fully (future).
|
|
*/
|
|
export const oidcSubject = (env: EnvName): string =>
|
|
env === "prod"
|
|
? `repo:${GITHUB_ORG}/${GITHUB_REPO}:environment:prod`
|
|
: `repo:${GITHUB_ORG}/${GITHUB_REPO}:ref:refs/heads/dev`;
|
|
|
|
/**
|
|
* The GitHub Actions OIDC provider already exists account-wide (created for
|
|
* seahaven-site; see .github/oidc-deploy-roles.yaml `CreateOIDCProvider=false`).
|
|
* Reference it by ARN — never create a duplicate `AWS::IAM::OIDCProvider`
|
|
* (CloudFormation rejects a second provider for the same URL).
|
|
*/
|
|
export const GITHUB_OIDC_PROVIDER_ARN = `arn:aws:iam::${ACCOUNT}:oidc-provider/token.actions.githubusercontent.com`;
|