open-swe/infra/lib
Adam Moussa 42c9baca79
Scope secrets fetch to --secret-id-list; drop ListSecrets grant
Switch fetch-config.sh from a name-prefix batch-get-secret-value
--filters scan to an explicit --secret-id-list (the 28 SECRET_VARS,
chunked at the 20/call cap). An id-list batch authorizes per-secret
ARN, so the instance role's BatchGetSecretValue moves from Resource:*
to the open-swe-<env>/* prefix and the account-wide ListSecrets grant
is dropped entirely. The box can no longer enumerate secret names
account-wide; cross-env value isolation is unchanged (GetSecretValue
was already prefix-scoped). Resolves OSWE-IAC-SECRETS-LIST-01.

Also capture each chunk response into a variable and consume the
producer via command substitution so a failed AWS call aborts under
set -e instead of being swallowed by process substitution and
misreported as a missing required var.

Refs: OSWE-IAC-SECRETS-LIST-01
2026-06-28 16:32:51 -04:00
..
aspects feat: Secrets Manager + SSM config store for open-swe (T11) (#10) 2026-06-26 16:07:23 -04:00
constructs Scope secrets fetch to --secret-id-list; drop ListSecrets grant 2026-06-28 16:32:51 -04:00
config.ts feat(infra): add /infra CDK scaffold + per-env OIDC/instance IAM role defs (#6) 2026-06-26 15:06:30 -04:00
open-swe-iam-stack.ts feat(infra): add /infra CDK scaffold + per-env OIDC/instance IAM role defs (#6) 2026-06-26 15:06:30 -04:00
open-swe-stack.ts feat: stand up dev properly — assets bucket + artifact CD + baked AMI + on-box uv sync (T7+T19+T14) (#18) 2026-06-26 18:49:09 -04:00