open-swe/deploy
Adam Moussa 42c9baca79
Scope secrets fetch to --secret-id-list; drop ListSecrets grant
Switch fetch-config.sh from a name-prefix batch-get-secret-value
--filters scan to an explicit --secret-id-list (the 28 SECRET_VARS,
chunked at the 20/call cap). An id-list batch authorizes per-secret
ARN, so the instance role's BatchGetSecretValue moves from Resource:*
to the open-swe-<env>/* prefix and the account-wide ListSecrets grant
is dropped entirely. The box can no longer enumerate secret names
account-wide; cross-env value isolation is unchanged (GetSecretValue
was already prefix-scoped). Resolves OSWE-IAC-SECRETS-LIST-01.

Also capture each chunk response into a variable and consume the
producer via command substitution so a failed AWS call aborts under
set -e instead of being swallowed by process substitution and
misreported as a missing required var.

Refs: OSWE-IAC-SECRETS-LIST-01
2026-06-28 16:32:51 -04:00
..
ami fix(deploy): use %%...%% for CDK user-data tokens (don't collide with @@ sed) (#21) 2026-06-26 19:06:37 -04:00
seahaven Scope secrets fetch to --secret-id-list; drop ListSecrets grant 2026-06-28 16:32:51 -04:00