mirror of
https://github.com/Sea-Haven-Industries/open-swe.git
synced 2026-09-30 09:13:14 +00:00
* fix: isolate dev CDK deploys on their own bootstrap qualifier (B-1) Dev synthesizes against the oswedev qualifier and the dev infra deploy role is scoped to cdk-oswedev-* — it can no longer assume the default hnb659fds bootstrap roles whose admin cfn-exec-role deploys prod, closing the cross-env escalation (OSWE-IAC-01). Prod stays on the default qualifier. * test: assert per-env bootstrap qualifier isolation + document (B-1)
59 lines
2.8 KiB
TypeScript
59 lines
2.8 KiB
TypeScript
/**
|
|
* Shared, non-sensitive constants for the open-swe infra app.
|
|
* Account / region are locked per the migration spec (TODO.md "Architecture (locked)").
|
|
*/
|
|
|
|
export const ACCOUNT = "328440206208";
|
|
export const REGION = "us-east-1";
|
|
|
|
export const GITHUB_ORG = "Sea-Haven-Industries";
|
|
export const GITHUB_REPO = "open-swe";
|
|
|
|
export type EnvName = "dev" | "prod";
|
|
|
|
/** `open-swe-dev` / `open-swe-prod` — kebab-case stack + resource prefix. */
|
|
export const prefix = (env: EnvName): string => `open-swe-${env}`;
|
|
|
|
/**
|
|
* Per-ENV GitHub OIDC trust subject for the deploy roles (T5 OSWE-IAC-01/02 fix:
|
|
* the dev/prod boundary is enforced in the IAM trust, not by convention).
|
|
*
|
|
* - `dev` → the `dev` integration branch ref (auto-deploy on push to dev).
|
|
* - `prod` → the **GitHub `prod` Environment** subject. A workflow can only mint
|
|
* a token with sub `…:environment:prod` by declaring `environment: prod`,
|
|
* which triggers the Environment's manual-approval gate (Adam, T18). So the
|
|
* prod approval is now expressed at the IAM layer: a dev-branch token can
|
|
* never assume a prod deploy role.
|
|
*
|
|
* Each env gets its OWN infra + app role (githubdeploy-open-swe-{infra,app}-<env>)
|
|
* so a dev token cannot reach prod. Exact subject → StringEquals (no `*`).
|
|
*
|
|
* Cross-env deploy isolation is enforced at the bootstrap layer too — see
|
|
* `bootstrapQualifier`: dev runs on its own qualifier so the dev infra role
|
|
* cannot assume the bootstrap roles that deploy prod.
|
|
*/
|
|
export const oidcSubject = (env: EnvName): string =>
|
|
env === "prod"
|
|
? `repo:${GITHUB_ORG}/${GITHUB_REPO}:environment:prod`
|
|
: `repo:${GITHUB_ORG}/${GITHUB_REPO}:ref:refs/heads/dev`;
|
|
|
|
/**
|
|
* Per-env CDK bootstrap qualifier (B-1 / OSWE-IAC-01 fix). Dev runs on its OWN
|
|
* qualifier `oswedev` (bootstrapped into the `CDKToolkit-oswedev` stack), so the
|
|
* dev infra deploy role only assumes `cdk-oswedev-*` and can NO LONGER assume the
|
|
* default `cdk-hnb659fds-*` set whose admin `cfn-exec-role` deploys prod. Prod
|
|
* stays on the default qualifier. This closes the cross-env escalation where a
|
|
* dev-branch token could `cdk deploy open-swe-prod` via the shared bootstrap
|
|
* roles, bypassing prod's Environment approval gate.
|
|
*/
|
|
export const DEFAULT_BOOTSTRAP_QUALIFIER = "hnb659fds";
|
|
export const bootstrapQualifier = (env: EnvName): string =>
|
|
env === "dev" ? "oswedev" : DEFAULT_BOOTSTRAP_QUALIFIER;
|
|
|
|
/**
|
|
* The GitHub Actions OIDC provider already exists account-wide (created for
|
|
* seahaven-site; see .github/oidc-deploy-roles.yaml `CreateOIDCProvider=false`).
|
|
* Reference it by ARN — never create a duplicate `AWS::IAM::OIDCProvider`
|
|
* (CloudFormation rejects a second provider for the same URL).
|
|
*/
|
|
export const GITHUB_OIDC_PROVIDER_ARN = `arn:aws:iam::${ACCOUNT}:oidc-provider/token.actions.githubusercontent.com`;
|