fix(iam): trust the Lambda reusable at any pin (#126)

* ci: pin ci-terraform to v1.0.26

That release classifies a pull request against the merge parent, so a
re-run after main moves is not treated as a mixed app and Terraform change.

* fix(iam): trust the Lambda reusable at any pin

A digest in the deploy role meant every reusable bump had to edit Terraform
before dev and prod could assume the role.
This commit is contained in:
Adam Moussa 2026-10-06 15:10:10 -04:00 • committed by GitHub
parent ca728ce179
commit 15ddb7dc74
No known key found for this signature in database
GPG key ID: B5690EEEBB952194
3 changed files with 13 additions and 10 deletions

View file

@ -3,7 +3,8 @@
#
# One role per account: GitHub Environments have a single DEPLOY_ROLE_ARN.
# The prod role trusts environment:prod only. The dev role trusts environment:dev only.
# job_workflow_ref is StringEquals on the reusable SHA pinned by deploy.yaml.
# job_workflow_ref is StringLike on the org reusable at any pin. The caller
# stays SHA-pinned. @* keeps a pin bump from invalidating the role.
# AWS STS GitHub condition keys include job_workflow_ref, not workflow_ref.
#
# Not a Lambda execution role: no permissions_boundary. Path /tf-managed/ so
@ -34,7 +35,7 @@ data "aws_iam_policy_document" "github_deploy_assume" {
}
condition {
test = "StringEquals"
test = "StringLike"
variable = "token.actions.githubusercontent.com:job_workflow_ref"
values = [local.github_deploy_workflow_ref]
}

View file

@ -29,9 +29,9 @@ locals {
"repo:${var.github_repo}:environment:dev",
]
github_oidc_subs = local.is_prod ? local.github_oidc_subs_prod : local.github_oidc_subs_dev
# Matches the SHA pin in .github/workflows/deploy.yaml. A reusable bump
# updates both together. StringEquals, not @*.
github_deploy_workflow_ref = "Sea-Haven-Industries/.github/.github/workflows/cd-hcp-lambda.yaml@ee5b843ca105422b679c3fdeb9eaa68c6e500a85"
# The caller workflow stays SHA-pinned. @* keeps a pin bump from
# invalidating this role. sub still names this repo and environment.
github_deploy_workflow_ref = "Sea-Haven-Industries/.github/.github/workflows/cd-hcp-lambda.yaml@*"
dynamodb_cmk_arns = {
prod = "arn:aws:kms:us-east-1:011934824531:key/be5fa4cb-c546-40fe-a13d-c7bec79f5d12"

View file

@ -85,8 +85,9 @@ describe("HCP Terraform seam (PLAT-79)", () => {
assert.doesNotMatch(ci, /run-sam-validate/);
assert.match(ci, /npm test/);
assert.match(ci, /ci-terraform\.yaml@[0-9a-f]{40} # v/);
assert.match(ci, /ci-autofix\.yaml@[0-9a-f]{40} # v/);
assert.doesNotMatch(ci, /ci-terraform\.yaml@\*/);
assert.match(ci, /ci-autofix\.yaml@47185fa602dffddb8297db5f3525d7c9bc05d7cd/);
assert.doesNotMatch(ci, /ci-autofix\.yaml@\*/);
assert.match(ci, /presets: prettier,terraform/);
assert.match(ci, /npm run format:check/);
assert.match(ci, /src\//);
@ -117,10 +118,11 @@ describe("HCP Terraform seam (PLAT-79)", () => {
assert.doesNotMatch(prodSubs, /environment:dev/);
assert.match(githubDeploy, /github_oidc_subs/);
assert.match(githubDeploy, /job_workflow_ref/);
assert.match(locals, /cd-hcp-lambda\.yaml@ee5b843ca105422b679c3fdeb9eaa68c6e500a85/);
assert.match(deploy, /cd-hcp-lambda\.yaml@ee5b843ca105422b679c3fdeb9eaa68c6e500a85/);
assert.doesNotMatch(githubDeploy, /cd-hcp-lambda\.yaml@\*/);
assert.doesNotMatch(locals, /cd-hcp-lambda\.yaml@\*/);
assert.match(githubDeploy, /StringLike[\s\S]{0,80}job_workflow_ref/);
assert.doesNotMatch(githubDeploy, /StringEquals[\s\S]{0,80}job_workflow_ref/);
assert.match(locals, /cd-hcp-lambda\.yaml@\*/);
assert.match(deploy, /cd-hcp-lambda\.yaml@[0-9a-f]{40} # v/);
assert.doesNotMatch(deploy, /cd-hcp-lambda\.yaml@\*/);
assert.doesNotMatch(githubDeploy, /deploy\.yaml@refs\/heads/);
assert.doesNotMatch(variables, /github_deploy_branch/);
});