diff --git a/terraform/iam_github_deploy.tf b/terraform/iam_github_deploy.tf index b60cafa..bfe3ed3 100644 --- a/terraform/iam_github_deploy.tf +++ b/terraform/iam_github_deploy.tf @@ -3,7 +3,8 @@ # # One role per account: GitHub Environments have a single DEPLOY_ROLE_ARN. # The prod role trusts environment:prod only. The dev role trusts environment:dev only. -# job_workflow_ref is StringEquals on the reusable SHA pinned by deploy.yaml. +# job_workflow_ref is StringLike on the org reusable at any pin. The caller +# stays SHA-pinned. @* keeps a pin bump from invalidating the role. # AWS STS GitHub condition keys include job_workflow_ref, not workflow_ref. # # Not a Lambda execution role: no permissions_boundary. Path /tf-managed/ so @@ -34,7 +35,7 @@ data "aws_iam_policy_document" "github_deploy_assume" { } condition { - test = "StringEquals" + test = "StringLike" variable = "token.actions.githubusercontent.com:job_workflow_ref" values = [local.github_deploy_workflow_ref] } diff --git a/terraform/locals.tf b/terraform/locals.tf index 4b75140..f9f6764 100644 --- a/terraform/locals.tf +++ b/terraform/locals.tf @@ -29,9 +29,9 @@ locals { "repo:${var.github_repo}:environment:dev", ] github_oidc_subs = local.is_prod ? local.github_oidc_subs_prod : local.github_oidc_subs_dev - # Matches the SHA pin in .github/workflows/deploy.yaml. A reusable bump - # updates both together. StringEquals, not @*. - github_deploy_workflow_ref = "Sea-Haven-Industries/.github/.github/workflows/cd-hcp-lambda.yaml@ee5b843ca105422b679c3fdeb9eaa68c6e500a85" + # The caller workflow stays SHA-pinned. @* keeps a pin bump from + # invalidating this role. sub still names this repo and environment. + github_deploy_workflow_ref = "Sea-Haven-Industries/.github/.github/workflows/cd-hcp-lambda.yaml@*" dynamodb_cmk_arns = { prod = "arn:aws:kms:us-east-1:011934824531:key/be5fa4cb-c546-40fe-a13d-c7bec79f5d12" diff --git a/tests/infra/hcpContract.test.js b/tests/infra/hcpContract.test.js index f66dae0..b4b33bb 100644 --- a/tests/infra/hcpContract.test.js +++ b/tests/infra/hcpContract.test.js @@ -85,8 +85,9 @@ describe("HCP Terraform seam (PLAT-79)", () => { assert.doesNotMatch(ci, /run-sam-validate/); assert.match(ci, /npm test/); assert.match(ci, /ci-terraform\.yaml@[0-9a-f]{40} # v/); + assert.match(ci, /ci-autofix\.yaml@[0-9a-f]{40} # v/); assert.doesNotMatch(ci, /ci-terraform\.yaml@\*/); - assert.match(ci, /ci-autofix\.yaml@47185fa602dffddb8297db5f3525d7c9bc05d7cd/); + assert.doesNotMatch(ci, /ci-autofix\.yaml@\*/); assert.match(ci, /presets: prettier,terraform/); assert.match(ci, /npm run format:check/); assert.match(ci, /src\//); @@ -117,10 +118,11 @@ describe("HCP Terraform seam (PLAT-79)", () => { assert.doesNotMatch(prodSubs, /environment:dev/); assert.match(githubDeploy, /github_oidc_subs/); assert.match(githubDeploy, /job_workflow_ref/); - assert.match(locals, /cd-hcp-lambda\.yaml@ee5b843ca105422b679c3fdeb9eaa68c6e500a85/); - assert.match(deploy, /cd-hcp-lambda\.yaml@ee5b843ca105422b679c3fdeb9eaa68c6e500a85/); - assert.doesNotMatch(githubDeploy, /cd-hcp-lambda\.yaml@\*/); - assert.doesNotMatch(locals, /cd-hcp-lambda\.yaml@\*/); + assert.match(githubDeploy, /StringLike[\s\S]{0,80}job_workflow_ref/); + assert.doesNotMatch(githubDeploy, /StringEquals[\s\S]{0,80}job_workflow_ref/); + assert.match(locals, /cd-hcp-lambda\.yaml@\*/); + assert.match(deploy, /cd-hcp-lambda\.yaml@[0-9a-f]{40} # v/); + assert.doesNotMatch(deploy, /cd-hcp-lambda\.yaml@\*/); assert.doesNotMatch(githubDeploy, /deploy\.yaml@refs\/heads/); assert.doesNotMatch(variables, /github_deploy_branch/); });