mirror of
https://github.com/Sea-Haven-Industries/payments-dashboard.git
synced 2026-10-07 09:19:25 +00:00
* ci: pin ci-terraform to v1.0.26 That release classifies a pull request against the merge parent, so a re-run after main moves is not treated as a mixed app and Terraform change. * fix(iam): trust the Lambda reusable at any pin A digest in the deploy role meant every reusable bump had to edit Terraform before dev and prod could assume the role.
101 lines
2.9 KiB
HCL
101 lines
2.9 KiB
HCL
# GitHub Actions OIDC role for the thin deploy.yaml caller of
|
|
# org reusable cd-hcp-lambda.yaml.
|
|
#
|
|
# One role per account: GitHub Environments have a single DEPLOY_ROLE_ARN.
|
|
# The prod role trusts environment:prod only. The dev role trusts environment:dev only.
|
|
# job_workflow_ref is StringLike on the org reusable at any pin. The caller
|
|
# stays SHA-pinned. @* keeps a pin bump from invalidating the role.
|
|
# AWS STS GitHub condition keys include job_workflow_ref, not workflow_ref.
|
|
#
|
|
# Not a Lambda execution role: no permissions_boundary. Path /tf-managed/ so
|
|
# seahaven-hcptf-iam-management DenySelfMutation (role/githubdeploy-*) does not
|
|
# match.
|
|
|
|
data "aws_iam_policy_document" "github_deploy_assume" {
|
|
statement {
|
|
sid = "GithubDeployOidc"
|
|
effect = "Allow"
|
|
actions = ["sts:AssumeRoleWithWebIdentity"]
|
|
|
|
principals {
|
|
type = "Federated"
|
|
identifiers = [local.github_oidc_provider_arn]
|
|
}
|
|
|
|
condition {
|
|
test = "StringEquals"
|
|
variable = "token.actions.githubusercontent.com:aud"
|
|
values = ["sts.amazonaws.com"]
|
|
}
|
|
|
|
condition {
|
|
test = "StringEquals"
|
|
variable = "token.actions.githubusercontent.com:sub"
|
|
values = local.github_oidc_subs
|
|
}
|
|
|
|
condition {
|
|
test = "StringLike"
|
|
variable = "token.actions.githubusercontent.com:job_workflow_ref"
|
|
values = [local.github_deploy_workflow_ref]
|
|
}
|
|
}
|
|
}
|
|
|
|
resource "aws_iam_role" "github_deploy" {
|
|
name = local.deploy_role
|
|
path = "/tf-managed/"
|
|
description = "GitHub Actions Lambda deploy role for ${var.github_repo}"
|
|
assume_role_policy = data.aws_iam_policy_document.github_deploy_assume.json
|
|
max_session_duration = 3600
|
|
}
|
|
|
|
data "aws_iam_policy_document" "github_deploy" {
|
|
statement {
|
|
sid = "ListArtifactsBucket"
|
|
effect = "Allow"
|
|
actions = [
|
|
"s3:GetBucketLocation",
|
|
"s3:ListBucket",
|
|
]
|
|
resources = [aws_s3_bucket.artifacts.arn]
|
|
}
|
|
|
|
statement {
|
|
sid = "UploadFunctionArtifacts"
|
|
effect = "Allow"
|
|
actions = [
|
|
"s3:GetObject",
|
|
"s3:PutObject",
|
|
]
|
|
resources = ["${aws_s3_bucket.artifacts.arn}/functions/*"]
|
|
}
|
|
|
|
statement {
|
|
sid = "UpdateFunctionCode"
|
|
effect = "Allow"
|
|
actions = [
|
|
"lambda:GetFunction",
|
|
"lambda:GetFunctionConfiguration",
|
|
"lambda:UpdateFunctionCode",
|
|
]
|
|
resources = [for fn in local.functions : "arn:aws:lambda:${var.aws_region}:${local.account_id}:function:${fn.function_name}"]
|
|
}
|
|
|
|
statement {
|
|
sid = "DeployParams"
|
|
effect = "Allow"
|
|
actions = [
|
|
"ssm:GetParameter",
|
|
]
|
|
resources = [
|
|
"arn:aws:ssm:${var.aws_region}:${local.account_id}:parameter${local.ssm_prefix}/deploy/*",
|
|
]
|
|
}
|
|
}
|
|
|
|
resource "aws_iam_role_policy" "github_deploy" {
|
|
name = "payments-dashboard-deploy"
|
|
role = aws_iam_role.github_deploy.id
|
|
policy = data.aws_iam_policy_document.github_deploy.json
|
|
}
|