mirror of
https://github.com/Sea-Haven-Industries/procurement-ingest.git
synced 2026-10-04 09:01:57 +00:00
35 lines
2.1 KiB
Markdown
35 lines
2.1 KiB
Markdown
|
|
# Deploy role: githubdeploy-procurement-ingest (seahaven-prod)
|
||
|
|
|
||
|
|
OIDC deploy role for this repo's GitHub Actions pipeline in AWS account
|
||
|
|
`011934824531` (seahaven-prod), us-east-1. Created as part of the migration
|
||
|
|
from the management account (328440206208); the mgmt role of the same name
|
||
|
|
stays untouched until decommission as the emergency mgmt deploy path.
|
||
|
|
|
||
|
|
## Files
|
||
|
|
|
||
|
|
| File | Purpose |
|
||
|
|
|---|---|
|
||
|
|
| `trust-policy.json` | OIDC trust: `repo:Sea-Haven-Industries/procurement-ingest:ref:refs/heads/main` only |
|
||
|
|
| `permissions-policy.json` | `sts:AssumeRole` on the four `cdk-hnb659fds-*` bootstrap roles, `cloudformation:DescribeStacks` scoped to this repo's stacks + `CDKToolkit` (cd-cdk health check), and `lambda:InvokeFunction` on exactly the two email-processor function ARNs (post-deploy smoke gate) |
|
||
|
|
| `create-deploy-role.sh` | Idempotent create-or-update from the two JSON files, profile `seahaven-prod` |
|
||
|
|
|
||
|
|
> **Maintenance note:** `DescribeStacks` is scoped to `stack/po-ingest/*`, `stack/WorkorderIngestStack/*`, and `stack/CDKToolkit/*`. If a third stack is ever added to this CDK app, add its ARN pattern here and re-run the review-then-apply flow — otherwise the cd-cdk health check on the new stack will `AccessDenied`.
|
||
|
|
|
||
|
|
## Why the SmokeInvokeLambda statement exists
|
||
|
|
|
||
|
|
`deploy.yaml` runs `scripts/post-deploy-smoke.sh` under the deploy role's own
|
||
|
|
session, not the assumed `cdk-*` roles. Without `lambda:InvokeFunction` on the
|
||
|
|
two function ARNs the smoke gate hits AccessDenied and every deploy fails
|
||
|
|
closed. The mgmt-era grant was applied out-of-band and undocumented; keeping
|
||
|
|
it in these reviewed artifacts closes that gap. Scope it to exactly the two
|
||
|
|
ARNs, never `Resource: "*"`.
|
||
|
|
|
||
|
|
## Change process
|
||
|
|
|
||
|
|
1. Edit the JSON artifacts on a branch; both gates must pass on the exact
|
||
|
|
files before anything is applied: GPT-4.1 cross-family review
|
||
|
|
(cross_review.py) and /sh-security-review.
|
||
|
|
2. Run `./create-deploy-role.sh` (idempotent) with the seahaven-prod profile.
|
||
|
|
3. Verify: `aws iam simulate-principal-policy` for the bootstrap-role
|
||
|
|
AssumeRole and both InvokeFunction ARNs, then a real pipeline run.
|