fix(iam): attach scoped IAM as a managed policy (PLAT-146)

The apply role's services inline already uses 6894 of 10240 bytes, so a second inline policy cannot hold scoped IAM.
This commit is contained in:
Adam Moussa 2026-09-02 15:06:03 -04:00
parent e72873409e
commit fa6bcc90cc
No known key found for this signature in database

View file

@ -8,7 +8,7 @@
# 2. Point this workspace's TFC_AWS_* at hcptf-bootstrap /
# hcptf-bootstrap-plan (workspace vars, never a project set).
# 3. One Manual apply (import + detach seahaven-hcptf-iam-management +
# put scoped inline).
# put scoped IAM as a customer-managed policy).
# 4. Point TFC_AWS_* back at hcptf-procurement-ingest / hcptf-procurement-ingest-plan.
# 5. Re-run the script without --allow-workspace to pin trust back to
# iam-bootstrap-prod only.
@ -821,10 +821,14 @@ resource "aws_iam_role" "hcptf_apply" {
}
}
# Empty exclusive set keeps seahaven-hcptf-iam-management detached.
# Services inline is 6894 bytes; a second inline for scoped IAM exceeds the
# 10240 role quota. Attach scoped IAM as a customer-managed policy instead.
# Exclusive set keeps seahaven-hcptf-iam-management detached.
resource "aws_iam_role_policy_attachments_exclusive" "hcptf_apply" {
role_name = aws_iam_role.hcptf_apply.name
policy_arns = []
role_name = aws_iam_role.hcptf_apply.name
policy_arns = [
aws_iam_policy.hcptf_scoped_iam.arn,
]
}
resource "aws_iam_role" "hcptf_plan" {
@ -851,8 +855,19 @@ resource "aws_iam_role_policy_attachments_exclusive" "hcptf_plan" {
]
}
resource "aws_iam_role_policy" "hcptf_scoped_iam" {
name = "scoped-iam-management"
role = aws_iam_role.hcptf_apply.id
resource "aws_iam_policy" "hcptf_scoped_iam" {
name = "hcptf-procurement-ingest-scoped-iam"
path = "/tf-managed/"
policy = data.aws_iam_policy_document.hcptf_scoped_iam.json
tags = {
Project = "procurement-ingest"
Owner = "adam@seahavenind.com"
ManagedBy = "terraform"
}
}
resource "aws_iam_role_policy_attachment" "hcptf_scoped_iam" {
role = aws_iam_role.hcptf_apply.name
policy_arn = aws_iam_policy.hcptf_scoped_iam.arn
}