fix(iam): attach scoped IAM as a managed policy (PLAT-146)

The apply role's services inline already uses 6894 of 10240 bytes, so a second inline policy cannot hold scoped IAM.
This commit is contained in:
Adam Moussa 2026-09-02 15:06:03 -04:00
parent e72873409e
commit fa6bcc90cc
No known key found for this signature in database

View file

@ -8,7 +8,7 @@
# 2. Point this workspace's TFC_AWS_* at hcptf-bootstrap / # 2. Point this workspace's TFC_AWS_* at hcptf-bootstrap /
# hcptf-bootstrap-plan (workspace vars, never a project set). # hcptf-bootstrap-plan (workspace vars, never a project set).
# 3. One Manual apply (import + detach seahaven-hcptf-iam-management + # 3. One Manual apply (import + detach seahaven-hcptf-iam-management +
# put scoped inline). # put scoped IAM as a customer-managed policy).
# 4. Point TFC_AWS_* back at hcptf-procurement-ingest / hcptf-procurement-ingest-plan. # 4. Point TFC_AWS_* back at hcptf-procurement-ingest / hcptf-procurement-ingest-plan.
# 5. Re-run the script without --allow-workspace to pin trust back to # 5. Re-run the script without --allow-workspace to pin trust back to
# iam-bootstrap-prod only. # iam-bootstrap-prod only.
@ -821,10 +821,14 @@ resource "aws_iam_role" "hcptf_apply" {
} }
} }
# Empty exclusive set keeps seahaven-hcptf-iam-management detached. # Services inline is 6894 bytes; a second inline for scoped IAM exceeds the
# 10240 role quota. Attach scoped IAM as a customer-managed policy instead.
# Exclusive set keeps seahaven-hcptf-iam-management detached.
resource "aws_iam_role_policy_attachments_exclusive" "hcptf_apply" { resource "aws_iam_role_policy_attachments_exclusive" "hcptf_apply" {
role_name = aws_iam_role.hcptf_apply.name role_name = aws_iam_role.hcptf_apply.name
policy_arns = [] policy_arns = [
aws_iam_policy.hcptf_scoped_iam.arn,
]
} }
resource "aws_iam_role" "hcptf_plan" { resource "aws_iam_role" "hcptf_plan" {
@ -851,8 +855,19 @@ resource "aws_iam_role_policy_attachments_exclusive" "hcptf_plan" {
] ]
} }
resource "aws_iam_role_policy" "hcptf_scoped_iam" { resource "aws_iam_policy" "hcptf_scoped_iam" {
name = "scoped-iam-management" name = "hcptf-procurement-ingest-scoped-iam"
role = aws_iam_role.hcptf_apply.id path = "/tf-managed/"
policy = data.aws_iam_policy_document.hcptf_scoped_iam.json policy = data.aws_iam_policy_document.hcptf_scoped_iam.json
tags = {
Project = "procurement-ingest"
Owner = "adam@seahavenind.com"
ManagedBy = "terraform"
}
}
resource "aws_iam_role_policy_attachment" "hcptf_scoped_iam" {
role = aws_iam_role.hcptf_apply.name
policy_arn = aws_iam_policy.hcptf_scoped_iam.arn
} }