#!/usr/bin/env bash ############################################################################### # teardown-assessment-reader.sh # # Deletes the temporary `shoc-assessment-dynamo-reader` role in seahaven-prod # (011934824531). Run once the Luby initial assessment is complete — and this # is ALSO the emergency kill switch: a successful DeleteRole immediately # invalidates all outstanding session credentials for the role. # # DeleteRole fails with DeleteConflict while ANY policy remains on the role # (including the inline `AWSRevokeOlderSessions` policy the IAM console's # "Revoke active sessions" button attaches), so this script enumerates and # strips ALL inline policies, attached managed policies, and instance-profile # memberships first. Idempotent: a rerun after the role is gone exits 0. ############################################################################### set -euo pipefail PROFILE="seahaven-prod" ROLE_NAME="shoc-assessment-dynamo-reader" ACCOUNT_ID="011934824531" CALLER_ACCOUNT="$(aws --profile "${PROFILE}" sts get-caller-identity --query Account --output text)" if [[ "${CALLER_ACCOUNT}" != "${ACCOUNT_ID}" ]]; then echo "ERROR: profile '${PROFILE}' resolves to account ${CALLER_ACCOUNT}, expected ${ACCOUNT_ID}. Aborting." >&2 exit 1 fi if ! aws --profile "${PROFILE}" iam get-role --role-name "${ROLE_NAME}" >/dev/null 2>&1; then echo "==> Role '${ROLE_NAME}' already absent in ${ACCOUNT_ID} - nothing to do." exit 0 fi echo "==> Deleting ALL inline policies on '${ROLE_NAME}'..." for POLICY in $(aws --profile "${PROFILE}" iam list-role-policies \ --role-name "${ROLE_NAME}" --query 'PolicyNames[]' --output text); do echo " delete-role-policy ${POLICY}" aws --profile "${PROFILE}" iam delete-role-policy \ --role-name "${ROLE_NAME}" --policy-name "${POLICY}" done echo "==> Detaching ALL managed policies on '${ROLE_NAME}'..." for POLICY_ARN in $(aws --profile "${PROFILE}" iam list-attached-role-policies \ --role-name "${ROLE_NAME}" --query 'AttachedPolicies[].PolicyArn' --output text); do echo " detach-role-policy ${POLICY_ARN}" aws --profile "${PROFILE}" iam detach-role-policy \ --role-name "${ROLE_NAME}" --policy-arn "${POLICY_ARN}" done echo "==> Removing '${ROLE_NAME}' from any instance profiles..." for IP in $(aws --profile "${PROFILE}" iam list-instance-profiles-for-role \ --role-name "${ROLE_NAME}" --query 'InstanceProfiles[].InstanceProfileName' --output text); do echo " remove-role-from-instance-profile ${IP}" aws --profile "${PROFILE}" iam remove-role-from-instance-profile \ --instance-profile-name "${IP}" --role-name "${ROLE_NAME}" done echo "==> Deleting role '${ROLE_NAME}' (this invalidates all outstanding sessions)..." aws --profile "${PROFILE}" iam delete-role --role-name "${ROLE_NAME}" echo "==> Done. ${ROLE_NAME} removed from ${ACCOUNT_ID}; all live sessions are dead."