# Deploy role: githubdeploy-procurement-ingest (seahaven-prod) OIDC deploy role for this repo's GitHub Actions pipeline in AWS account `011934824531` (seahaven-prod), us-east-1. Created as part of the migration from the management account (328440206208); the mgmt role of the same name stays untouched until decommission as the emergency mgmt deploy path. ## Files | File | Purpose | |---|---| | `trust-policy.json` | OIDC trust: `repo:Sea-Haven-Industries/procurement-ingest:ref:refs/heads/main` only | | `permissions-policy.json` | `sts:AssumeRole` on the four `cdk-hnb659fds-*` bootstrap roles, `cloudformation:DescribeStacks` scoped to this repo's stacks + `CDKToolkit` (cd-cdk health check), and `lambda:InvokeFunction` on exactly the three smoke-gated function ARNs (post-deploy smoke gate) | | `create-deploy-role.sh` | Idempotent create-or-update from the two JSON files, profile `seahaven-prod` | > **Maintenance note:** `DescribeStacks` is scoped to `stack/po-ingest/*`, `stack/WorkorderIngestStack/*`, `stack/procurement-api/*` (added with the procurement-api stack), and `stack/CDKToolkit/*`. If another stack is ever added to this CDK app, add its ARN pattern here and re-run the review-then-apply flow — otherwise the cd-cdk health check on the new stack will `AccessDenied`. ## Why the SmokeInvokeLambda statement exists `deploy.yaml` runs `scripts/post-deploy-smoke.sh` under the deploy role's own session, not the assumed `cdk-*` roles. Without `lambda:InvokeFunction` on the smoke-gated function ARNs (the two email processors + `procurement-api`) the smoke gate hits AccessDenied and every deploy fails closed. The mgmt-era grant was applied out-of-band and undocumented; keeping it in these reviewed artifacts closes that gap. Scope it to exactly the named ARNs, never `Resource: "*"`. ## Change process 1. Edit the JSON artifacts on a branch; both gates must pass on the exact files before anything is applied: GPT-4.1 cross-family review (cross_review.py) and /sh-security-review. 2. Run `./create-deploy-role.sh` (idempotent) with the seahaven-prod profile. 3. Verify: `aws iam simulate-principal-policy` for the bootstrap-role AssumeRole and both InvokeFunction ARNs, then a real pipeline run.