procurement-ingest/infra/deploy-role
Adam Moussa 5b3e20bd35
Some checks failed
Deploy / deploy (push) Has been cancelled
chore(docs): drop mgmt dual-delivery rollback language (#159)
2026-08-04 20:24:38 -04:00
..
create-deploy-role.sh chore(docs): drop mgmt dual-delivery rollback language (#159) 2026-08-04 20:24:38 -04:00
permissions-policy.json feat(api): procurement-api read stack + OpenAPI docs (SHOC reconciliation path) (#127) 2026-07-23 19:32:20 -04:00
README.md chore(docs): drop mgmt dual-delivery rollback language (#159) 2026-08-04 20:24:38 -04:00
trust-policy.json Migrate to seahaven-prod: deploy role, backfill tooling, account-portability fixes (#125) 2026-07-23 17:08:47 -04:00

Deploy role: githubdeploy-procurement-ingest (seahaven-prod)

OIDC deploy role for this repo's GitHub Actions pipeline in AWS account 011934824531 (seahaven-prod), us-east-1. Created during the migration from the management account (328440206208). The former mgmt twin of this role was deleted in PLAT-67 (2026-08-05); do not recreate it.

Files

File Purpose
trust-policy.json OIDC trust: repo:Sea-Haven-Industries/procurement-ingest:ref:refs/heads/main only
permissions-policy.json sts:AssumeRole on the four cdk-hnb659fds-* bootstrap roles, cloudformation:DescribeStacks scoped to this repo's stacks + CDKToolkit (cd-cdk health check), and lambda:InvokeFunction on exactly the three smoke-gated function ARNs (post-deploy smoke gate)
create-deploy-role.sh Idempotent create-or-update from the two JSON files, profile seahaven-prod

Maintenance note: DescribeStacks is scoped to stack/po-ingest/*, stack/WorkorderIngestStack/*, stack/procurement-api/* (added with the procurement-api stack), and stack/CDKToolkit/*. If another stack is ever added to this CDK app, add its ARN pattern here and re-run the review-then-apply flow — otherwise the cd-cdk health check on the new stack will AccessDenied.

Why the SmokeInvokeLambda statement exists

deploy.yaml runs scripts/post-deploy-smoke.sh under the deploy role's own session, not the assumed cdk-* roles. Without lambda:InvokeFunction on the smoke-gated function ARNs (the two email processors + procurement-api) the smoke gate hits AccessDenied and every deploy fails closed. The mgmt-era grant was applied out-of-band and undocumented; keeping it in these reviewed artifacts closes that gap. Scope it to exactly the named ARNs, never Resource: "*".

Change process

  1. Edit the JSON artifacts on a branch; both gates must pass on the exact files before anything is applied: GPT-4.1 cross-family review (cross_review.py) and /sh-security-review.
  2. Run ./create-deploy-role.sh (idempotent) with the seahaven-prod profile.
  3. Verify: aws iam simulate-principal-policy for the bootstrap-role AssumeRole and both InvokeFunction ARNs, then a real pipeline run.