2.2 KiB
Deploy role: githubdeploy-procurement-ingest (seahaven-prod)
OIDC deploy role for this repo's GitHub Actions pipeline in AWS account
011934824531 (seahaven-prod), us-east-1. Created during the migration from
the management account (328440206208). The former mgmt twin of this role was
deleted in PLAT-67 (2026-08-05); do not recreate it.
Files
| File | Purpose |
|---|---|
trust-policy.json |
OIDC trust: repo:Sea-Haven-Industries/procurement-ingest:ref:refs/heads/main only |
permissions-policy.json |
sts:AssumeRole on the four cdk-hnb659fds-* bootstrap roles, cloudformation:DescribeStacks scoped to this repo's stacks + CDKToolkit (cd-cdk health check), and lambda:InvokeFunction on exactly the three smoke-gated function ARNs (post-deploy smoke gate) |
create-deploy-role.sh |
Idempotent create-or-update from the two JSON files, profile seahaven-prod |
Maintenance note:
DescribeStacksis scoped tostack/po-ingest/*,stack/WorkorderIngestStack/*,stack/procurement-api/*(added with the procurement-api stack), andstack/CDKToolkit/*. If another stack is ever added to this CDK app, add its ARN pattern here and re-run the review-then-apply flow — otherwise the cd-cdk health check on the new stack willAccessDenied.
Why the SmokeInvokeLambda statement exists
deploy.yaml runs scripts/post-deploy-smoke.sh under the deploy role's own
session, not the assumed cdk-* roles. Without lambda:InvokeFunction on the
smoke-gated function ARNs (the two email processors + procurement-api) the
smoke gate hits AccessDenied and every deploy fails closed. The mgmt-era grant
was applied out-of-band and undocumented; keeping it in these reviewed
artifacts closes that gap. Scope it to exactly the named ARNs, never
Resource: "*".
Change process
- Edit the JSON artifacts on a branch; both gates must pass on the exact files before anything is applied: GPT-4.1 cross-family review (cross_review.py) and /sh-security-review.
- Run
./create-deploy-role.sh(idempotent) with the seahaven-prod profile. - Verify:
aws iam simulate-principal-policyfor the bootstrap-role AssumeRole and both InvokeFunction ARNs, then a real pipeline run.