mirror of
https://github.com/Sea-Haven-Industries/procurement-ingest.git
synced 2026-10-01 14:43:13 +00:00
35 lines
2.2 KiB
Markdown
35 lines
2.2 KiB
Markdown
# Deploy role: githubdeploy-procurement-ingest (seahaven-prod)
|
|
|
|
OIDC deploy role for this repo's GitHub Actions pipeline in AWS account
|
|
`011934824531` (seahaven-prod), us-east-1. Created during the migration from
|
|
the management account (328440206208). The former mgmt twin of this role was
|
|
deleted in PLAT-67 (2026-08-05); do not recreate it.
|
|
|
|
## Files
|
|
|
|
| File | Purpose |
|
|
|---|---|
|
|
| `trust-policy.json` | OIDC trust: `repo:Sea-Haven-Industries/procurement-ingest:ref:refs/heads/main` only |
|
|
| `permissions-policy.json` | `sts:AssumeRole` on the four `cdk-hnb659fds-*` bootstrap roles, `cloudformation:DescribeStacks` scoped to this repo's stacks + `CDKToolkit` (cd-cdk health check), and `lambda:InvokeFunction` on exactly the three smoke-gated function ARNs (post-deploy smoke gate) |
|
|
| `create-deploy-role.sh` | Idempotent create-or-update from the two JSON files, profile `seahaven-prod` |
|
|
|
|
> **Maintenance note:** `DescribeStacks` is scoped to `stack/po-ingest/*`, `stack/WorkorderIngestStack/*`, `stack/procurement-api/*` (added with the procurement-api stack), and `stack/CDKToolkit/*`. If another stack is ever added to this CDK app, add its ARN pattern here and re-run the review-then-apply flow — otherwise the cd-cdk health check on the new stack will `AccessDenied`.
|
|
|
|
## Why the SmokeInvokeLambda statement exists
|
|
|
|
`deploy.yaml` runs `scripts/post-deploy-smoke.sh` under the deploy role's own
|
|
session, not the assumed `cdk-*` roles. Without `lambda:InvokeFunction` on the
|
|
smoke-gated function ARNs (the two email processors + `procurement-api`) the
|
|
smoke gate hits AccessDenied and every deploy fails closed. The mgmt-era grant
|
|
was applied out-of-band and undocumented; keeping it in these reviewed
|
|
artifacts closes that gap. Scope it to exactly the named ARNs, never
|
|
`Resource: "*"`.
|
|
|
|
## Change process
|
|
|
|
1. Edit the JSON artifacts on a branch; both gates must pass on the exact
|
|
files before anything is applied: GPT-4.1 cross-family review
|
|
(cross_review.py) and /sh-security-review.
|
|
2. Run `./create-deploy-role.sh` (idempotent) with the seahaven-prod profile.
|
|
3. Verify: `aws iam simulate-principal-policy` for the bootstrap-role
|
|
AssumeRole and both InvokeFunction ARNs, then a real pipeline run.
|