mirror of
https://github.com/Sea-Haven-Industries/procurement-ingest.git
synced 2026-10-07 16:08:54 +00:00
Delete retired CDK sources, retarget bundle/principal contract tests to Terraform packaging, disable CDK synth in CI, and scrub deploy-adjacent docs.
77 lines
2.9 KiB
Python
77 lines
2.9 KiB
Python
"""Pin the cross-account principal surface of the Terraform app.
|
|
|
|
The SHOC integration deliberately trusts EXACTLY ONE foreign principal:
|
|
``arn:aws:iam::396287094661:role/shoc-backend-dev`` (API resource policy in
|
|
api.tf, HMAC secret + KMS grants in wo_shoc.tf; documented literal in
|
|
variables.tf + terraform.tfvars.example). Future shoc-backend-staging/-prod
|
|
roles are each a deliberate, individually-reviewed policy addition — so any
|
|
new foreign account id or role ARN appearing under terraform/ must consciously
|
|
update this pin (and go through the mandatory GPT-4.1 cross-family IAM review).
|
|
|
|
Raised as a QUESTION in the 2026-07-24 cross-family review of the
|
|
webhook emitter policy surface: "how is the exact-one-principal
|
|
invariant enforced over time?" — this test is the answer.
|
|
"""
|
|
|
|
import re
|
|
from pathlib import Path
|
|
|
|
REPO_ROOT = Path(__file__).resolve().parents[1]
|
|
TF_DIR = REPO_ROOT / "terraform"
|
|
|
|
# The one foreign principal the app may reference as a literal ARN, and the
|
|
# only files allowed to embed that literal (grants use the variable).
|
|
ALLOWED_FOREIGN_PRINCIPAL = "arn:aws:iam::396287094661:role/shoc-backend-dev"
|
|
ALLOWED_LITERAL_FILES = {"variables.tf", "terraform.tfvars.example"}
|
|
|
|
# Grant sites must keep referencing the variable so dropping one half of the
|
|
# secret/KMS/API trust surface fails this pin.
|
|
GRANT_FILES = {
|
|
"api.tf": "shoc_consumer_role_arn",
|
|
"wo_shoc.tf": "shoc_consumer_role_arn",
|
|
}
|
|
|
|
# Accounts that are not "foreign": seahaven-prod (the deploy target).
|
|
HOME_ACCOUNTS = {"011934824531"}
|
|
|
|
_IAM_ARN_RE = re.compile(r"arn:aws:iam::(\d{12}):\S*?(?=[\"'\s])")
|
|
|
|
|
|
def _terraform_sources():
|
|
paths = sorted(TF_DIR.glob("*.tf"))
|
|
example = TF_DIR / "terraform.tfvars.example"
|
|
if example.exists():
|
|
paths.append(example)
|
|
return paths
|
|
|
|
|
|
def test_only_the_pinned_foreign_principal_appears_in_terraform_sources():
|
|
findings = []
|
|
for path in _terraform_sources():
|
|
for match in _IAM_ARN_RE.finditer(path.read_text()):
|
|
account = match.group(1)
|
|
if account in HOME_ACCOUNTS:
|
|
continue
|
|
findings.append((path.name, match.group(0)))
|
|
|
|
unexpected = [
|
|
(name, arn)
|
|
for name, arn in findings
|
|
if arn != ALLOWED_FOREIGN_PRINCIPAL or name not in ALLOWED_LITERAL_FILES
|
|
]
|
|
assert not unexpected, (
|
|
"Unexpected foreign IAM principal(s) under terraform/ — every "
|
|
"cross-account trust addition must update this pin deliberately: "
|
|
f"{unexpected}"
|
|
)
|
|
# Both documentation/example sites must still name the pinned role.
|
|
assert {name for name, _ in findings} == ALLOWED_LITERAL_FILES
|
|
|
|
|
|
def test_grant_files_reference_shoc_consumer_role_arn():
|
|
for filename, needle in GRANT_FILES.items():
|
|
text = (TF_DIR / filename).read_text()
|
|
assert needle in text, (
|
|
f"{filename} must reference {needle} so the SHOC cross-account "
|
|
"grant surface cannot silently drop one half of the trust pair"
|
|
)
|