procurement-ingest/tests/test_cross_account_principal_pin.py
Adam Moussa e5f9e2d5f0
chore(infra): remove cdk tree after hcp cutover
Delete retired CDK sources, retarget bundle/principal contract tests to
Terraform packaging, disable CDK synth in CI, and scrub deploy-adjacent docs.
2026-08-07 12:03:25 -04:00

77 lines
2.9 KiB
Python

"""Pin the cross-account principal surface of the Terraform app.
The SHOC integration deliberately trusts EXACTLY ONE foreign principal:
``arn:aws:iam::396287094661:role/shoc-backend-dev`` (API resource policy in
api.tf, HMAC secret + KMS grants in wo_shoc.tf; documented literal in
variables.tf + terraform.tfvars.example). Future shoc-backend-staging/-prod
roles are each a deliberate, individually-reviewed policy addition — so any
new foreign account id or role ARN appearing under terraform/ must consciously
update this pin (and go through the mandatory GPT-4.1 cross-family IAM review).
Raised as a QUESTION in the 2026-07-24 cross-family review of the
webhook emitter policy surface: "how is the exact-one-principal
invariant enforced over time?" — this test is the answer.
"""
import re
from pathlib import Path
REPO_ROOT = Path(__file__).resolve().parents[1]
TF_DIR = REPO_ROOT / "terraform"
# The one foreign principal the app may reference as a literal ARN, and the
# only files allowed to embed that literal (grants use the variable).
ALLOWED_FOREIGN_PRINCIPAL = "arn:aws:iam::396287094661:role/shoc-backend-dev"
ALLOWED_LITERAL_FILES = {"variables.tf", "terraform.tfvars.example"}
# Grant sites must keep referencing the variable so dropping one half of the
# secret/KMS/API trust surface fails this pin.
GRANT_FILES = {
"api.tf": "shoc_consumer_role_arn",
"wo_shoc.tf": "shoc_consumer_role_arn",
}
# Accounts that are not "foreign": seahaven-prod (the deploy target).
HOME_ACCOUNTS = {"011934824531"}
_IAM_ARN_RE = re.compile(r"arn:aws:iam::(\d{12}):\S*?(?=[\"'\s])")
def _terraform_sources():
paths = sorted(TF_DIR.glob("*.tf"))
example = TF_DIR / "terraform.tfvars.example"
if example.exists():
paths.append(example)
return paths
def test_only_the_pinned_foreign_principal_appears_in_terraform_sources():
findings = []
for path in _terraform_sources():
for match in _IAM_ARN_RE.finditer(path.read_text()):
account = match.group(1)
if account in HOME_ACCOUNTS:
continue
findings.append((path.name, match.group(0)))
unexpected = [
(name, arn)
for name, arn in findings
if arn != ALLOWED_FOREIGN_PRINCIPAL or name not in ALLOWED_LITERAL_FILES
]
assert not unexpected, (
"Unexpected foreign IAM principal(s) under terraform/ — every "
"cross-account trust addition must update this pin deliberately: "
f"{unexpected}"
)
# Both documentation/example sites must still name the pinned role.
assert {name for name, _ in findings} == ALLOWED_LITERAL_FILES
def test_grant_files_reference_shoc_consumer_role_arn():
for filename, needle in GRANT_FILES.items():
text = (TF_DIR / filename).read_text()
assert needle in text, (
f"{filename} must reference {needle} so the SHOC cross-account "
"grant surface cannot silently drop one half of the trust pair"
)