From a9fcc89362ca7b67c050cf363a78772dd922d1bc Mon Sep 17 00:00:00 2001 From: Adam Moussa Date: Tue, 14 Jul 2026 13:51:15 -0400 Subject: [PATCH] Split CD into per-account deploy jobs The app now spans two AWS accounts; cdk deploy --all under one role fails on the other account's stacks (security review IAC-01). Each job passes explicit stack selectors and its own account's OIDC role via the new cd-cdk stacks input. --- .github/workflows/deploy.yaml | 18 ++++++++++++++++-- 1 file changed, 16 insertions(+), 2 deletions(-) diff --git a/.github/workflows/deploy.yaml b/.github/workflows/deploy.yaml index 4d0aaa7..7d2717f 100644 --- a/.github/workflows/deploy.yaml +++ b/.github/workflows/deploy.yaml @@ -11,10 +11,24 @@ concurrency: group: deploy cancel-in-progress: false +# One job per target AWS account: cdk deploy with explicit stack selectors so +# each OIDC role only ever deploys its own account's stacks. A new stack added +# to bin/app.ts MUST be appended to exactly one job's `stacks` list — explicit +# selectors mean an unlisted stack is silently never deployed (security review +# SH-ORG-005). jobs: - deploy: - uses: Sea-Haven-Industries/.github/.github/workflows/cd-cdk.yaml@fd60e4c9041784f666ac0fdefb9bec3c7fbf5143 # main + deploy-management: + uses: Sea-Haven-Industries/.github/.github/workflows/cd-cdk.yaml@3cde673b9d05c0e68aac4d997d582f2543853d20 # main with: node-version: "24" + stacks: "account-baseline dynamodb-cmk regional-baseline-us-west-2 regional-baseline-us-east-2 backup-offsite backup" secrets: deploy-role-arn: ${{ secrets.AWS_DEPLOY_ROLE_ARN }} + + deploy-external-dev: + uses: Sea-Haven-Industries/.github/.github/workflows/cd-cdk.yaml@3cde673b9d05c0e68aac4d997d582f2543853d20 # main + with: + node-version: "24" + stacks: "external-dev-baseline" + secrets: + deploy-role-arn: ${{ secrets.AWS_DEPLOY_ROLE_ARN_EXTDEV }}