mirror of
https://github.com/Sea-Haven-Industries/seahaven-account-baseline.git
synced 2026-08-04 16:56:14 +00:00
New stack seahaven-terraform-substrate (instances terraform-substrate-prod + terraform-substrate-dev): app.terraform.io OIDC provider and the shared boundary-gated guardrail policy seahaven-hcptf-iam-management that per-workspace Terraform apply roles attach at migration time. No roles are pre-provisioned (accumulator pattern, parallel to githubdeploy-*). Guardrail statements mirror seahaven-cfn-exec-iam-management byte-identically except DenySelfMutation, whose scope extends to hcptf-* alongside the GitHub-substrate principals. Explicit stack dependency on the same-account deploy-substrate stack (boundary ARN appears only in Condition strings, so CFN infers no edge).
62 lines
2.2 KiB
YAML
62 lines
2.2 KiB
YAML
name: Deploy
|
|
on:
|
|
push:
|
|
branches: [main]
|
|
|
|
permissions:
|
|
id-token: write
|
|
contents: read
|
|
|
|
concurrency:
|
|
group: deploy
|
|
cancel-in-progress: false
|
|
|
|
# One job per target AWS account: cdk deploy with explicit stack selectors so
|
|
# each OIDC role only ever deploys its own account's stacks. A new stack added
|
|
# to bin/app.ts MUST be appended to exactly one job's `stacks` list — explicit
|
|
# selectors mean an unlisted stack is silently never deployed (security review
|
|
# SH-ORG-005).
|
|
|
|
jobs:
|
|
deploy-management:
|
|
uses: Sea-Haven-Industries/.github/.github/workflows/cd-cdk.yaml@0170a57c0d99b542cfafd1f3e1d369c32643f486 # v1.0.2
|
|
with:
|
|
node-version: "24"
|
|
stacks: "account-baseline dynamodb-cmk regional-baseline-us-west-2 regional-baseline-us-east-2 backup-offsite backup org-governance"
|
|
secrets:
|
|
deploy-role-arn: ${{ secrets.AWS_DEPLOY_ROLE_ARN }}
|
|
|
|
deploy-external-dev:
|
|
uses: Sea-Haven-Industries/.github/.github/workflows/cd-cdk.yaml@0170a57c0d99b542cfafd1f3e1d369c32643f486 # v1.0.2
|
|
with:
|
|
node-version: "24"
|
|
stacks: "external-dev-baseline"
|
|
secrets:
|
|
deploy-role-arn: ${{ secrets.AWS_DEPLOY_ROLE_ARN_EXTDEV }}
|
|
|
|
deploy-security:
|
|
uses: Sea-Haven-Industries/.github/.github/workflows/cd-cdk.yaml@0170a57c0d99b542cfafd1f3e1d369c32643f486 # v1.0.2
|
|
with:
|
|
node-version: "24"
|
|
stacks: "security-baseline"
|
|
stack-name: "seahaven-security-baseline"
|
|
secrets:
|
|
deploy-role-arn: ${{ secrets.AWS_DEPLOY_ROLE_ARN_SECURITY }}
|
|
|
|
deploy-dev:
|
|
uses: Sea-Haven-Industries/.github/.github/workflows/cd-cdk.yaml@0170a57c0d99b542cfafd1f3e1d369c32643f486 # v1.0.2
|
|
with:
|
|
node-version: "24"
|
|
stacks: "dev-baseline deploy-substrate-dev terraform-substrate-dev"
|
|
stack-name: "seahaven-dev-baseline"
|
|
secrets:
|
|
deploy-role-arn: ${{ secrets.AWS_DEPLOY_ROLE_ARN_DEV }}
|
|
|
|
deploy-prod:
|
|
uses: Sea-Haven-Industries/.github/.github/workflows/cd-cdk.yaml@0170a57c0d99b542cfafd1f3e1d369c32643f486 # v1.0.2
|
|
with:
|
|
node-version: "24"
|
|
stacks: "prod-baseline dynamodb-cmk-prod alarm-topic-prod deploy-substrate-prod terraform-substrate-prod"
|
|
stack-name: "seahaven-prod-baseline"
|
|
secrets:
|
|
deploy-role-arn: ${{ secrets.AWS_DEPLOY_ROLE_ARN_PROD }}
|