diff --git a/.github/workflows/oidc-claims.yaml b/.github/workflows/oidc-claims.yaml deleted file mode 100644 index aaaa1e6..0000000 --- a/.github/workflows/oidc-claims.yaml +++ /dev/null @@ -1,31 +0,0 @@ -name: oidc-claims - -on: - pull_request: - branches: [main] - -permissions: - contents: read - id-token: write - -jobs: - claims: - runs-on: ubuntu-latest - steps: - - name: Print selected OIDC claims - run: | - set -euo pipefail - RESP="$(curl -fsS -H "Authorization: bearer ${ACTIONS_ID_TOKEN_REQUEST_TOKEN}" \ - "${ACTIONS_ID_TOKEN_REQUEST_URL}&audience=sts.amazonaws.com")" - TOKEN="$(printf '%s' "${RESP}" | jq -r .value)" - echo "::add-mask::${TOKEN}" - PAYLOAD="$(printf '%s' "${TOKEN}" | cut -d. -f2)" - unset TOKEN RESP - python3 -c ' - import base64, json, sys - raw = sys.argv[1] - raw += "=" * (-len(raw) % 4) - data = json.loads(base64.urlsafe_b64decode(raw)) - keep = ["sub", "job_workflow_ref", "workflow_ref", "repository", "repository_id", "repository_owner_id"] - print(json.dumps({k: data.get(k) for k in keep}, indent=2)) - ' "${PAYLOAD}" diff --git a/README.md b/README.md index dbd2e94..9b8c731 100644 --- a/README.md +++ b/README.md @@ -58,6 +58,8 @@ npm run docs:preview # builds HTML via redocly build-docs and opens it HCP Terraform workspace `seahaven-ap-dev` (project `seahaven-dev`) uses working directory `terraform` and a `terraform/**` VCS trigger on `main`. GitHub Environment `dev` holds `DEPLOY_ROLE_ARN` for `githubdeploy-seahaven-ap`. +The first apply creates secret `seahaven-ap/google-oidc` with `client_id` and `client_secret` set to `replace-me`. Replace both values in Secrets Manager, then re-run the HCP apply. A `terraform/**` change on `main` starts that apply. The Google IdP is not registered while the placeholder is still current. + - `.github/workflows/deploy-web.yaml` syncs `placeholder/` to the web bucket. It does not run `vite build`. - `.github/workflows/deploy-api.yaml` builds the API image with `GIT_SHA`, registers the task definition from `/seahaven-ap/deploy/task-environment`, migrates, and checks `GET /api/health`. diff --git a/scripts/test-terraform-dev-only.py b/scripts/test-terraform-dev-only.py index e36d70c..0e64cc2 100755 --- a/scripts/test-terraform-dev-only.py +++ b/scripts/test-terraform-dev-only.py @@ -50,6 +50,10 @@ def test_no_hcp_iam_and_no_prod(): assert 'supported_identity_providers = ["COGNITO", "Google"]' in cognito assert '"ALLOW_USER_SRP_AUTH"' in cognito assert "aws_secretsmanager_secret_version.google_oidc" in cognito + assert 'local.google_oidc_client_id != "replace-me"' in cognito + assert 'local.google_oidc_client_secret != "replace-me"' in cognito + readme = (ROOT / "README.md").read_text() + assert "Replace both values in Secrets Manager, then re-run the HCP apply." in readme secrets = (tf_dir / "secrets.tf").read_text() assert 'resource "aws_secretsmanager_secret_version" "google_oidc"' in secrets assert "ignore_changes = [secret_string]" in secrets diff --git a/terraform/cognito.tf b/terraform/cognito.tf index 50439a5..3c6c0c4 100644 --- a/terraform/cognito.tf +++ b/terraform/cognito.tf @@ -138,6 +138,13 @@ resource "aws_cognito_identity_provider" "google" { provider_name = "Google" provider_type = "Google" + lifecycle { + precondition { + condition = local.google_oidc_client_id != "replace-me" && local.google_oidc_client_secret != "replace-me" + error_message = "seahaven-ap/google-oidc still has the placeholder. Replace client_id and client_secret in Secrets Manager, then re-run the HCP apply." + } + } + provider_details = { client_id = local.google_oidc_client_id client_secret = local.google_oidc_client_secret