fix(cd): block the Google IdP until real credentials are set

This commit is contained in:
Adam Moussa 2026-09-26 16:39:28 -04:00
parent 9b56475656
commit da959dda93
No known key found for this signature in database
4 changed files with 13 additions and 31 deletions

View file

@ -1,31 +0,0 @@
name: oidc-claims
on:
pull_request:
branches: [main]
permissions:
contents: read
id-token: write
jobs:
claims:
runs-on: ubuntu-latest
steps:
- name: Print selected OIDC claims
run: |
set -euo pipefail
RESP="$(curl -fsS -H "Authorization: bearer ${ACTIONS_ID_TOKEN_REQUEST_TOKEN}" \
"${ACTIONS_ID_TOKEN_REQUEST_URL}&audience=sts.amazonaws.com")"
TOKEN="$(printf '%s' "${RESP}" | jq -r .value)"
echo "::add-mask::${TOKEN}"
PAYLOAD="$(printf '%s' "${TOKEN}" | cut -d. -f2)"
unset TOKEN RESP
python3 -c '
import base64, json, sys
raw = sys.argv[1]
raw += "=" * (-len(raw) % 4)
data = json.loads(base64.urlsafe_b64decode(raw))
keep = ["sub", "job_workflow_ref", "workflow_ref", "repository", "repository_id", "repository_owner_id"]
print(json.dumps({k: data.get(k) for k in keep}, indent=2))
' "${PAYLOAD}"

View file

@ -58,6 +58,8 @@ npm run docs:preview # builds HTML via redocly build-docs and opens it
HCP Terraform workspace `seahaven-ap-dev` (project `seahaven-dev`) uses working directory `terraform` and a `terraform/**` VCS trigger on `main`. GitHub Environment `dev` holds `DEPLOY_ROLE_ARN` for `githubdeploy-seahaven-ap`.
The first apply creates secret `seahaven-ap/google-oidc` with `client_id` and `client_secret` set to `replace-me`. Replace both values in Secrets Manager, then re-run the HCP apply. A `terraform/**` change on `main` starts that apply. The Google IdP is not registered while the placeholder is still current.
- `.github/workflows/deploy-web.yaml` syncs `placeholder/` to the web bucket. It does not run `vite build`.
- `.github/workflows/deploy-api.yaml` builds the API image with `GIT_SHA`, registers the task definition from `/seahaven-ap/deploy/task-environment`, migrates, and checks `GET /api/health`.

View file

@ -50,6 +50,10 @@ def test_no_hcp_iam_and_no_prod():
assert 'supported_identity_providers = ["COGNITO", "Google"]' in cognito
assert '"ALLOW_USER_SRP_AUTH"' in cognito
assert "aws_secretsmanager_secret_version.google_oidc" in cognito
assert 'local.google_oidc_client_id != "replace-me"' in cognito
assert 'local.google_oidc_client_secret != "replace-me"' in cognito
readme = (ROOT / "README.md").read_text()
assert "Replace both values in Secrets Manager, then re-run the HCP apply." in readme
secrets = (tf_dir / "secrets.tf").read_text()
assert 'resource "aws_secretsmanager_secret_version" "google_oidc"' in secrets
assert "ignore_changes = [secret_string]" in secrets

View file

@ -138,6 +138,13 @@ resource "aws_cognito_identity_provider" "google" {
provider_name = "Google"
provider_type = "Google"
lifecycle {
precondition {
condition = local.google_oidc_client_id != "replace-me" && local.google_oidc_client_secret != "replace-me"
error_message = "seahaven-ap/google-oidc still has the placeholder. Replace client_id and client_secret in Secrets Manager, then re-run the HCP apply."
}
}
provider_details = {
client_id = local.google_oidc_client_id
client_secret = local.google_oidc_client_secret