mirror of
https://github.com/Sea-Haven-Industries/seahaven-ap.git
synced 2026-09-30 06:53:18 +00:00
fix(cd): block the Google IdP until real credentials are set
This commit is contained in:
parent
9b56475656
commit
da959dda93
4 changed files with 13 additions and 31 deletions
31
.github/workflows/oidc-claims.yaml
vendored
31
.github/workflows/oidc-claims.yaml
vendored
|
|
@ -1,31 +0,0 @@
|
|||
name: oidc-claims
|
||||
|
||||
on:
|
||||
pull_request:
|
||||
branches: [main]
|
||||
|
||||
permissions:
|
||||
contents: read
|
||||
id-token: write
|
||||
|
||||
jobs:
|
||||
claims:
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- name: Print selected OIDC claims
|
||||
run: |
|
||||
set -euo pipefail
|
||||
RESP="$(curl -fsS -H "Authorization: bearer ${ACTIONS_ID_TOKEN_REQUEST_TOKEN}" \
|
||||
"${ACTIONS_ID_TOKEN_REQUEST_URL}&audience=sts.amazonaws.com")"
|
||||
TOKEN="$(printf '%s' "${RESP}" | jq -r .value)"
|
||||
echo "::add-mask::${TOKEN}"
|
||||
PAYLOAD="$(printf '%s' "${TOKEN}" | cut -d. -f2)"
|
||||
unset TOKEN RESP
|
||||
python3 -c '
|
||||
import base64, json, sys
|
||||
raw = sys.argv[1]
|
||||
raw += "=" * (-len(raw) % 4)
|
||||
data = json.loads(base64.urlsafe_b64decode(raw))
|
||||
keep = ["sub", "job_workflow_ref", "workflow_ref", "repository", "repository_id", "repository_owner_id"]
|
||||
print(json.dumps({k: data.get(k) for k in keep}, indent=2))
|
||||
' "${PAYLOAD}"
|
||||
|
|
@ -58,6 +58,8 @@ npm run docs:preview # builds HTML via redocly build-docs and opens it
|
|||
|
||||
HCP Terraform workspace `seahaven-ap-dev` (project `seahaven-dev`) uses working directory `terraform` and a `terraform/**` VCS trigger on `main`. GitHub Environment `dev` holds `DEPLOY_ROLE_ARN` for `githubdeploy-seahaven-ap`.
|
||||
|
||||
The first apply creates secret `seahaven-ap/google-oidc` with `client_id` and `client_secret` set to `replace-me`. Replace both values in Secrets Manager, then re-run the HCP apply. A `terraform/**` change on `main` starts that apply. The Google IdP is not registered while the placeholder is still current.
|
||||
|
||||
- `.github/workflows/deploy-web.yaml` syncs `placeholder/` to the web bucket. It does not run `vite build`.
|
||||
- `.github/workflows/deploy-api.yaml` builds the API image with `GIT_SHA`, registers the task definition from `/seahaven-ap/deploy/task-environment`, migrates, and checks `GET /api/health`.
|
||||
|
||||
|
|
|
|||
|
|
@ -50,6 +50,10 @@ def test_no_hcp_iam_and_no_prod():
|
|||
assert 'supported_identity_providers = ["COGNITO", "Google"]' in cognito
|
||||
assert '"ALLOW_USER_SRP_AUTH"' in cognito
|
||||
assert "aws_secretsmanager_secret_version.google_oidc" in cognito
|
||||
assert 'local.google_oidc_client_id != "replace-me"' in cognito
|
||||
assert 'local.google_oidc_client_secret != "replace-me"' in cognito
|
||||
readme = (ROOT / "README.md").read_text()
|
||||
assert "Replace both values in Secrets Manager, then re-run the HCP apply." in readme
|
||||
secrets = (tf_dir / "secrets.tf").read_text()
|
||||
assert 'resource "aws_secretsmanager_secret_version" "google_oidc"' in secrets
|
||||
assert "ignore_changes = [secret_string]" in secrets
|
||||
|
|
|
|||
|
|
@ -138,6 +138,13 @@ resource "aws_cognito_identity_provider" "google" {
|
|||
provider_name = "Google"
|
||||
provider_type = "Google"
|
||||
|
||||
lifecycle {
|
||||
precondition {
|
||||
condition = local.google_oidc_client_id != "replace-me" && local.google_oidc_client_secret != "replace-me"
|
||||
error_message = "seahaven-ap/google-oidc still has the placeholder. Replace client_id and client_secret in Secrets Manager, then re-run the HCP apply."
|
||||
}
|
||||
}
|
||||
|
||||
provider_details = {
|
||||
client_id = local.google_oidc_client_id
|
||||
client_secret = local.google_oidc_client_secret
|
||||
|
|
|
|||
Loading…
Add table
Reference in a new issue