data "aws_iam_policy_document" "github_deploy_assume" { statement { sid = "GithubDeployOidc" effect = "Allow" actions = ["sts:AssumeRoleWithWebIdentity"] principals { type = "Federated" identifiers = [local.github_oidc_provider_arn] } condition { test = "StringEquals" variable = "token.actions.githubusercontent.com:aud" values = ["sts.amazonaws.com"] } condition { test = "StringEquals" variable = "token.actions.githubusercontent.com:sub" values = ["repo:Sea-Haven-Industries@183236204/seahaven-ap@1330218238:environment:dev"] } condition { test = "StringEquals" variable = "token.actions.githubusercontent.com:job_workflow_ref" values = [ "${var.github_repo}/.github/workflows/deploy-web.yaml@refs/heads/${var.github_deploy_branch}", "${var.github_repo}/.github/workflows/deploy-api.yaml@refs/heads/${var.github_deploy_branch}", ] } } } resource "aws_iam_role" "github_deploy" { name = local.deploy_role path = "/tf-managed/" description = "GitHub Actions SPA and API deploy role for ${var.github_repo} Environment dev" assume_role_policy = data.aws_iam_policy_document.github_deploy_assume.json permissions_boundary = data.aws_iam_policy.github_deploy_boundary.arn max_session_duration = 3600 } data "aws_iam_policy_document" "github_deploy" { statement { sid = "ListWebBucket" effect = "Allow" actions = [ "s3:GetBucketLocation", "s3:ListBucket", ] resources = [aws_s3_bucket.web.arn] } statement { sid = "SyncWebBucket" effect = "Allow" actions = [ "s3:GetObject", "s3:PutObject", "s3:DeleteObject", ] resources = ["${aws_s3_bucket.web.arn}/*"] } statement { sid = "InvalidateDistribution" effect = "Allow" actions = [ "cloudfront:CreateInvalidation", "cloudfront:GetInvalidation", "cloudfront:GetDistribution", ] resources = [aws_cloudfront_distribution.web.arn] } statement { sid = "EcrAuth" effect = "Allow" actions = [ "ecr:GetAuthorizationToken", ] resources = ["*"] } statement { sid = "EcrPush" effect = "Allow" actions = [ "ecr:BatchCheckLayerAvailability", "ecr:BatchGetImage", "ecr:CompleteLayerUpload", "ecr:GetDownloadUrlForLayer", "ecr:InitiateLayerUpload", "ecr:PutImage", "ecr:UploadLayerPart", "ecr:DescribeRepositories", "ecr:DescribeImages", ] resources = [aws_ecr_repository.api.arn] } statement { sid = "EcsRegisterTaskDefinition" effect = "Allow" actions = [ "ecs:DescribeTaskDefinition", "ecs:RegisterTaskDefinition", ] resources = ["*"] condition { test = "StringEquals" variable = "aws:RequestedRegion" values = [var.aws_region] } } statement { sid = "EcsUpdateService" effect = "Allow" actions = [ "ecs:DescribeServices", "ecs:DescribeTasks", "ecs:ListTasks", "ecs:RunTask", "ecs:StopTask", "ecs:TagResource", "ecs:UpdateService", ] resources = [ aws_ecs_cluster.api.arn, aws_ecs_service.api.id, "arn:aws:ecs:${var.aws_region}:${local.account_id}:task/${local.project}/*", "arn:aws:ecs:${var.aws_region}:${local.account_id}:task-definition/${local.project}", "arn:aws:ecs:${var.aws_region}:${local.account_id}:task-definition/${local.project}:*", ] } statement { sid = "PassTaskRoles" effect = "Allow" actions = ["iam:PassRole"] resources = [ aws_iam_role.ecs_task.arn, aws_iam_role.ecs_execution.arn, ] condition { test = "StringEquals" variable = "iam:PassedToService" values = ["ecs-tasks.amazonaws.com"] } } statement { sid = "DeployParams" effect = "Allow" actions = [ "ssm:GetParameter", ] resources = [ aws_ssm_parameter.deploy_bucket.arn, aws_ssm_parameter.deploy_distribution_id.arn, aws_ssm_parameter.deploy_cluster.arn, aws_ssm_parameter.deploy_service.arn, aws_ssm_parameter.deploy_task_family.arn, aws_ssm_parameter.deploy_ecr_repository.arn, aws_ssm_parameter.deploy_container_name.arn, aws_ssm_parameter.deploy_task_environment.arn, ] } statement { sid = "DecryptTaskEnvironment" effect = "Allow" actions = ["kms:Decrypt"] resources = [ "arn:aws:kms:${var.aws_region}:${local.account_id}:alias/aws/ssm", "arn:aws:kms:${var.aws_region}:${local.account_id}:key/*", ] condition { test = "StringEquals" variable = "kms:ViaService" values = ["ssm.${var.aws_region}.amazonaws.com"] } } } resource "aws_iam_role_policy" "github_deploy" { name = "seahaven-ap-spa-api-deploy" role = aws_iam_role.github_deploy.id policy = data.aws_iam_policy_document.github_deploy.json }