mirror of
https://github.com/Sea-Haven-Industries/seahaven-door-unlock-api.git
synced 2026-09-30 07:03:12 +00:00
feat(iam): import hcptf roles into app Terraform (PLAT-146) (#86)
* feat(iam): import hcptf roles into app Terraform (PLAT-146) Move the existing hcptf pair into this repo so app Terraform owns prod IAM after the substrate handoff. * fix(iam): add apply-role IAM list permissions (PLAT-146) IamReadOnly omitted ListRoleTags and ListInstanceProfilesForRole needed after detaching the substrate guardrail.
This commit is contained in:
parent
ad74f02ec4
commit
b43335b4a7
1 changed files with 686 additions and 0 deletions
686
terraform/hcp_iam.tf
Normal file
686
terraform/hcp_iam.tf
Normal file
|
|
@ -0,0 +1,686 @@
|
|||
# HCP plan/apply roles imported from seahaven-terraform-substrate (PLAT-146).
|
||||
# Import, do not recreate. Role names stay hcptf-seahaven-door-unlock-api / hcptf-seahaven-door-unlock-api-plan.
|
||||
#
|
||||
# Live seahaven-hcptf-iam-management DenySelfMutation blocks DetachRolePolicy
|
||||
# and PutRolePolicy on hcptf-* (including this role). Import apply sequence:
|
||||
# 1. seahaven-org-baseline scripts/create-hcptf-bootstrap-roles.sh
|
||||
# --account prod --allow-workspace seahaven-door-unlock-api-prod
|
||||
# 2. Point this workspace's TFC_AWS_* at hcptf-bootstrap /
|
||||
# hcptf-bootstrap-plan (workspace vars, never a project set).
|
||||
# 3. One Manual apply (import + detach seahaven-hcptf-iam-management +
|
||||
# put scoped inline).
|
||||
# 4. Point TFC_AWS_* back at hcptf-seahaven-door-unlock-api / hcptf-seahaven-door-unlock-api-plan.
|
||||
# 5. Re-run the script without --allow-workspace to pin trust back to
|
||||
# iam-bootstrap-prod only.
|
||||
# seahaven-lambda-execution-boundary remains seahaven-lambda-execution-boundary-seahaven-door-unlock-api.
|
||||
|
||||
import {
|
||||
to = aws_iam_role.hcptf_apply
|
||||
id = "hcptf-seahaven-door-unlock-api"
|
||||
}
|
||||
|
||||
import {
|
||||
to = aws_iam_role.hcptf_plan
|
||||
id = "hcptf-seahaven-door-unlock-api-plan"
|
||||
}
|
||||
|
||||
import {
|
||||
to = aws_iam_role_policy.hcptf_apply_services
|
||||
id = "hcptf-seahaven-door-unlock-api:seahaven-door-unlock-api-services"
|
||||
}
|
||||
|
||||
import {
|
||||
to = aws_iam_role_policy.hcptf_plan_refresh
|
||||
id = "hcptf-seahaven-door-unlock-api-plan:seahaven-door-unlock-api-plan-refresh"
|
||||
}
|
||||
|
||||
import {
|
||||
to = aws_iam_role_policy_attachments_exclusive.hcptf_apply
|
||||
id = "hcptf-seahaven-door-unlock-api"
|
||||
}
|
||||
|
||||
import {
|
||||
to = aws_iam_role_policy_attachment.hcptf_plan_viewonly
|
||||
id = "hcptf-seahaven-door-unlock-api-plan/arn:aws:iam::aws:policy/job-function/ViewOnlyAccess"
|
||||
}
|
||||
|
||||
import {
|
||||
to = aws_iam_role_policy_attachments_exclusive.hcptf_plan
|
||||
id = "hcptf-seahaven-door-unlock-api-plan"
|
||||
}
|
||||
|
||||
data "aws_iam_policy_document" "hcptf_apply_trust" {
|
||||
statement {
|
||||
sid = "HcpApply"
|
||||
effect = "Allow"
|
||||
actions = ["sts:AssumeRoleWithWebIdentity"]
|
||||
|
||||
principals {
|
||||
type = "Federated"
|
||||
identifiers = ["arn:aws:iam::${local.account_id}:oidc-provider/app.terraform.io"]
|
||||
}
|
||||
|
||||
condition {
|
||||
test = "StringEquals"
|
||||
variable = "app.terraform.io:aud"
|
||||
values = ["aws.workload.identity"]
|
||||
}
|
||||
|
||||
condition {
|
||||
test = "StringEquals"
|
||||
variable = "app.terraform.io:sub"
|
||||
values = [
|
||||
"organization:seahaven:project:seahaven-prod:workspace:seahaven-door-unlock-api-prod:run_phase:apply",
|
||||
]
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
data "aws_iam_policy_document" "hcptf_plan_trust" {
|
||||
statement {
|
||||
sid = "HcpPlan"
|
||||
effect = "Allow"
|
||||
actions = ["sts:AssumeRoleWithWebIdentity"]
|
||||
|
||||
principals {
|
||||
type = "Federated"
|
||||
identifiers = ["arn:aws:iam::${local.account_id}:oidc-provider/app.terraform.io"]
|
||||
}
|
||||
|
||||
condition {
|
||||
test = "StringEquals"
|
||||
variable = "app.terraform.io:aud"
|
||||
values = ["aws.workload.identity"]
|
||||
}
|
||||
|
||||
condition {
|
||||
test = "StringEquals"
|
||||
variable = "app.terraform.io:sub"
|
||||
values = [
|
||||
"organization:seahaven:project:seahaven-prod:workspace:seahaven-door-unlock-api-prod:run_phase:plan",
|
||||
]
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
data "aws_iam_policy_document" "hcptf_scoped_iam" {
|
||||
statement {
|
||||
sid = "DenyCreatePolicy"
|
||||
effect = "Deny"
|
||||
actions = ["iam:CreatePolicy", "iam:CreatePolicyVersion"]
|
||||
resources = ["*"]
|
||||
}
|
||||
|
||||
statement {
|
||||
sid = "CreateExecRoleWithBoundary"
|
||||
effect = "Allow"
|
||||
actions = ["iam:CreateRole"]
|
||||
resources = ["arn:aws:iam::${local.account_id}:role/tf-managed/door-unlock-api-*"]
|
||||
|
||||
condition {
|
||||
test = "StringLike"
|
||||
variable = "iam:PermissionsBoundary"
|
||||
values = [
|
||||
"arn:aws:iam::${local.account_id}:policy/tf-managed/door-unlock-api-*",
|
||||
"arn:aws:iam::${local.account_id}:policy/seahaven-lambda-execution-boundary-seahaven-door-unlock-api"
|
||||
]
|
||||
}
|
||||
}
|
||||
|
||||
statement {
|
||||
sid = "MutateExecRoleWithBoundary"
|
||||
effect = "Allow"
|
||||
actions = [
|
||||
"iam:AttachRolePolicy",
|
||||
"iam:PutRolePolicy",
|
||||
"iam:PutRolePermissionsBoundary",
|
||||
]
|
||||
resources = ["arn:aws:iam::${local.account_id}:role/tf-managed/door-unlock-api-*"]
|
||||
|
||||
condition {
|
||||
test = "StringLike"
|
||||
variable = "iam:PermissionsBoundary"
|
||||
values = [
|
||||
"arn:aws:iam::${local.account_id}:policy/tf-managed/door-unlock-api-*",
|
||||
"arn:aws:iam::${local.account_id}:policy/seahaven-lambda-execution-boundary-seahaven-door-unlock-api"
|
||||
]
|
||||
}
|
||||
}
|
||||
|
||||
statement {
|
||||
sid = "WriteExecRoles"
|
||||
effect = "Allow"
|
||||
actions = [
|
||||
"iam:DeleteRole",
|
||||
"iam:DeleteRolePolicy",
|
||||
"iam:DetachRolePolicy",
|
||||
"iam:TagRole",
|
||||
"iam:UntagRole",
|
||||
"iam:UpdateAssumeRolePolicy",
|
||||
"iam:UpdateRole",
|
||||
"iam:UpdateRoleDescription",
|
||||
]
|
||||
resources = ["arn:aws:iam::${local.account_id}:role/tf-managed/door-unlock-api-*"]
|
||||
}
|
||||
|
||||
statement {
|
||||
sid = "PassExecRolesToLambda"
|
||||
effect = "Allow"
|
||||
actions = ["iam:PassRole"]
|
||||
resources = ["arn:aws:iam::${local.account_id}:role/tf-managed/door-unlock-api-*"]
|
||||
|
||||
condition {
|
||||
test = "StringEquals"
|
||||
variable = "iam:PassedToService"
|
||||
values = ["lambda.amazonaws.com"]
|
||||
}
|
||||
}
|
||||
|
||||
statement {
|
||||
sid = "IamReadOnly"
|
||||
effect = "Allow"
|
||||
actions = [
|
||||
"iam:GetPolicy",
|
||||
"iam:GetPolicyVersion",
|
||||
"iam:GetRole",
|
||||
"iam:GetRolePolicy",
|
||||
"iam:ListAttachedRolePolicies",
|
||||
"iam:ListInstanceProfilesForRole",
|
||||
"iam:ListPolicies",
|
||||
"iam:ListPolicyVersions",
|
||||
"iam:ListRolePolicies",
|
||||
"iam:ListRoles",
|
||||
"iam:ListRoleTags",
|
||||
]
|
||||
resources = ["*"]
|
||||
}
|
||||
|
||||
statement {
|
||||
sid = "DenySelfMutation"
|
||||
effect = "Deny"
|
||||
actions = [
|
||||
"iam:AttachRolePolicy",
|
||||
"iam:DeleteRole",
|
||||
"iam:DeleteRolePolicy",
|
||||
"iam:DeleteRolePermissionsBoundary",
|
||||
"iam:DetachRolePolicy",
|
||||
"iam:PutRolePolicy",
|
||||
"iam:PutRolePermissionsBoundary",
|
||||
"iam:UpdateAssumeRolePolicy",
|
||||
"iam:UpdateRole",
|
||||
"iam:UpdateRoleDescription",
|
||||
]
|
||||
resources = [
|
||||
"arn:aws:iam::${local.account_id}:role/hcptf-*",
|
||||
"arn:aws:iam::${local.account_id}:role/github-cfn-execution-role",
|
||||
"arn:aws:iam::${local.account_id}:role/githubdeploy-*",
|
||||
"arn:aws:iam::${local.account_id}:role/cdk-hnb659fds-*",
|
||||
"arn:aws:iam::${local.account_id}:role/OrganizationAccountAccessRole",
|
||||
"arn:aws:iam::${local.account_id}:role/seahaven-*",
|
||||
]
|
||||
}
|
||||
|
||||
statement {
|
||||
sid = "DenyBoundaryTampering"
|
||||
effect = "Deny"
|
||||
actions = [
|
||||
"iam:DeleteRolePermissionsBoundary",
|
||||
"iam:DeleteUserPermissionsBoundary",
|
||||
]
|
||||
resources = [
|
||||
"arn:aws:iam::${local.account_id}:role/*",
|
||||
"arn:aws:iam::${local.account_id}:user/*",
|
||||
]
|
||||
}
|
||||
|
||||
statement {
|
||||
sid = "DenyBoundaryPolicyEdit"
|
||||
effect = "Deny"
|
||||
actions = [
|
||||
"iam:CreatePolicyVersion",
|
||||
"iam:DeletePolicy",
|
||||
"iam:DeletePolicyVersion",
|
||||
"iam:SetDefaultPolicyVersion",
|
||||
]
|
||||
resources = ["arn:aws:iam::${local.account_id}:policy/seahaven-*"]
|
||||
}
|
||||
}
|
||||
|
||||
resource "aws_iam_role_policy" "hcptf_apply_services" {
|
||||
name = "seahaven-door-unlock-api-services"
|
||||
role = aws_iam_role.hcptf_apply.id
|
||||
policy = jsonencode({
|
||||
Version = "2012-10-17"
|
||||
Statement = [
|
||||
{
|
||||
Action = [
|
||||
"lambda:*",
|
||||
]
|
||||
Resource = [
|
||||
"arn:aws:lambda:us-east-1:${local.account_id}:function:door-unlock-api-*",
|
||||
]
|
||||
Effect = "Allow"
|
||||
Sid = "LambdaAll"
|
||||
},
|
||||
{
|
||||
Action = [
|
||||
"lambda:ListFunctions",
|
||||
"lambda:GetAccountSettings",
|
||||
]
|
||||
Resource = "*"
|
||||
Effect = "Allow"
|
||||
Sid = "LambdaList"
|
||||
},
|
||||
{
|
||||
Action = [
|
||||
"events:*",
|
||||
]
|
||||
Resource = [
|
||||
"arn:aws:events:us-east-1:${local.account_id}:rule/door-unlock-api-*",
|
||||
]
|
||||
Effect = "Allow"
|
||||
Sid = "EventBridgeRules"
|
||||
},
|
||||
{
|
||||
Action = [
|
||||
"logs:CreateLogGroup",
|
||||
"logs:DeleteLogGroup",
|
||||
"logs:PutRetentionPolicy",
|
||||
"logs:DeleteRetentionPolicy",
|
||||
"logs:TagResource",
|
||||
"logs:UntagResource",
|
||||
"logs:ListTagsForResource",
|
||||
]
|
||||
Resource = [
|
||||
"arn:aws:logs:us-east-1:${local.account_id}:log-group:/aws/lambda/door-unlock-api-*",
|
||||
"arn:aws:logs:us-east-1:${local.account_id}:log-group:/aws/apigateway/door-unlock-api*",
|
||||
]
|
||||
Effect = "Allow"
|
||||
Sid = "CloudWatchLogs"
|
||||
},
|
||||
{
|
||||
Action = [
|
||||
"logs:DescribeLogGroups",
|
||||
]
|
||||
Resource = "*"
|
||||
Effect = "Allow"
|
||||
Sid = "CloudWatchLogsDescribe"
|
||||
},
|
||||
{
|
||||
Action = [
|
||||
"logs:CreateLogDelivery",
|
||||
"logs:GetLogDelivery",
|
||||
"logs:UpdateLogDelivery",
|
||||
"logs:DeleteLogDelivery",
|
||||
"logs:ListLogDeliveries",
|
||||
"logs:DescribeResourcePolicies",
|
||||
]
|
||||
Resource = "*"
|
||||
Effect = "Allow"
|
||||
Sid = "DoorUnlockApiGwAccessLogDelivery"
|
||||
},
|
||||
{
|
||||
Action = [
|
||||
"s3:*",
|
||||
]
|
||||
Resource = [
|
||||
"arn:aws:s3:::door-unlock-api-artifacts-${local.account_id}",
|
||||
"arn:aws:s3:::door-unlock-api-artifacts-${local.account_id}/*",
|
||||
]
|
||||
Effect = "Allow"
|
||||
Sid = "StackBuckets"
|
||||
},
|
||||
{
|
||||
Action = [
|
||||
"apigateway:*",
|
||||
]
|
||||
Resource = [
|
||||
"arn:aws:apigateway:us-east-1::/apis",
|
||||
"arn:aws:apigateway:us-east-1::/apis/*",
|
||||
"arn:aws:apigateway:us-east-1::/tags/*",
|
||||
]
|
||||
Effect = "Allow"
|
||||
Sid = "HttpApiManage"
|
||||
},
|
||||
{
|
||||
Action = [
|
||||
"apigateway:*",
|
||||
]
|
||||
Resource = [
|
||||
"arn:aws:apigateway:us-east-1::/domainnames/doorunlock.seahaven.com",
|
||||
"arn:aws:apigateway:us-east-1::/domainnames/doorunlock.seahaven.com/*",
|
||||
]
|
||||
Effect = "Allow"
|
||||
Sid = "HttpApiDomain"
|
||||
},
|
||||
{
|
||||
Condition = {
|
||||
StringEquals = {
|
||||
"aws:RequestTag/Project" = "seahaven-door-unlock-api"
|
||||
}
|
||||
}
|
||||
Action = [
|
||||
"acm:RequestCertificate",
|
||||
]
|
||||
Resource = "*"
|
||||
Effect = "Allow"
|
||||
Sid = "AcmCreate"
|
||||
},
|
||||
{
|
||||
Action = [
|
||||
"acm:ListCertificates",
|
||||
"acm:ListTagsForCertificate",
|
||||
]
|
||||
Resource = "*"
|
||||
Effect = "Allow"
|
||||
Sid = "AcmList"
|
||||
},
|
||||
{
|
||||
Condition = {
|
||||
StringEquals = {
|
||||
"aws:ResourceTag/Project" = "seahaven-door-unlock-api"
|
||||
}
|
||||
}
|
||||
Action = [
|
||||
"acm:DescribeCertificate",
|
||||
"acm:GetCertificate",
|
||||
"acm:DeleteCertificate",
|
||||
"acm:AddTagsToCertificate",
|
||||
"acm:RemoveTagsFromCertificate",
|
||||
"acm:RenewCertificate",
|
||||
]
|
||||
Resource = "*"
|
||||
Effect = "Allow"
|
||||
Sid = "AcmManageTagged"
|
||||
},
|
||||
{
|
||||
Action = [
|
||||
"ssm:GetParameter",
|
||||
"ssm:GetParameters",
|
||||
]
|
||||
Resource = [
|
||||
"arn:aws:ssm:us-east-1:${local.account_id}:parameter/seahaven/door-unlock/door-id",
|
||||
]
|
||||
Effect = "Allow"
|
||||
Sid = "DoorUnlockSsm"
|
||||
},
|
||||
{
|
||||
Action = [
|
||||
"ssm:ListTagsForResource",
|
||||
]
|
||||
Resource = [
|
||||
"arn:aws:ssm:us-east-1:${local.account_id}:parameter/seahaven/door-unlock/*",
|
||||
]
|
||||
Effect = "Allow"
|
||||
Sid = "DoorUnlockSsmTags"
|
||||
},
|
||||
{
|
||||
Action = [
|
||||
"ssm:DescribeParameters",
|
||||
]
|
||||
Resource = "*"
|
||||
Effect = "Allow"
|
||||
Sid = "DoorUnlockSsmDescribeParameters"
|
||||
},
|
||||
{
|
||||
Action = [
|
||||
"secretsmanager:DescribeSecret",
|
||||
"secretsmanager:GetResourcePolicy",
|
||||
"secretsmanager:ListSecretVersionIds",
|
||||
]
|
||||
Resource = [
|
||||
"arn:aws:secretsmanager:us-east-1:${local.account_id}:secret:afterhours-shift-manager/3cx-domain-TPwqWP",
|
||||
"arn:aws:secretsmanager:us-east-1:${local.account_id}:secret:afterhours-shift-manager/3cx-client-id-jzyQXb",
|
||||
"arn:aws:secretsmanager:us-east-1:${local.account_id}:secret:afterhours-shift-manager/3cx-client-secret-jpO476",
|
||||
]
|
||||
Effect = "Allow"
|
||||
Sid = "DescribeThreeCxSecrets"
|
||||
},
|
||||
{
|
||||
Condition = {
|
||||
StringEquals = {
|
||||
"iam:PassedToService" = "apigateway.amazonaws.com"
|
||||
}
|
||||
}
|
||||
Action = [
|
||||
"iam:PassRole",
|
||||
]
|
||||
Resource = [
|
||||
"arn:aws:iam::${local.account_id}:role/tf-managed/door-unlock-api-*",
|
||||
]
|
||||
Effect = "Allow"
|
||||
Sid = "DoorUnlockPassRoleApiGateway"
|
||||
},
|
||||
{
|
||||
Action = [
|
||||
"cloudwatch:PutMetricAlarm",
|
||||
"cloudwatch:DeleteAlarms",
|
||||
"cloudwatch:DescribeAlarms",
|
||||
"cloudwatch:TagResource",
|
||||
"cloudwatch:UntagResource",
|
||||
"cloudwatch:ListTagsForResource",
|
||||
]
|
||||
Resource = [
|
||||
"arn:aws:cloudwatch:us-east-1:${local.account_id}:alarm:door-unlock-api-*",
|
||||
]
|
||||
Effect = "Allow"
|
||||
Sid = "CloudWatchAlarms"
|
||||
},
|
||||
{
|
||||
Action = [
|
||||
"sns:Publish",
|
||||
"sns:GetTopicAttributes",
|
||||
"sns:ListTagsForResource",
|
||||
]
|
||||
Resource = [
|
||||
"arn:aws:sns:us-east-1:${local.account_id}:site-alerts",
|
||||
]
|
||||
Effect = "Allow"
|
||||
Sid = "SnsPublishSiteAlerts"
|
||||
},
|
||||
]
|
||||
})
|
||||
}
|
||||
|
||||
resource "aws_iam_role_policy" "hcptf_plan_refresh" {
|
||||
name = "seahaven-door-unlock-api-plan-refresh"
|
||||
role = aws_iam_role.hcptf_plan.id
|
||||
policy = jsonencode({
|
||||
Version = "2012-10-17"
|
||||
Statement = [
|
||||
{
|
||||
Action = [
|
||||
"iam:GetRole",
|
||||
"iam:GetRolePolicy",
|
||||
"iam:ListRolePolicies",
|
||||
"iam:ListAttachedRolePolicies",
|
||||
"iam:ListRoleTags",
|
||||
]
|
||||
Resource = [
|
||||
"arn:aws:iam::${local.account_id}:role/tf-managed/door-unlock-api-*",
|
||||
"arn:aws:iam::${local.account_id}:role/hcptf-seahaven-door-unlock-api",
|
||||
"arn:aws:iam::${local.account_id}:role/hcptf-seahaven-door-unlock-api-plan",
|
||||
]
|
||||
Effect = "Allow"
|
||||
Sid = "RefreshIamRoles"
|
||||
},
|
||||
{
|
||||
Action = [
|
||||
"iam:GetPolicy",
|
||||
"iam:GetPolicyVersion",
|
||||
]
|
||||
Resource = "*"
|
||||
Effect = "Allow"
|
||||
Sid = "RefreshManagedPolicies"
|
||||
},
|
||||
{
|
||||
Action = [
|
||||
"events:DescribeRule",
|
||||
"events:ListTargetsByRule",
|
||||
"events:ListTagsForResource",
|
||||
]
|
||||
Resource = [
|
||||
"arn:aws:events:us-east-1:${local.account_id}:rule/door-unlock-api-*",
|
||||
]
|
||||
Effect = "Allow"
|
||||
Sid = "RefreshEventBridge"
|
||||
},
|
||||
{
|
||||
Action = [
|
||||
"lambda:Get*",
|
||||
"lambda:List*",
|
||||
]
|
||||
Resource = [
|
||||
"arn:aws:lambda:us-east-1:${local.account_id}:function:door-unlock-api-*",
|
||||
]
|
||||
Effect = "Allow"
|
||||
Sid = "RefreshLambda"
|
||||
},
|
||||
{
|
||||
Action = [
|
||||
"s3:Get*",
|
||||
"s3:ListBucket",
|
||||
]
|
||||
Resource = [
|
||||
"arn:aws:s3:::door-unlock-api-artifacts-${local.account_id}",
|
||||
"arn:aws:s3:::door-unlock-api-artifacts-${local.account_id}/*",
|
||||
]
|
||||
Effect = "Allow"
|
||||
Sid = "RefreshBuckets"
|
||||
},
|
||||
{
|
||||
Action = [
|
||||
"logs:DescribeLogGroups",
|
||||
"logs:ListTagsForResource",
|
||||
]
|
||||
Resource = "*"
|
||||
Effect = "Allow"
|
||||
Sid = "RefreshLogs"
|
||||
},
|
||||
{
|
||||
Action = [
|
||||
"acm:DescribeCertificate",
|
||||
"acm:ListCertificates",
|
||||
"acm:ListTagsForCertificate",
|
||||
"acm:GetCertificate",
|
||||
]
|
||||
Resource = "*"
|
||||
Effect = "Allow"
|
||||
Sid = "RefreshAcm"
|
||||
},
|
||||
{
|
||||
Action = [
|
||||
"ssm:GetParameter",
|
||||
"ssm:GetParameters",
|
||||
]
|
||||
Resource = [
|
||||
"arn:aws:ssm:us-east-1:${local.account_id}:parameter/seahaven/door-unlock/door-id",
|
||||
]
|
||||
Effect = "Allow"
|
||||
Sid = "RefreshDoorUnlockSsm"
|
||||
},
|
||||
{
|
||||
Action = [
|
||||
"ssm:ListTagsForResource",
|
||||
]
|
||||
Resource = [
|
||||
"arn:aws:ssm:us-east-1:${local.account_id}:parameter/seahaven/door-unlock/*",
|
||||
]
|
||||
Effect = "Allow"
|
||||
Sid = "RefreshDoorUnlockSsmTags"
|
||||
},
|
||||
{
|
||||
Action = [
|
||||
"ssm:DescribeParameters",
|
||||
]
|
||||
Resource = "*"
|
||||
Effect = "Allow"
|
||||
Sid = "RefreshSsmDescribeParameters"
|
||||
},
|
||||
{
|
||||
Action = [
|
||||
"apigateway:GET",
|
||||
]
|
||||
Resource = [
|
||||
"arn:aws:apigateway:us-east-1::/apis/*",
|
||||
"arn:aws:apigateway:us-east-1::/domainnames/doorunlock.seahaven.com",
|
||||
"arn:aws:apigateway:us-east-1::/domainnames/doorunlock.seahaven.com/*",
|
||||
"arn:aws:apigateway:us-east-1::/tags/*",
|
||||
]
|
||||
Effect = "Allow"
|
||||
Sid = "RefreshHttpApi"
|
||||
},
|
||||
{
|
||||
Action = [
|
||||
"cloudwatch:DescribeAlarms",
|
||||
"cloudwatch:ListTagsForResource",
|
||||
]
|
||||
Resource = "*"
|
||||
Effect = "Allow"
|
||||
Sid = "RefreshAlarms"
|
||||
},
|
||||
{
|
||||
Action = [
|
||||
"secretsmanager:DescribeSecret",
|
||||
"secretsmanager:GetResourcePolicy",
|
||||
"secretsmanager:ListSecretVersionIds",
|
||||
]
|
||||
Resource = [
|
||||
"arn:aws:secretsmanager:us-east-1:${local.account_id}:secret:afterhours-shift-manager/3cx-domain-TPwqWP",
|
||||
"arn:aws:secretsmanager:us-east-1:${local.account_id}:secret:afterhours-shift-manager/3cx-client-id-jzyQXb",
|
||||
"arn:aws:secretsmanager:us-east-1:${local.account_id}:secret:afterhours-shift-manager/3cx-client-secret-jpO476",
|
||||
]
|
||||
Effect = "Allow"
|
||||
Sid = "RefreshThreeCxSecrets"
|
||||
},
|
||||
]
|
||||
})
|
||||
}
|
||||
|
||||
resource "aws_iam_role" "hcptf_apply" {
|
||||
name = "hcptf-seahaven-door-unlock-api"
|
||||
assume_role_policy = data.aws_iam_policy_document.hcptf_apply_trust.json
|
||||
max_session_duration = 3600
|
||||
|
||||
tags = {
|
||||
Project = "seahaven-door-unlock-api"
|
||||
Owner = "adam@seahavenind.com"
|
||||
ManagedBy = "terraform"
|
||||
}
|
||||
}
|
||||
|
||||
# Empty exclusive set keeps seahaven-hcptf-iam-management detached.
|
||||
resource "aws_iam_role_policy_attachments_exclusive" "hcptf_apply" {
|
||||
role_name = aws_iam_role.hcptf_apply.name
|
||||
policy_arns = []
|
||||
}
|
||||
|
||||
resource "aws_iam_role" "hcptf_plan" {
|
||||
name = "hcptf-seahaven-door-unlock-api-plan"
|
||||
assume_role_policy = data.aws_iam_policy_document.hcptf_plan_trust.json
|
||||
max_session_duration = 3600
|
||||
|
||||
tags = {
|
||||
Project = "seahaven-door-unlock-api"
|
||||
Owner = "adam@seahavenind.com"
|
||||
ManagedBy = "terraform"
|
||||
}
|
||||
}
|
||||
|
||||
resource "aws_iam_role_policy_attachment" "hcptf_plan_viewonly" {
|
||||
role = aws_iam_role.hcptf_plan.name
|
||||
policy_arn = "arn:aws:iam::aws:policy/job-function/ViewOnlyAccess"
|
||||
}
|
||||
|
||||
resource "aws_iam_role_policy_attachments_exclusive" "hcptf_plan" {
|
||||
role_name = aws_iam_role.hcptf_plan.name
|
||||
policy_arns = [
|
||||
aws_iam_role_policy_attachment.hcptf_plan_viewonly.policy_arn,
|
||||
]
|
||||
}
|
||||
|
||||
resource "aws_iam_role_policy" "hcptf_scoped_iam" {
|
||||
name = "scoped-iam-management"
|
||||
role = aws_iam_role.hcptf_apply.id
|
||||
policy = data.aws_iam_policy_document.hcptf_scoped_iam.json
|
||||
}
|
||||
Loading…
Add table
Reference in a new issue