mirror of
https://github.com/Sea-Haven-Industries/seahaven-org-baseline.git
synced 2026-09-30 09:13:17 +00:00
65 lines
2.4 KiB
TypeScript
65 lines
2.4 KiB
TypeScript
|
|
import * as cdk from "aws-cdk-lib";
|
||
|
|
import * as identitystore from "aws-cdk-lib/aws-identitystore";
|
||
|
|
import * as sso from "aws-cdk-lib/aws-sso";
|
||
|
|
import { Construct } from "constructs";
|
||
|
|
|
||
|
|
const IDENTITY_CENTER_INSTANCE_ARN =
|
||
|
|
"arn:aws:sso:::instance/ssoins-722321f42ca610e4";
|
||
|
|
const IDENTITY_STORE_ID = "d-9067ec8e26";
|
||
|
|
const MANAGEMENT_ACCOUNT_ID = "328440206208";
|
||
|
|
|
||
|
|
/**
|
||
|
|
* Identity Center group and permission set for platform operators (SEC-37).
|
||
|
|
*
|
||
|
|
* Assigned only to the management account. ReadOnlyAccess plus
|
||
|
|
* sts:AssumeRole on OrganizationAccountAccessRole, so the existing
|
||
|
|
* bootstrap and teardown scripts keep working after a person uses this
|
||
|
|
* set. Those scripts still assume OrganizationAccountAccessRole directly.
|
||
|
|
* Retarget them only after this set is deployed and a real sign-in has
|
||
|
|
* assumed the member role.
|
||
|
|
*
|
||
|
|
* This is not an SCP exemption. /platform/ path denies exempt the
|
||
|
|
* reserved SSO role name AWSReservedSSO_Platform_* once the set exists.
|
||
|
|
*/
|
||
|
|
export class PlatformAccessStack extends cdk.Stack {
|
||
|
|
constructor(scope: Construct, id: string, props?: cdk.StackProps) {
|
||
|
|
super(scope, id, props);
|
||
|
|
|
||
|
|
const group = new identitystore.CfnGroup(this, "PlatformGroup", {
|
||
|
|
identityStoreId: IDENTITY_STORE_ID,
|
||
|
|
displayName: "platform",
|
||
|
|
description:
|
||
|
|
"Platform operators. Management account only. Assumes OrganizationAccountAccessRole for bootstrap.",
|
||
|
|
});
|
||
|
|
|
||
|
|
const permissionSet = new sso.CfnPermissionSet(this, "PlatformPermissionSet", {
|
||
|
|
instanceArn: IDENTITY_CENTER_INSTANCE_ARN,
|
||
|
|
name: "Platform",
|
||
|
|
description:
|
||
|
|
"Read-only in the management account, plus assume OrganizationAccountAccessRole.",
|
||
|
|
sessionDuration: "PT8H",
|
||
|
|
managedPolicies: ["arn:aws:iam::aws:policy/ReadOnlyAccess"],
|
||
|
|
inlinePolicy: {
|
||
|
|
Version: "2012-10-17",
|
||
|
|
Statement: [
|
||
|
|
{
|
||
|
|
Sid: "AssumeOrganizationAccountAccessRole",
|
||
|
|
Effect: "Allow",
|
||
|
|
Action: "sts:AssumeRole",
|
||
|
|
Resource: "arn:aws:iam::*:role/OrganizationAccountAccessRole",
|
||
|
|
},
|
||
|
|
],
|
||
|
|
},
|
||
|
|
});
|
||
|
|
|
||
|
|
new sso.CfnAssignment(this, "PlatformManagementAssignment", {
|
||
|
|
instanceArn: IDENTITY_CENTER_INSTANCE_ARN,
|
||
|
|
permissionSetArn: permissionSet.attrPermissionSetArn,
|
||
|
|
principalId: group.attrGroupId,
|
||
|
|
principalType: "GROUP",
|
||
|
|
targetId: MANAGEMENT_ACCOUNT_ID,
|
||
|
|
targetType: "AWS_ACCOUNT",
|
||
|
|
});
|
||
|
|
}
|
||
|
|
}
|