seahaven-org-baseline/lib/platform-access-stack.ts

65 lines
2.4 KiB
TypeScript
Raw Normal View History

import * as cdk from "aws-cdk-lib";
import * as identitystore from "aws-cdk-lib/aws-identitystore";
import * as sso from "aws-cdk-lib/aws-sso";
import { Construct } from "constructs";
const IDENTITY_CENTER_INSTANCE_ARN =
"arn:aws:sso:::instance/ssoins-722321f42ca610e4";
const IDENTITY_STORE_ID = "d-9067ec8e26";
const MANAGEMENT_ACCOUNT_ID = "328440206208";
/**
* Identity Center group and permission set for platform operators (SEC-37).
*
* Assigned only to the management account. ReadOnlyAccess plus
* sts:AssumeRole on OrganizationAccountAccessRole, so the existing
* bootstrap and teardown scripts keep working after a person uses this
* set. Those scripts still assume OrganizationAccountAccessRole directly.
* Retarget them only after this set is deployed and a real sign-in has
* assumed the member role.
*
* This is not an SCP exemption. /platform/ path denies exempt the
* reserved SSO role name AWSReservedSSO_Platform_* once the set exists.
*/
export class PlatformAccessStack extends cdk.Stack {
constructor(scope: Construct, id: string, props?: cdk.StackProps) {
super(scope, id, props);
const group = new identitystore.CfnGroup(this, "PlatformGroup", {
identityStoreId: IDENTITY_STORE_ID,
displayName: "platform",
description:
"Platform operators. Management account only. Assumes OrganizationAccountAccessRole for bootstrap.",
});
const permissionSet = new sso.CfnPermissionSet(this, "PlatformPermissionSet", {
instanceArn: IDENTITY_CENTER_INSTANCE_ARN,
name: "Platform",
description:
"Read-only in the management account, plus assume OrganizationAccountAccessRole.",
sessionDuration: "PT8H",
managedPolicies: ["arn:aws:iam::aws:policy/ReadOnlyAccess"],
inlinePolicy: {
Version: "2012-10-17",
Statement: [
{
Sid: "AssumeOrganizationAccountAccessRole",
Effect: "Allow",
Action: "sts:AssumeRole",
Resource: "arn:aws:iam::*:role/OrganizationAccountAccessRole",
},
],
},
});
new sso.CfnAssignment(this, "PlatformManagementAssignment", {
instanceArn: IDENTITY_CENTER_INSTANCE_ARN,
permissionSetArn: permissionSet.attrPermissionSetArn,
principalId: group.attrGroupId,
principalType: "GROUP",
targetId: MANAGEMENT_ACCOUNT_ID,
targetType: "AWS_ACCOUNT",
});
}
}