mirror of
https://github.com/Sea-Haven-Industries/seahaven-org-baseline.git
synced 2026-09-30 05:43:17 +00:00
chore(iam): finalize backend role ownership (#132)
* chore(iam): finalize backend role ownership * fix(iam): complete backend import permissions
This commit is contained in:
parent
dba0871587
commit
08191ded4c
3 changed files with 25 additions and 25 deletions
12
README.md
12
README.md
|
|
@ -273,11 +273,13 @@ stack's migration time so an account never carries trust for workspaces that
|
|||
do not deploy to it.
|
||||
|
||||
**External-dev SHOC role adoption is a staged CloudFormation import, not a
|
||||
normal first deploy.** Exactly four roles exist today:
|
||||
`hcptf-shoc-backend-{dev,staging}` and their `-plan` partners. The tf-poc pair
|
||||
does not exist. Two independent CDK contexts make each transition explicit:
|
||||
`enableShocBackendPocRoles` and `enableShocBackendLiveRoles`. Both are
|
||||
version-controlled as `false` in `cdk.json` for the initial rollout.
|
||||
normal first deploy.** Six roles exist today:
|
||||
`hcptf-shoc-backend-{dev,staging}` and their `-plan` partners, plus the
|
||||
`hcptf-shoc-backend-tf-poc` pair. Two independent CDK contexts make each
|
||||
transition explicit:
|
||||
`enableShocBackendPocRoles` and `enableShocBackendLiveRoles`. Both began as
|
||||
`false` for the initial rollout and remain version-controlled as `true` after
|
||||
their completed ownership transitions.
|
||||
`terraform-substrate-external-dev` is deliberately absent from the automatic
|
||||
external-dev deploy job during this sequence; `external-dev-baseline` remains
|
||||
automatic and unchanged.
|
||||
|
|
|
|||
4
cdk.json
4
cdk.json
|
|
@ -18,7 +18,7 @@
|
|||
"@aws-cdk/aws-lambda:recognizeLayerVersion": true,
|
||||
"@aws-cdk/core:checkSecretUsage": true,
|
||||
"@aws-cdk/core:target-partitions": ["aws"],
|
||||
"enableShocBackendPocRoles": false,
|
||||
"enableShocBackendLiveRoles": false
|
||||
"enableShocBackendPocRoles": true,
|
||||
"enableShocBackendLiveRoles": true
|
||||
}
|
||||
}
|
||||
|
|
|
|||
|
|
@ -2999,8 +2999,10 @@ Resources:
|
|||
Effect: Allow
|
||||
Action:
|
||||
- acm:ListCertificates
|
||||
- autoscaling:DescribeAutoScalingGroups
|
||||
- ec2:DescribeSecurityGroups
|
||||
- ec2:DescribeSubnets
|
||||
- ec2:DescribeVpcAttribute
|
||||
- ec2:DescribeVpcs
|
||||
- elasticbeanstalk:DescribeApplications
|
||||
- elasticbeanstalk:DescribeConfigurationOptions
|
||||
|
|
@ -3026,23 +3028,25 @@ Resources:
|
|||
Resource: arn:aws:acm:us-east-1:396287094661:certificate/*
|
||||
Condition:
|
||||
StringEquals:
|
||||
"aws:ResourceTag/Project": shoc-backend
|
||||
"aws:ResourceTag/Environment": tf-poc
|
||||
"aws:ResourceTag/project": shoc
|
||||
"aws:ResourceTag/env": tf-poc
|
||||
- Sid: ReadSharedRdsTags
|
||||
Effect: Allow
|
||||
Action: rds:ListTagsForResource
|
||||
Resource: arn:aws:rds:us-east-1:396287094661:db:shoc-sqlserver-shared
|
||||
- Sid: AccessExistingElasticBeanstalkStorage
|
||||
Effect: Allow
|
||||
Action:
|
||||
- s3:CreateBucket
|
||||
- s3:PutBucketOwnershipControls
|
||||
Resource: arn:aws:s3:::elasticbeanstalk-us-east-1-396287094661
|
||||
- Sid: ReadPocDns
|
||||
Effect: Allow
|
||||
Action:
|
||||
- route53:GetHostedZone
|
||||
- route53:ListResourceRecordSets
|
||||
- route53:ListTagsForResource
|
||||
Resource: arn:aws:route53:::hostedzone/*
|
||||
Condition:
|
||||
StringEquals:
|
||||
"aws:ResourceTag/Project": shoc-backend
|
||||
"aws:ResourceTag/Environment": tf-poc
|
||||
Resource: arn:aws:route53:::hostedzone/Z02451891BSZD93CMMGDU
|
||||
- Sid: ReadRoute53Changes
|
||||
Effect: Allow
|
||||
Action: route53:GetChange
|
||||
|
|
@ -3087,9 +3091,7 @@ Resources:
|
|||
Statement:
|
||||
- Sid: UpdatePocEnvironment
|
||||
Effect: Allow
|
||||
Action:
|
||||
- elasticbeanstalk:UpdateEnvironment
|
||||
- elasticbeanstalk:UpdateTagsForResource
|
||||
Action: elasticbeanstalk:UpdateEnvironment
|
||||
Resource: arn:aws:elasticbeanstalk:us-east-1:396287094661:environment/shoc-backend/shoc-backend-tf-poc
|
||||
- Sid: PutPocRuntimePolicy
|
||||
Effect: Allow
|
||||
|
|
@ -3132,7 +3134,7 @@ Resources:
|
|||
- Sid: ChangePocApiAndValidationRecords
|
||||
Effect: Allow
|
||||
Action: route53:ChangeResourceRecordSets
|
||||
Resource: arn:aws:route53:::hostedzone/*
|
||||
Resource: arn:aws:route53:::hostedzone/Z02451891BSZD93CMMGDU
|
||||
Condition:
|
||||
ForAllValues:StringLike:
|
||||
"route53:ChangeResourceRecordSetsNormalizedRecordNames":
|
||||
|
|
@ -3144,11 +3146,7 @@ Resources:
|
|||
- Sid: TagPocHostedZone
|
||||
Effect: Allow
|
||||
Action: route53:ChangeTagsForResource
|
||||
Resource: arn:aws:route53:::hostedzone/*
|
||||
Condition:
|
||||
StringEquals:
|
||||
"aws:ResourceTag/Project": shoc-backend
|
||||
"aws:ResourceTag/Environment": tf-poc
|
||||
Resource: arn:aws:route53:::hostedzone/Z02451891BSZD93CMMGDU
|
||||
- Sid: TagPocCertificate
|
||||
Effect: Allow
|
||||
Action:
|
||||
|
|
@ -3157,8 +3155,8 @@ Resources:
|
|||
Resource: arn:aws:acm:us-east-1:396287094661:certificate/*
|
||||
Condition:
|
||||
StringEquals:
|
||||
"aws:ResourceTag/Project": shoc-backend
|
||||
"aws:ResourceTag/Environment": tf-poc
|
||||
"aws:ResourceTag/project": shoc
|
||||
"aws:ResourceTag/env": tf-poc
|
||||
|
||||
HcptfShocBackendDevPlanRole:
|
||||
Type: AWS::IAM::Role
|
||||
|
|
|
|||
Loading…
Add table
Reference in a new issue