chore(iam): finalize backend role ownership (#132)
Some checks are pending
Deploy / deploy-management (push) Waiting to run
Deploy / deploy-external-dev (push) Waiting to run
Deploy / deploy-security (push) Waiting to run
Deploy / deploy-dev (push) Waiting to run
Deploy / deploy-prod (push) Waiting to run

* chore(iam): finalize backend role ownership

* fix(iam): complete backend import permissions
This commit is contained in:
Adam Moussa 2026-08-30 20:12:54 +00:00 • committed by GitHub
parent dba0871587
commit 08191ded4c
No known key found for this signature in database
GPG key ID: B5690EEEBB952194
3 changed files with 25 additions and 25 deletions

View file

@ -273,11 +273,13 @@ stack's migration time so an account never carries trust for workspaces that
do not deploy to it.
**External-dev SHOC role adoption is a staged CloudFormation import, not a
normal first deploy.** Exactly four roles exist today:
`hcptf-shoc-backend-{dev,staging}` and their `-plan` partners. The tf-poc pair
does not exist. Two independent CDK contexts make each transition explicit:
`enableShocBackendPocRoles` and `enableShocBackendLiveRoles`. Both are
version-controlled as `false` in `cdk.json` for the initial rollout.
normal first deploy.** Six roles exist today:
`hcptf-shoc-backend-{dev,staging}` and their `-plan` partners, plus the
`hcptf-shoc-backend-tf-poc` pair. Two independent CDK contexts make each
transition explicit:
`enableShocBackendPocRoles` and `enableShocBackendLiveRoles`. Both began as
`false` for the initial rollout and remain version-controlled as `true` after
their completed ownership transitions.
`terraform-substrate-external-dev` is deliberately absent from the automatic
external-dev deploy job during this sequence; `external-dev-baseline` remains
automatic and unchanged.

View file

@ -18,7 +18,7 @@
"@aws-cdk/aws-lambda:recognizeLayerVersion": true,
"@aws-cdk/core:checkSecretUsage": true,
"@aws-cdk/core:target-partitions": ["aws"],
"enableShocBackendPocRoles": false,
"enableShocBackendLiveRoles": false
"enableShocBackendPocRoles": true,
"enableShocBackendLiveRoles": true
}
}

View file

@ -2999,8 +2999,10 @@ Resources:
Effect: Allow
Action:
- acm:ListCertificates
- autoscaling:DescribeAutoScalingGroups
- ec2:DescribeSecurityGroups
- ec2:DescribeSubnets
- ec2:DescribeVpcAttribute
- ec2:DescribeVpcs
- elasticbeanstalk:DescribeApplications
- elasticbeanstalk:DescribeConfigurationOptions
@ -3026,23 +3028,25 @@ Resources:
Resource: arn:aws:acm:us-east-1:396287094661:certificate/*
Condition:
StringEquals:
"aws:ResourceTag/Project": shoc-backend
"aws:ResourceTag/Environment": tf-poc
"aws:ResourceTag/project": shoc
"aws:ResourceTag/env": tf-poc
- Sid: ReadSharedRdsTags
Effect: Allow
Action: rds:ListTagsForResource
Resource: arn:aws:rds:us-east-1:396287094661:db:shoc-sqlserver-shared
- Sid: AccessExistingElasticBeanstalkStorage
Effect: Allow
Action:
- s3:CreateBucket
- s3:PutBucketOwnershipControls
Resource: arn:aws:s3:::elasticbeanstalk-us-east-1-396287094661
- Sid: ReadPocDns
Effect: Allow
Action:
- route53:GetHostedZone
- route53:ListResourceRecordSets
- route53:ListTagsForResource
Resource: arn:aws:route53:::hostedzone/*
Condition:
StringEquals:
"aws:ResourceTag/Project": shoc-backend
"aws:ResourceTag/Environment": tf-poc
Resource: arn:aws:route53:::hostedzone/Z02451891BSZD93CMMGDU
- Sid: ReadRoute53Changes
Effect: Allow
Action: route53:GetChange
@ -3087,9 +3091,7 @@ Resources:
Statement:
- Sid: UpdatePocEnvironment
Effect: Allow
Action:
- elasticbeanstalk:UpdateEnvironment
- elasticbeanstalk:UpdateTagsForResource
Action: elasticbeanstalk:UpdateEnvironment
Resource: arn:aws:elasticbeanstalk:us-east-1:396287094661:environment/shoc-backend/shoc-backend-tf-poc
- Sid: PutPocRuntimePolicy
Effect: Allow
@ -3132,7 +3134,7 @@ Resources:
- Sid: ChangePocApiAndValidationRecords
Effect: Allow
Action: route53:ChangeResourceRecordSets
Resource: arn:aws:route53:::hostedzone/*
Resource: arn:aws:route53:::hostedzone/Z02451891BSZD93CMMGDU
Condition:
ForAllValues:StringLike:
"route53:ChangeResourceRecordSetsNormalizedRecordNames":
@ -3144,11 +3146,7 @@ Resources:
- Sid: TagPocHostedZone
Effect: Allow
Action: route53:ChangeTagsForResource
Resource: arn:aws:route53:::hostedzone/*
Condition:
StringEquals:
"aws:ResourceTag/Project": shoc-backend
"aws:ResourceTag/Environment": tf-poc
Resource: arn:aws:route53:::hostedzone/Z02451891BSZD93CMMGDU
- Sid: TagPocCertificate
Effect: Allow
Action:
@ -3157,8 +3155,8 @@ Resources:
Resource: arn:aws:acm:us-east-1:396287094661:certificate/*
Condition:
StringEquals:
"aws:ResourceTag/Project": shoc-backend
"aws:ResourceTag/Environment": tf-poc
"aws:ResourceTag/project": shoc
"aws:ResourceTag/env": tf-poc
HcptfShocBackendDevPlanRole:
Type: AWS::IAM::Role