From 08191ded4ce2c0b06c85a63aa1e43b4c3e62f4d0 Mon Sep 17 00:00:00 2001 From: Adam Moussa <166072409+amoussa1229@users.noreply.github.com> Date: Sun, 30 Aug 2026 20:12:54 +0000 Subject: [PATCH] chore(iam): finalize backend role ownership (#132) * chore(iam): finalize backend role ownership * fix(iam): complete backend import permissions --- README.md | 12 ++++--- cdk.json | 4 +-- .../terraform-substrate.template.yaml | 34 +++++++++---------- 3 files changed, 25 insertions(+), 25 deletions(-) diff --git a/README.md b/README.md index a1b4444..ff88e17 100644 --- a/README.md +++ b/README.md @@ -273,11 +273,13 @@ stack's migration time so an account never carries trust for workspaces that do not deploy to it. **External-dev SHOC role adoption is a staged CloudFormation import, not a -normal first deploy.** Exactly four roles exist today: -`hcptf-shoc-backend-{dev,staging}` and their `-plan` partners. The tf-poc pair -does not exist. Two independent CDK contexts make each transition explicit: -`enableShocBackendPocRoles` and `enableShocBackendLiveRoles`. Both are -version-controlled as `false` in `cdk.json` for the initial rollout. +normal first deploy.** Six roles exist today: +`hcptf-shoc-backend-{dev,staging}` and their `-plan` partners, plus the +`hcptf-shoc-backend-tf-poc` pair. Two independent CDK contexts make each +transition explicit: +`enableShocBackendPocRoles` and `enableShocBackendLiveRoles`. Both began as +`false` for the initial rollout and remain version-controlled as `true` after +their completed ownership transitions. `terraform-substrate-external-dev` is deliberately absent from the automatic external-dev deploy job during this sequence; `external-dev-baseline` remains automatic and unchanged. diff --git a/cdk.json b/cdk.json index 729caac..69c9475 100644 --- a/cdk.json +++ b/cdk.json @@ -18,7 +18,7 @@ "@aws-cdk/aws-lambda:recognizeLayerVersion": true, "@aws-cdk/core:checkSecretUsage": true, "@aws-cdk/core:target-partitions": ["aws"], - "enableShocBackendPocRoles": false, - "enableShocBackendLiveRoles": false + "enableShocBackendPocRoles": true, + "enableShocBackendLiveRoles": true } } diff --git a/lib/terraform-substrate/terraform-substrate.template.yaml b/lib/terraform-substrate/terraform-substrate.template.yaml index c01b89a..3483108 100644 --- a/lib/terraform-substrate/terraform-substrate.template.yaml +++ b/lib/terraform-substrate/terraform-substrate.template.yaml @@ -2999,8 +2999,10 @@ Resources: Effect: Allow Action: - acm:ListCertificates + - autoscaling:DescribeAutoScalingGroups - ec2:DescribeSecurityGroups - ec2:DescribeSubnets + - ec2:DescribeVpcAttribute - ec2:DescribeVpcs - elasticbeanstalk:DescribeApplications - elasticbeanstalk:DescribeConfigurationOptions @@ -3026,23 +3028,25 @@ Resources: Resource: arn:aws:acm:us-east-1:396287094661:certificate/* Condition: StringEquals: - "aws:ResourceTag/Project": shoc-backend - "aws:ResourceTag/Environment": tf-poc + "aws:ResourceTag/project": shoc + "aws:ResourceTag/env": tf-poc - Sid: ReadSharedRdsTags Effect: Allow Action: rds:ListTagsForResource Resource: arn:aws:rds:us-east-1:396287094661:db:shoc-sqlserver-shared + - Sid: AccessExistingElasticBeanstalkStorage + Effect: Allow + Action: + - s3:CreateBucket + - s3:PutBucketOwnershipControls + Resource: arn:aws:s3:::elasticbeanstalk-us-east-1-396287094661 - Sid: ReadPocDns Effect: Allow Action: - route53:GetHostedZone - route53:ListResourceRecordSets - route53:ListTagsForResource - Resource: arn:aws:route53:::hostedzone/* - Condition: - StringEquals: - "aws:ResourceTag/Project": shoc-backend - "aws:ResourceTag/Environment": tf-poc + Resource: arn:aws:route53:::hostedzone/Z02451891BSZD93CMMGDU - Sid: ReadRoute53Changes Effect: Allow Action: route53:GetChange @@ -3087,9 +3091,7 @@ Resources: Statement: - Sid: UpdatePocEnvironment Effect: Allow - Action: - - elasticbeanstalk:UpdateEnvironment - - elasticbeanstalk:UpdateTagsForResource + Action: elasticbeanstalk:UpdateEnvironment Resource: arn:aws:elasticbeanstalk:us-east-1:396287094661:environment/shoc-backend/shoc-backend-tf-poc - Sid: PutPocRuntimePolicy Effect: Allow @@ -3132,7 +3134,7 @@ Resources: - Sid: ChangePocApiAndValidationRecords Effect: Allow Action: route53:ChangeResourceRecordSets - Resource: arn:aws:route53:::hostedzone/* + Resource: arn:aws:route53:::hostedzone/Z02451891BSZD93CMMGDU Condition: ForAllValues:StringLike: "route53:ChangeResourceRecordSetsNormalizedRecordNames": @@ -3144,11 +3146,7 @@ Resources: - Sid: TagPocHostedZone Effect: Allow Action: route53:ChangeTagsForResource - Resource: arn:aws:route53:::hostedzone/* - Condition: - StringEquals: - "aws:ResourceTag/Project": shoc-backend - "aws:ResourceTag/Environment": tf-poc + Resource: arn:aws:route53:::hostedzone/Z02451891BSZD93CMMGDU - Sid: TagPocCertificate Effect: Allow Action: @@ -3157,8 +3155,8 @@ Resources: Resource: arn:aws:acm:us-east-1:396287094661:certificate/* Condition: StringEquals: - "aws:ResourceTag/Project": shoc-backend - "aws:ResourceTag/Environment": tf-poc + "aws:ResourceTag/project": shoc + "aws:ResourceTag/env": tf-poc HcptfShocBackendDevPlanRole: Type: AWS::IAM::Role