chore(iam): finalize backend role ownership (#132)
Some checks are pending
Deploy / deploy-management (push) Waiting to run
Deploy / deploy-external-dev (push) Waiting to run
Deploy / deploy-security (push) Waiting to run
Deploy / deploy-dev (push) Waiting to run
Deploy / deploy-prod (push) Waiting to run

* chore(iam): finalize backend role ownership

* fix(iam): complete backend import permissions
This commit is contained in:
Adam Moussa 2026-08-30 20:12:54 +00:00 • committed by GitHub
parent dba0871587
commit 08191ded4c
No known key found for this signature in database
GPG key ID: B5690EEEBB952194
3 changed files with 25 additions and 25 deletions

View file

@ -273,11 +273,13 @@ stack's migration time so an account never carries trust for workspaces that
do not deploy to it. do not deploy to it.
**External-dev SHOC role adoption is a staged CloudFormation import, not a **External-dev SHOC role adoption is a staged CloudFormation import, not a
normal first deploy.** Exactly four roles exist today: normal first deploy.** Six roles exist today:
`hcptf-shoc-backend-{dev,staging}` and their `-plan` partners. The tf-poc pair `hcptf-shoc-backend-{dev,staging}` and their `-plan` partners, plus the
does not exist. Two independent CDK contexts make each transition explicit: `hcptf-shoc-backend-tf-poc` pair. Two independent CDK contexts make each
`enableShocBackendPocRoles` and `enableShocBackendLiveRoles`. Both are transition explicit:
version-controlled as `false` in `cdk.json` for the initial rollout. `enableShocBackendPocRoles` and `enableShocBackendLiveRoles`. Both began as
`false` for the initial rollout and remain version-controlled as `true` after
their completed ownership transitions.
`terraform-substrate-external-dev` is deliberately absent from the automatic `terraform-substrate-external-dev` is deliberately absent from the automatic
external-dev deploy job during this sequence; `external-dev-baseline` remains external-dev deploy job during this sequence; `external-dev-baseline` remains
automatic and unchanged. automatic and unchanged.

View file

@ -18,7 +18,7 @@
"@aws-cdk/aws-lambda:recognizeLayerVersion": true, "@aws-cdk/aws-lambda:recognizeLayerVersion": true,
"@aws-cdk/core:checkSecretUsage": true, "@aws-cdk/core:checkSecretUsage": true,
"@aws-cdk/core:target-partitions": ["aws"], "@aws-cdk/core:target-partitions": ["aws"],
"enableShocBackendPocRoles": false, "enableShocBackendPocRoles": true,
"enableShocBackendLiveRoles": false "enableShocBackendLiveRoles": true
} }
} }

View file

@ -2999,8 +2999,10 @@ Resources:
Effect: Allow Effect: Allow
Action: Action:
- acm:ListCertificates - acm:ListCertificates
- autoscaling:DescribeAutoScalingGroups
- ec2:DescribeSecurityGroups - ec2:DescribeSecurityGroups
- ec2:DescribeSubnets - ec2:DescribeSubnets
- ec2:DescribeVpcAttribute
- ec2:DescribeVpcs - ec2:DescribeVpcs
- elasticbeanstalk:DescribeApplications - elasticbeanstalk:DescribeApplications
- elasticbeanstalk:DescribeConfigurationOptions - elasticbeanstalk:DescribeConfigurationOptions
@ -3026,23 +3028,25 @@ Resources:
Resource: arn:aws:acm:us-east-1:396287094661:certificate/* Resource: arn:aws:acm:us-east-1:396287094661:certificate/*
Condition: Condition:
StringEquals: StringEquals:
"aws:ResourceTag/Project": shoc-backend "aws:ResourceTag/project": shoc
"aws:ResourceTag/Environment": tf-poc "aws:ResourceTag/env": tf-poc
- Sid: ReadSharedRdsTags - Sid: ReadSharedRdsTags
Effect: Allow Effect: Allow
Action: rds:ListTagsForResource Action: rds:ListTagsForResource
Resource: arn:aws:rds:us-east-1:396287094661:db:shoc-sqlserver-shared Resource: arn:aws:rds:us-east-1:396287094661:db:shoc-sqlserver-shared
- Sid: AccessExistingElasticBeanstalkStorage
Effect: Allow
Action:
- s3:CreateBucket
- s3:PutBucketOwnershipControls
Resource: arn:aws:s3:::elasticbeanstalk-us-east-1-396287094661
- Sid: ReadPocDns - Sid: ReadPocDns
Effect: Allow Effect: Allow
Action: Action:
- route53:GetHostedZone - route53:GetHostedZone
- route53:ListResourceRecordSets - route53:ListResourceRecordSets
- route53:ListTagsForResource - route53:ListTagsForResource
Resource: arn:aws:route53:::hostedzone/* Resource: arn:aws:route53:::hostedzone/Z02451891BSZD93CMMGDU
Condition:
StringEquals:
"aws:ResourceTag/Project": shoc-backend
"aws:ResourceTag/Environment": tf-poc
- Sid: ReadRoute53Changes - Sid: ReadRoute53Changes
Effect: Allow Effect: Allow
Action: route53:GetChange Action: route53:GetChange
@ -3087,9 +3091,7 @@ Resources:
Statement: Statement:
- Sid: UpdatePocEnvironment - Sid: UpdatePocEnvironment
Effect: Allow Effect: Allow
Action: Action: elasticbeanstalk:UpdateEnvironment
- elasticbeanstalk:UpdateEnvironment
- elasticbeanstalk:UpdateTagsForResource
Resource: arn:aws:elasticbeanstalk:us-east-1:396287094661:environment/shoc-backend/shoc-backend-tf-poc Resource: arn:aws:elasticbeanstalk:us-east-1:396287094661:environment/shoc-backend/shoc-backend-tf-poc
- Sid: PutPocRuntimePolicy - Sid: PutPocRuntimePolicy
Effect: Allow Effect: Allow
@ -3132,7 +3134,7 @@ Resources:
- Sid: ChangePocApiAndValidationRecords - Sid: ChangePocApiAndValidationRecords
Effect: Allow Effect: Allow
Action: route53:ChangeResourceRecordSets Action: route53:ChangeResourceRecordSets
Resource: arn:aws:route53:::hostedzone/* Resource: arn:aws:route53:::hostedzone/Z02451891BSZD93CMMGDU
Condition: Condition:
ForAllValues:StringLike: ForAllValues:StringLike:
"route53:ChangeResourceRecordSetsNormalizedRecordNames": "route53:ChangeResourceRecordSetsNormalizedRecordNames":
@ -3144,11 +3146,7 @@ Resources:
- Sid: TagPocHostedZone - Sid: TagPocHostedZone
Effect: Allow Effect: Allow
Action: route53:ChangeTagsForResource Action: route53:ChangeTagsForResource
Resource: arn:aws:route53:::hostedzone/* Resource: arn:aws:route53:::hostedzone/Z02451891BSZD93CMMGDU
Condition:
StringEquals:
"aws:ResourceTag/Project": shoc-backend
"aws:ResourceTag/Environment": tf-poc
- Sid: TagPocCertificate - Sid: TagPocCertificate
Effect: Allow Effect: Allow
Action: Action:
@ -3157,8 +3155,8 @@ Resources:
Resource: arn:aws:acm:us-east-1:396287094661:certificate/* Resource: arn:aws:acm:us-east-1:396287094661:certificate/*
Condition: Condition:
StringEquals: StringEquals:
"aws:ResourceTag/Project": shoc-backend "aws:ResourceTag/project": shoc
"aws:ResourceTag/Environment": tf-poc "aws:ResourceTag/env": tf-poc
HcptfShocBackendDevPlanRole: HcptfShocBackendDevPlanRole:
Type: AWS::IAM::Role Type: AWS::IAM::Role