mirror of
https://github.com/Sea-Haven-Industries/seahaven-org-baseline.git
synced 2026-10-07 02:11:59 +00:00
chore(iam): finalize backend role ownership (#132)
* chore(iam): finalize backend role ownership * fix(iam): complete backend import permissions
This commit is contained in:
parent
dba0871587
commit
08191ded4c
3 changed files with 25 additions and 25 deletions
12
README.md
12
README.md
|
|
@ -273,11 +273,13 @@ stack's migration time so an account never carries trust for workspaces that
|
||||||
do not deploy to it.
|
do not deploy to it.
|
||||||
|
|
||||||
**External-dev SHOC role adoption is a staged CloudFormation import, not a
|
**External-dev SHOC role adoption is a staged CloudFormation import, not a
|
||||||
normal first deploy.** Exactly four roles exist today:
|
normal first deploy.** Six roles exist today:
|
||||||
`hcptf-shoc-backend-{dev,staging}` and their `-plan` partners. The tf-poc pair
|
`hcptf-shoc-backend-{dev,staging}` and their `-plan` partners, plus the
|
||||||
does not exist. Two independent CDK contexts make each transition explicit:
|
`hcptf-shoc-backend-tf-poc` pair. Two independent CDK contexts make each
|
||||||
`enableShocBackendPocRoles` and `enableShocBackendLiveRoles`. Both are
|
transition explicit:
|
||||||
version-controlled as `false` in `cdk.json` for the initial rollout.
|
`enableShocBackendPocRoles` and `enableShocBackendLiveRoles`. Both began as
|
||||||
|
`false` for the initial rollout and remain version-controlled as `true` after
|
||||||
|
their completed ownership transitions.
|
||||||
`terraform-substrate-external-dev` is deliberately absent from the automatic
|
`terraform-substrate-external-dev` is deliberately absent from the automatic
|
||||||
external-dev deploy job during this sequence; `external-dev-baseline` remains
|
external-dev deploy job during this sequence; `external-dev-baseline` remains
|
||||||
automatic and unchanged.
|
automatic and unchanged.
|
||||||
|
|
|
||||||
4
cdk.json
4
cdk.json
|
|
@ -18,7 +18,7 @@
|
||||||
"@aws-cdk/aws-lambda:recognizeLayerVersion": true,
|
"@aws-cdk/aws-lambda:recognizeLayerVersion": true,
|
||||||
"@aws-cdk/core:checkSecretUsage": true,
|
"@aws-cdk/core:checkSecretUsage": true,
|
||||||
"@aws-cdk/core:target-partitions": ["aws"],
|
"@aws-cdk/core:target-partitions": ["aws"],
|
||||||
"enableShocBackendPocRoles": false,
|
"enableShocBackendPocRoles": true,
|
||||||
"enableShocBackendLiveRoles": false
|
"enableShocBackendLiveRoles": true
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
|
||||||
|
|
@ -2999,8 +2999,10 @@ Resources:
|
||||||
Effect: Allow
|
Effect: Allow
|
||||||
Action:
|
Action:
|
||||||
- acm:ListCertificates
|
- acm:ListCertificates
|
||||||
|
- autoscaling:DescribeAutoScalingGroups
|
||||||
- ec2:DescribeSecurityGroups
|
- ec2:DescribeSecurityGroups
|
||||||
- ec2:DescribeSubnets
|
- ec2:DescribeSubnets
|
||||||
|
- ec2:DescribeVpcAttribute
|
||||||
- ec2:DescribeVpcs
|
- ec2:DescribeVpcs
|
||||||
- elasticbeanstalk:DescribeApplications
|
- elasticbeanstalk:DescribeApplications
|
||||||
- elasticbeanstalk:DescribeConfigurationOptions
|
- elasticbeanstalk:DescribeConfigurationOptions
|
||||||
|
|
@ -3026,23 +3028,25 @@ Resources:
|
||||||
Resource: arn:aws:acm:us-east-1:396287094661:certificate/*
|
Resource: arn:aws:acm:us-east-1:396287094661:certificate/*
|
||||||
Condition:
|
Condition:
|
||||||
StringEquals:
|
StringEquals:
|
||||||
"aws:ResourceTag/Project": shoc-backend
|
"aws:ResourceTag/project": shoc
|
||||||
"aws:ResourceTag/Environment": tf-poc
|
"aws:ResourceTag/env": tf-poc
|
||||||
- Sid: ReadSharedRdsTags
|
- Sid: ReadSharedRdsTags
|
||||||
Effect: Allow
|
Effect: Allow
|
||||||
Action: rds:ListTagsForResource
|
Action: rds:ListTagsForResource
|
||||||
Resource: arn:aws:rds:us-east-1:396287094661:db:shoc-sqlserver-shared
|
Resource: arn:aws:rds:us-east-1:396287094661:db:shoc-sqlserver-shared
|
||||||
|
- Sid: AccessExistingElasticBeanstalkStorage
|
||||||
|
Effect: Allow
|
||||||
|
Action:
|
||||||
|
- s3:CreateBucket
|
||||||
|
- s3:PutBucketOwnershipControls
|
||||||
|
Resource: arn:aws:s3:::elasticbeanstalk-us-east-1-396287094661
|
||||||
- Sid: ReadPocDns
|
- Sid: ReadPocDns
|
||||||
Effect: Allow
|
Effect: Allow
|
||||||
Action:
|
Action:
|
||||||
- route53:GetHostedZone
|
- route53:GetHostedZone
|
||||||
- route53:ListResourceRecordSets
|
- route53:ListResourceRecordSets
|
||||||
- route53:ListTagsForResource
|
- route53:ListTagsForResource
|
||||||
Resource: arn:aws:route53:::hostedzone/*
|
Resource: arn:aws:route53:::hostedzone/Z02451891BSZD93CMMGDU
|
||||||
Condition:
|
|
||||||
StringEquals:
|
|
||||||
"aws:ResourceTag/Project": shoc-backend
|
|
||||||
"aws:ResourceTag/Environment": tf-poc
|
|
||||||
- Sid: ReadRoute53Changes
|
- Sid: ReadRoute53Changes
|
||||||
Effect: Allow
|
Effect: Allow
|
||||||
Action: route53:GetChange
|
Action: route53:GetChange
|
||||||
|
|
@ -3087,9 +3091,7 @@ Resources:
|
||||||
Statement:
|
Statement:
|
||||||
- Sid: UpdatePocEnvironment
|
- Sid: UpdatePocEnvironment
|
||||||
Effect: Allow
|
Effect: Allow
|
||||||
Action:
|
Action: elasticbeanstalk:UpdateEnvironment
|
||||||
- elasticbeanstalk:UpdateEnvironment
|
|
||||||
- elasticbeanstalk:UpdateTagsForResource
|
|
||||||
Resource: arn:aws:elasticbeanstalk:us-east-1:396287094661:environment/shoc-backend/shoc-backend-tf-poc
|
Resource: arn:aws:elasticbeanstalk:us-east-1:396287094661:environment/shoc-backend/shoc-backend-tf-poc
|
||||||
- Sid: PutPocRuntimePolicy
|
- Sid: PutPocRuntimePolicy
|
||||||
Effect: Allow
|
Effect: Allow
|
||||||
|
|
@ -3132,7 +3134,7 @@ Resources:
|
||||||
- Sid: ChangePocApiAndValidationRecords
|
- Sid: ChangePocApiAndValidationRecords
|
||||||
Effect: Allow
|
Effect: Allow
|
||||||
Action: route53:ChangeResourceRecordSets
|
Action: route53:ChangeResourceRecordSets
|
||||||
Resource: arn:aws:route53:::hostedzone/*
|
Resource: arn:aws:route53:::hostedzone/Z02451891BSZD93CMMGDU
|
||||||
Condition:
|
Condition:
|
||||||
ForAllValues:StringLike:
|
ForAllValues:StringLike:
|
||||||
"route53:ChangeResourceRecordSetsNormalizedRecordNames":
|
"route53:ChangeResourceRecordSetsNormalizedRecordNames":
|
||||||
|
|
@ -3144,11 +3146,7 @@ Resources:
|
||||||
- Sid: TagPocHostedZone
|
- Sid: TagPocHostedZone
|
||||||
Effect: Allow
|
Effect: Allow
|
||||||
Action: route53:ChangeTagsForResource
|
Action: route53:ChangeTagsForResource
|
||||||
Resource: arn:aws:route53:::hostedzone/*
|
Resource: arn:aws:route53:::hostedzone/Z02451891BSZD93CMMGDU
|
||||||
Condition:
|
|
||||||
StringEquals:
|
|
||||||
"aws:ResourceTag/Project": shoc-backend
|
|
||||||
"aws:ResourceTag/Environment": tf-poc
|
|
||||||
- Sid: TagPocCertificate
|
- Sid: TagPocCertificate
|
||||||
Effect: Allow
|
Effect: Allow
|
||||||
Action:
|
Action:
|
||||||
|
|
@ -3157,8 +3155,8 @@ Resources:
|
||||||
Resource: arn:aws:acm:us-east-1:396287094661:certificate/*
|
Resource: arn:aws:acm:us-east-1:396287094661:certificate/*
|
||||||
Condition:
|
Condition:
|
||||||
StringEquals:
|
StringEquals:
|
||||||
"aws:ResourceTag/Project": shoc-backend
|
"aws:ResourceTag/project": shoc
|
||||||
"aws:ResourceTag/Environment": tf-poc
|
"aws:ResourceTag/env": tf-poc
|
||||||
|
|
||||||
HcptfShocBackendDevPlanRole:
|
HcptfShocBackendDevPlanRole:
|
||||||
Type: AWS::IAM::Role
|
Type: AWS::IAM::Role
|
||||||
|
|
|
||||||
Loading…
Add table
Reference in a new issue