fix(iam): grant frontend HCP plan named SSM describe and tag reads (PLAT-212)

This commit is contained in:
Adam Moussa 2026-09-18 14:53:43 -04:00
parent 707d795b47
commit 0857174b6d
No known key found for this signature in database
2 changed files with 20 additions and 11 deletions

View file

@ -476,7 +476,8 @@ policies. Live apply roles may `UpdateAssumeRolePolicy` only on the matching
`githubdeploy-shoc-frontend-new-<env>` role. `DenySecretAccess` still denies
Secrets Manager and KMS decrypt; SSM GetParameter/GetParameters/GetParametersByPath
are denied except `/shoc-frontend-new/<env>/deploy/*`, which plan and apply
may read by named GetParameter/GetParameters/DescribeParameters. `UpdateDistribution` is allowed on the exact pinned distribution ARN.
may read by named GetParameter/GetParameters/ListTagsForResource. DescribeParameters
is a collection API, so it is named on `*` (not `ssm:Get*`). `UpdateDistribution` is allowed on the exact pinned distribution ARN.
`CreateInvalidation` and `GetInvalidation` are allowed on that same ARN so the
Terraform invalidation action can run. `GetObject`/`GetObjectTagging`/`PutObject`/`PutObjectTagging` on
`.release/current` lets Terraform own the release pointer, including the

View file

@ -236,16 +236,24 @@ const frontendReadPolicy = (
},
];
if (isLiveFrontendEnvironment(environment)) {
statements.push({
Sid: `Read${environmentSid(environment)}DeploySsm`,
Effect: "Allow",
Action: [
"ssm:GetParameter",
"ssm:GetParameters",
"ssm:DescribeParameters",
],
Resource: deployParameterArn(environment),
});
statements.push(
{
Sid: `Read${environmentSid(environment)}DeploySsm`,
Effect: "Allow",
Action: [
"ssm:GetParameter",
"ssm:GetParameters",
"ssm:ListTagsForResource",
],
Resource: deployParameterArn(environment),
},
{
Sid: `Describe${environmentSid(environment)}DeploySsm`,
Effect: "Allow",
Action: "ssm:DescribeParameters",
Resource: "*",
},
);
}
return {
Version: "2012-10-17",