fix(iam): allow PublishFunction on exact frontend CloudFront functions (PLAT-187)

The AWS provider publishes after UpdateFunction, including tag-only applies, so denying PublishFunction on * still blocked Phase 2 function updates.
This commit is contained in:
Adam Moussa 2026-09-11 11:03:03 -04:00
parent cb49670711
commit 25c90e7480
No known key found for this signature in database
2 changed files with 15 additions and 14 deletions

View file

@ -439,8 +439,9 @@ job:
existing site resources only after a no-replacement plan. Apply-role writes
are limited to ordinary tags, `PutRolePolicy` on the exact deploy role,
`PutBucketPolicy` on the exact bucket, `UpdateDistribution` on the exact
distribution, `UpdateFunction` on the exact CloudFront function, and A/AAAA
changes for the exact site name with CREATE/DELETE/UPSERT conditions.
distribution, `UpdateFunction` and `PublishFunction` on the exact CloudFront
function, and A/AAAA changes for the exact site name with
CREATE/DELETE/UPSERT conditions.
5. For a future tf-poc, first provision and inventory the site outside these
adoption roles. Set all five `shocFrontendPoc*` identifiers from the
frontend shared creator outputs while its role gate remains false, deploy
@ -453,14 +454,14 @@ job:
The apply roles explicitly deny role lifecycle/trust/boundary/managed-policy
changes, `PassRole`, secret and parameter reads, CloudFront/S3 create and
delete (including OAC mutation and `PublishFunction`), and deletion of inline
role or bucket policies. `UpdateDistribution` and `UpdateFunction` are allowed
only on the exact pinned distribution and function ARNs so Phase 2 ownership
tags can apply; create, delete, and OAC updates stay denied. IAM does not
expose a condition key for an inline policy name, so `PutRolePolicy` is
constrained to the exact target-role ARN and requires the exact dedicated
deploy boundary to already be attached. The boundary limits effective
permissions, and the SCP requires the target role's locked
delete (including OAC mutation), and deletion of inline role or bucket
policies. `UpdateDistribution` is allowed on the exact pinned distribution ARN.
`UpdateFunction` and `PublishFunction` are allowed on the exact pinned function
ARN so Phase 2 ownership tags can apply; create, delete, and OAC updates stay
denied. IAM does not expose a condition key for an inline policy name, so
`PutRolePolicy` is constrained to the exact target-role ARN and requires the
exact dedicated deploy boundary to already be attached. The boundary limits
effective permissions, and the SCP requires the target role's locked
`HcpTerraformWorkspace` tag to equal the apply role's principal tag. The
Terraform resource must retain the inventoried inline policy name.

View file

@ -270,7 +270,6 @@ const frontendApplyPolicy = (
"cloudfront:DeleteDistribution",
"cloudfront:DeleteFunction",
"cloudfront:DeleteOriginAccessControl",
"cloudfront:PublishFunction",
"cloudfront:UpdateOriginAccessControl",
"s3:CreateBucket",
"s3:DeleteBucket",
@ -329,8 +328,9 @@ const frontendApplyPolicy = (
functionArn(environment.functionName),
],
},
// TagResource is already allowed. Update* was denied on * so Phase 2
// in-place CloudFront updates could not apply. Scope both to exact ARNs.
// TagResource is already allowed. Update* and PublishFunction were denied
// on * so Phase 2 in-place CloudFront updates could not apply. Scope them
// to exact ARNs. The AWS provider publishes after UpdateFunction.
{
Sid: "UpdateExactDistribution",
Effect: "Allow",
@ -340,7 +340,7 @@ const frontendApplyPolicy = (
{
Sid: "UpdateExactFunction",
Effect: "Allow",
Action: "cloudfront:UpdateFunction",
Action: ["cloudfront:UpdateFunction", "cloudfront:PublishFunction"],
Resource: functionArn(environment.functionName),
},
{