mirror of
https://github.com/Sea-Haven-Industries/seahaven-org-baseline.git
synced 2026-10-04 16:01:59 +00:00
fix(iam): allow PublishFunction on exact frontend CloudFront functions (PLAT-187)
The AWS provider publishes after UpdateFunction, including tag-only applies, so denying PublishFunction on * still blocked Phase 2 function updates.
This commit is contained in:
parent
cb49670711
commit
25c90e7480
2 changed files with 15 additions and 14 deletions
21
README.md
21
README.md
|
|
@ -439,8 +439,9 @@ job:
|
|||
existing site resources only after a no-replacement plan. Apply-role writes
|
||||
are limited to ordinary tags, `PutRolePolicy` on the exact deploy role,
|
||||
`PutBucketPolicy` on the exact bucket, `UpdateDistribution` on the exact
|
||||
distribution, `UpdateFunction` on the exact CloudFront function, and A/AAAA
|
||||
changes for the exact site name with CREATE/DELETE/UPSERT conditions.
|
||||
distribution, `UpdateFunction` and `PublishFunction` on the exact CloudFront
|
||||
function, and A/AAAA changes for the exact site name with
|
||||
CREATE/DELETE/UPSERT conditions.
|
||||
5. For a future tf-poc, first provision and inventory the site outside these
|
||||
adoption roles. Set all five `shocFrontendPoc*` identifiers from the
|
||||
frontend shared creator outputs while its role gate remains false, deploy
|
||||
|
|
@ -453,14 +454,14 @@ job:
|
|||
|
||||
The apply roles explicitly deny role lifecycle/trust/boundary/managed-policy
|
||||
changes, `PassRole`, secret and parameter reads, CloudFront/S3 create and
|
||||
delete (including OAC mutation and `PublishFunction`), and deletion of inline
|
||||
role or bucket policies. `UpdateDistribution` and `UpdateFunction` are allowed
|
||||
only on the exact pinned distribution and function ARNs so Phase 2 ownership
|
||||
tags can apply; create, delete, and OAC updates stay denied. IAM does not
|
||||
expose a condition key for an inline policy name, so `PutRolePolicy` is
|
||||
constrained to the exact target-role ARN and requires the exact dedicated
|
||||
deploy boundary to already be attached. The boundary limits effective
|
||||
permissions, and the SCP requires the target role's locked
|
||||
delete (including OAC mutation), and deletion of inline role or bucket
|
||||
policies. `UpdateDistribution` is allowed on the exact pinned distribution ARN.
|
||||
`UpdateFunction` and `PublishFunction` are allowed on the exact pinned function
|
||||
ARN so Phase 2 ownership tags can apply; create, delete, and OAC updates stay
|
||||
denied. IAM does not expose a condition key for an inline policy name, so
|
||||
`PutRolePolicy` is constrained to the exact target-role ARN and requires the
|
||||
exact dedicated deploy boundary to already be attached. The boundary limits
|
||||
effective permissions, and the SCP requires the target role's locked
|
||||
`HcpTerraformWorkspace` tag to equal the apply role's principal tag. The
|
||||
Terraform resource must retain the inventoried inline policy name.
|
||||
|
||||
|
|
|
|||
|
|
@ -270,7 +270,6 @@ const frontendApplyPolicy = (
|
|||
"cloudfront:DeleteDistribution",
|
||||
"cloudfront:DeleteFunction",
|
||||
"cloudfront:DeleteOriginAccessControl",
|
||||
"cloudfront:PublishFunction",
|
||||
"cloudfront:UpdateOriginAccessControl",
|
||||
"s3:CreateBucket",
|
||||
"s3:DeleteBucket",
|
||||
|
|
@ -329,8 +328,9 @@ const frontendApplyPolicy = (
|
|||
functionArn(environment.functionName),
|
||||
],
|
||||
},
|
||||
// TagResource is already allowed. Update* was denied on * so Phase 2
|
||||
// in-place CloudFront updates could not apply. Scope both to exact ARNs.
|
||||
// TagResource is already allowed. Update* and PublishFunction were denied
|
||||
// on * so Phase 2 in-place CloudFront updates could not apply. Scope them
|
||||
// to exact ARNs. The AWS provider publishes after UpdateFunction.
|
||||
{
|
||||
Sid: "UpdateExactDistribution",
|
||||
Effect: "Allow",
|
||||
|
|
@ -340,7 +340,7 @@ const frontendApplyPolicy = (
|
|||
{
|
||||
Sid: "UpdateExactFunction",
|
||||
Effect: "Allow",
|
||||
Action: "cloudfront:UpdateFunction",
|
||||
Action: ["cloudfront:UpdateFunction", "cloudfront:PublishFunction"],
|
||||
Resource: functionArn(environment.functionName),
|
||||
},
|
||||
{
|
||||
|
|
|
|||
Loading…
Add table
Reference in a new issue