From 2f2858f885452e5c3ff803440f799d5bcc07c611 Mon Sep 17 00:00:00 2001 From: Adam Moussa <166072409+amoussa1229@users.noreply.github.com> Date: Fri, 25 Sep 2026 16:40:34 +0000 Subject: [PATCH] fix(iam): let the site plan role describe SSM parameters (PLAT-225) (#154) * fix(iam): let the site plan role describe SSM parameters * fix(iam): address review feedback --- .github/workflows/deploy.yaml | 6 ++---- README.md | 2 +- bin/app.ts | 3 +-- lib/seahaven-site-hcptf-stack.ts | 25 +++++++++++++------------ 4 files changed, 17 insertions(+), 19 deletions(-) diff --git a/.github/workflows/deploy.yaml b/.github/workflows/deploy.yaml index 7c14f45..7588331 100644 --- a/.github/workflows/deploy.yaml +++ b/.github/workflows/deploy.yaml @@ -56,10 +56,8 @@ jobs: uses: Sea-Haven-Industries/.github/.github/workflows/cd-cdk.yaml@e5691d8a7f96ac4d5a841a82975ff0a4354d53ac # v1.0.7 with: node-version: "24" - # seahaven-site-hcptf stays off this list until `cdk import` adopts the - # live roles. A create fails, and a failed create blocks the import. - # Add the id here in the change that follows a successful import. - stacks: "prod-baseline dynamodb-cmk-prod alarm-topic-prod deploy-substrate-prod terraform-substrate-prod app-web-acl-prod" + # seahaven-site-hcptf was imported after the roles left terraform-substrate. + stacks: "prod-baseline dynamodb-cmk-prod alarm-topic-prod deploy-substrate-prod terraform-substrate-prod app-web-acl-prod seahaven-site-hcptf" stack-name: "seahaven-prod-baseline" secrets: deploy-role-arn: ${{ secrets.AWS_DEPLOY_ROLE_ARN_PROD }} diff --git a/README.md b/README.md index 05f0e79..1f5214e 100644 --- a/README.md +++ b/README.md @@ -32,7 +32,7 @@ are noted): | `seahaven-org-governance` | 328440206208 | us-east-1 | AWS Organizations OU tree + SCPs (incl. the cdk-imported external-dev guardrails) | | `seahaven-external-dev-baseline` | 396287094661 | us-east-1 | Member-account baseline: Config, GuardDuty, Security Hub (FSBP + CIS v3.0), Access Analyzer, flow logs, budget | | `seahaven-terraform-substrate` | 011934824531, 710827005802 | us-east-1 | Prod/dev HCP substrate: OIDC + shared IAM manager + eight existing `hcptf-*` pairs (DeletionPolicy Retain). Pending PLAT-147 delete after consumer imports. New prod/dev HCP IAM is not added here. | -| `seahaven-site-hcptf` | 011934824531 | us-east-1 | Imported `hcptf-seahaven-site` apply and plan roles (PLAT-225). Adopt with `cdk import` after the site workspace drops them from state. Do not create. | +| `seahaven-site-hcptf` | 011934824531 | us-east-1 | Imported `hcptf-seahaven-site` apply and plan roles (PLAT-225). On the prod deploy job. Do not create. | | `seahaven-terraform-substrate` | 396287094661 | us-east-1 | Staged manually for SHOC backend/frontend adoption; exact HCP roles and deploy boundaries referencing the existing OIDC provider. Stays (PLAT-148). | | `seahaven-security-baseline` | 001520130573 | us-east-1 | Member-account baseline for the delegated security-admin account (same construct set) | | `seahaven-dev-baseline` | 710827005802 | us-east-1 | Member-account baseline for internal dev/staging (org-managed detection — no local GuardDuty/SecurityHub) | diff --git a/bin/app.ts b/bin/app.ts index 3087f14..bc42311 100644 --- a/bin/app.ts +++ b/bin/app.ts @@ -229,8 +229,7 @@ new AppWebAclStack(app, "app-web-acl-prod", { }); // seahaven-site exec roles (PLAT-225). Not part of terraform-substrate. -// First operation is `cdk import`, after the site workspace drops the roles -// from its state. A create fails because the roles already exist. +// Imported. On the prod deploy job. A create fails because the roles already exist. new SeahavenSiteHcptfStack(app, "seahaven-site-hcptf", { stackName: "seahaven-site-hcptf", env: { account: PROD_ACCOUNT, region: "us-east-1" }, diff --git a/lib/seahaven-site-hcptf-stack.ts b/lib/seahaven-site-hcptf-stack.ts index a3b44af..975348d 100644 --- a/lib/seahaven-site-hcptf-stack.ts +++ b/lib/seahaven-site-hcptf-stack.ts @@ -5,19 +5,12 @@ import { Construct } from "constructs"; /** * Prod exec roles for the seahaven-site HCP workspace (PLAT-225). * - * These roles already exist. Adopt them. Do not create them. The substrate - * template no longer declares them. Its next deploy drops them from that - * stack and retains the live roles. + * These roles already exist and were imported into this stack. Do not + * create them. A plain create fails because the roles already exist. + * The stack is on the prod deploy job. * - * Import only after that deploy, and after seahaven-site-prod applies its - * `removed` blocks: - * - * npx cdk import seahaven-site-hcptf - * - * Import identifiers are the role names `hcptf-seahaven-site` and - * `hcptf-seahaven-site-plan`. The stack stays off the prod deploy job until - * that import succeeds. A plain create fails because the roles already - * exist, and a failed create blocks the import. + * Import identifiers were the role names `hcptf-seahaven-site` and + * `hcptf-seahaven-site-plan`. */ export class SeahavenSiteHcptfStack extends cdk.Stack { constructor(scope: Construct, id: string, props: cdk.StackProps) { @@ -459,6 +452,14 @@ function planPolicy( Action: ["ssm:GetParameter", "ssm:GetParameters", "ssm:ListTagsForResource"], Resource: [wafParam, deployParams], }, + { + // DescribeParameters accepts only Resource "*". The AWS provider + // calls it while refreshing aws_ssm_parameter. + Sid: "DescribeParameters", + Effect: "Allow", + Action: "ssm:DescribeParameters", + Resource: "*", + }, { Sid: "RefreshWafWebAcl", Effect: "Allow",