mirror of
https://github.com/Sea-Haven-Industries/seahaven-org-baseline.git
synced 2026-09-30 05:43:17 +00:00
fix(iam): let the site plan role describe SSM parameters (PLAT-225) (#154)
* fix(iam): let the site plan role describe SSM parameters * fix(iam): address review feedback
This commit is contained in:
parent
38ed1bfe00
commit
2f2858f885
4 changed files with 17 additions and 19 deletions
6
.github/workflows/deploy.yaml
vendored
6
.github/workflows/deploy.yaml
vendored
|
|
@ -56,10 +56,8 @@ jobs:
|
|||
uses: Sea-Haven-Industries/.github/.github/workflows/cd-cdk.yaml@e5691d8a7f96ac4d5a841a82975ff0a4354d53ac # v1.0.7
|
||||
with:
|
||||
node-version: "24"
|
||||
# seahaven-site-hcptf stays off this list until `cdk import` adopts the
|
||||
# live roles. A create fails, and a failed create blocks the import.
|
||||
# Add the id here in the change that follows a successful import.
|
||||
stacks: "prod-baseline dynamodb-cmk-prod alarm-topic-prod deploy-substrate-prod terraform-substrate-prod app-web-acl-prod"
|
||||
# seahaven-site-hcptf was imported after the roles left terraform-substrate.
|
||||
stacks: "prod-baseline dynamodb-cmk-prod alarm-topic-prod deploy-substrate-prod terraform-substrate-prod app-web-acl-prod seahaven-site-hcptf"
|
||||
stack-name: "seahaven-prod-baseline"
|
||||
secrets:
|
||||
deploy-role-arn: ${{ secrets.AWS_DEPLOY_ROLE_ARN_PROD }}
|
||||
|
|
|
|||
|
|
@ -32,7 +32,7 @@ are noted):
|
|||
| `seahaven-org-governance` | 328440206208 | us-east-1 | AWS Organizations OU tree + SCPs (incl. the cdk-imported external-dev guardrails) |
|
||||
| `seahaven-external-dev-baseline` | 396287094661 | us-east-1 | Member-account baseline: Config, GuardDuty, Security Hub (FSBP + CIS v3.0), Access Analyzer, flow logs, budget |
|
||||
| `seahaven-terraform-substrate` | 011934824531, 710827005802 | us-east-1 | Prod/dev HCP substrate: OIDC + shared IAM manager + eight existing `hcptf-*` pairs (DeletionPolicy Retain). Pending PLAT-147 delete after consumer imports. New prod/dev HCP IAM is not added here. |
|
||||
| `seahaven-site-hcptf` | 011934824531 | us-east-1 | Imported `hcptf-seahaven-site` apply and plan roles (PLAT-225). Adopt with `cdk import` after the site workspace drops them from state. Do not create. |
|
||||
| `seahaven-site-hcptf` | 011934824531 | us-east-1 | Imported `hcptf-seahaven-site` apply and plan roles (PLAT-225). On the prod deploy job. Do not create. |
|
||||
| `seahaven-terraform-substrate` | 396287094661 | us-east-1 | Staged manually for SHOC backend/frontend adoption; exact HCP roles and deploy boundaries referencing the existing OIDC provider. Stays (PLAT-148). |
|
||||
| `seahaven-security-baseline` | 001520130573 | us-east-1 | Member-account baseline for the delegated security-admin account (same construct set) |
|
||||
| `seahaven-dev-baseline` | 710827005802 | us-east-1 | Member-account baseline for internal dev/staging (org-managed detection — no local GuardDuty/SecurityHub) |
|
||||
|
|
|
|||
|
|
@ -229,8 +229,7 @@ new AppWebAclStack(app, "app-web-acl-prod", {
|
|||
});
|
||||
|
||||
// seahaven-site exec roles (PLAT-225). Not part of terraform-substrate.
|
||||
// First operation is `cdk import`, after the site workspace drops the roles
|
||||
// from its state. A create fails because the roles already exist.
|
||||
// Imported. On the prod deploy job. A create fails because the roles already exist.
|
||||
new SeahavenSiteHcptfStack(app, "seahaven-site-hcptf", {
|
||||
stackName: "seahaven-site-hcptf",
|
||||
env: { account: PROD_ACCOUNT, region: "us-east-1" },
|
||||
|
|
|
|||
|
|
@ -5,19 +5,12 @@ import { Construct } from "constructs";
|
|||
/**
|
||||
* Prod exec roles for the seahaven-site HCP workspace (PLAT-225).
|
||||
*
|
||||
* These roles already exist. Adopt them. Do not create them. The substrate
|
||||
* template no longer declares them. Its next deploy drops them from that
|
||||
* stack and retains the live roles.
|
||||
* These roles already exist and were imported into this stack. Do not
|
||||
* create them. A plain create fails because the roles already exist.
|
||||
* The stack is on the prod deploy job.
|
||||
*
|
||||
* Import only after that deploy, and after seahaven-site-prod applies its
|
||||
* `removed` blocks:
|
||||
*
|
||||
* npx cdk import seahaven-site-hcptf
|
||||
*
|
||||
* Import identifiers are the role names `hcptf-seahaven-site` and
|
||||
* `hcptf-seahaven-site-plan`. The stack stays off the prod deploy job until
|
||||
* that import succeeds. A plain create fails because the roles already
|
||||
* exist, and a failed create blocks the import.
|
||||
* Import identifiers were the role names `hcptf-seahaven-site` and
|
||||
* `hcptf-seahaven-site-plan`.
|
||||
*/
|
||||
export class SeahavenSiteHcptfStack extends cdk.Stack {
|
||||
constructor(scope: Construct, id: string, props: cdk.StackProps) {
|
||||
|
|
@ -459,6 +452,14 @@ function planPolicy(
|
|||
Action: ["ssm:GetParameter", "ssm:GetParameters", "ssm:ListTagsForResource"],
|
||||
Resource: [wafParam, deployParams],
|
||||
},
|
||||
{
|
||||
// DescribeParameters accepts only Resource "*". The AWS provider
|
||||
// calls it while refreshing aws_ssm_parameter.
|
||||
Sid: "DescribeParameters",
|
||||
Effect: "Allow",
|
||||
Action: "ssm:DescribeParameters",
|
||||
Resource: "*",
|
||||
},
|
||||
{
|
||||
Sid: "RefreshWafWebAcl",
|
||||
Effect: "Allow",
|
||||
|
|
|
|||
Loading…
Add table
Reference in a new issue