fix(iam): let the site plan role describe SSM parameters (PLAT-225) (#154)
Some checks are pending
Deploy / deploy-management (push) Waiting to run
Deploy / deploy-external-dev (push) Waiting to run
Deploy / deploy-security (push) Waiting to run
Deploy / deploy-dev (push) Waiting to run
Deploy / deploy-prod (push) Waiting to run

* fix(iam): let the site plan role describe SSM parameters

* fix(iam): address review feedback
This commit is contained in:
Adam Moussa 2026-09-25 16:40:34 +00:00 • committed by GitHub
parent 38ed1bfe00
commit 2f2858f885
No known key found for this signature in database
GPG key ID: B5690EEEBB952194
4 changed files with 17 additions and 19 deletions

View file

@ -56,10 +56,8 @@ jobs:
uses: Sea-Haven-Industries/.github/.github/workflows/cd-cdk.yaml@e5691d8a7f96ac4d5a841a82975ff0a4354d53ac # v1.0.7
with:
node-version: "24"
# seahaven-site-hcptf stays off this list until `cdk import` adopts the
# live roles. A create fails, and a failed create blocks the import.
# Add the id here in the change that follows a successful import.
stacks: "prod-baseline dynamodb-cmk-prod alarm-topic-prod deploy-substrate-prod terraform-substrate-prod app-web-acl-prod"
# seahaven-site-hcptf was imported after the roles left terraform-substrate.
stacks: "prod-baseline dynamodb-cmk-prod alarm-topic-prod deploy-substrate-prod terraform-substrate-prod app-web-acl-prod seahaven-site-hcptf"
stack-name: "seahaven-prod-baseline"
secrets:
deploy-role-arn: ${{ secrets.AWS_DEPLOY_ROLE_ARN_PROD }}

View file

@ -32,7 +32,7 @@ are noted):
| `seahaven-org-governance` | 328440206208 | us-east-1 | AWS Organizations OU tree + SCPs (incl. the cdk-imported external-dev guardrails) |
| `seahaven-external-dev-baseline` | 396287094661 | us-east-1 | Member-account baseline: Config, GuardDuty, Security Hub (FSBP + CIS v3.0), Access Analyzer, flow logs, budget |
| `seahaven-terraform-substrate` | 011934824531, 710827005802 | us-east-1 | Prod/dev HCP substrate: OIDC + shared IAM manager + eight existing `hcptf-*` pairs (DeletionPolicy Retain). Pending PLAT-147 delete after consumer imports. New prod/dev HCP IAM is not added here. |
| `seahaven-site-hcptf` | 011934824531 | us-east-1 | Imported `hcptf-seahaven-site` apply and plan roles (PLAT-225). Adopt with `cdk import` after the site workspace drops them from state. Do not create. |
| `seahaven-site-hcptf` | 011934824531 | us-east-1 | Imported `hcptf-seahaven-site` apply and plan roles (PLAT-225). On the prod deploy job. Do not create. |
| `seahaven-terraform-substrate` | 396287094661 | us-east-1 | Staged manually for SHOC backend/frontend adoption; exact HCP roles and deploy boundaries referencing the existing OIDC provider. Stays (PLAT-148). |
| `seahaven-security-baseline` | 001520130573 | us-east-1 | Member-account baseline for the delegated security-admin account (same construct set) |
| `seahaven-dev-baseline` | 710827005802 | us-east-1 | Member-account baseline for internal dev/staging (org-managed detection — no local GuardDuty/SecurityHub) |

View file

@ -229,8 +229,7 @@ new AppWebAclStack(app, "app-web-acl-prod", {
});
// seahaven-site exec roles (PLAT-225). Not part of terraform-substrate.
// First operation is `cdk import`, after the site workspace drops the roles
// from its state. A create fails because the roles already exist.
// Imported. On the prod deploy job. A create fails because the roles already exist.
new SeahavenSiteHcptfStack(app, "seahaven-site-hcptf", {
stackName: "seahaven-site-hcptf",
env: { account: PROD_ACCOUNT, region: "us-east-1" },

View file

@ -5,19 +5,12 @@ import { Construct } from "constructs";
/**
* Prod exec roles for the seahaven-site HCP workspace (PLAT-225).
*
* These roles already exist. Adopt them. Do not create them. The substrate
* template no longer declares them. Its next deploy drops them from that
* stack and retains the live roles.
* These roles already exist and were imported into this stack. Do not
* create them. A plain create fails because the roles already exist.
* The stack is on the prod deploy job.
*
* Import only after that deploy, and after seahaven-site-prod applies its
* `removed` blocks:
*
* npx cdk import seahaven-site-hcptf
*
* Import identifiers are the role names `hcptf-seahaven-site` and
* `hcptf-seahaven-site-plan`. The stack stays off the prod deploy job until
* that import succeeds. A plain create fails because the roles already
* exist, and a failed create blocks the import.
* Import identifiers were the role names `hcptf-seahaven-site` and
* `hcptf-seahaven-site-plan`.
*/
export class SeahavenSiteHcptfStack extends cdk.Stack {
constructor(scope: Construct, id: string, props: cdk.StackProps) {
@ -459,6 +452,14 @@ function planPolicy(
Action: ["ssm:GetParameter", "ssm:GetParameters", "ssm:ListTagsForResource"],
Resource: [wafParam, deployParams],
},
{
// DescribeParameters accepts only Resource "*". The AWS provider
// calls it while refreshing aws_ssm_parameter.
Sid: "DescribeParameters",
Effect: "Allow",
Action: "ssm:DescribeParameters",
Resource: "*",
},
{
Sid: "RefreshWafWebAcl",
Effect: "Allow",