fix(iam): allow GitHub frontend deploy roles to GetDistribution (PLAT-192) (#144)
Some checks are pending
Deploy / deploy-management (push) Waiting to run
Deploy / deploy-external-dev (push) Waiting to run
Deploy / deploy-security (push) Waiting to run
Deploy / deploy-dev (push) Waiting to run
Deploy / deploy-prod (push) Waiting to run

Verify and live-state summary call get-distribution; the identity policy already granted it, but the permissions boundary denied the action.
This commit is contained in:
Adam Moussa 2026-09-11 19:37:24 +00:00 • committed by GitHub
parent 60b978aa2a
commit 3c54df6341
No known key found for this signature in database
GPG key ID: B5690EEEBB952194
2 changed files with 31 additions and 14 deletions

View file

@ -409,13 +409,14 @@ external-dev IAM guardrail SCP is 5,095 compact characters against its
boundaries first.** The three retained boundaries are
`shoc-frontend-new-{tf-poc,dev,staging}-deploy-boundary`. Each permits only
bucket location/list/version reads, object get/put/current and version delete,
and invalidation create/read for one exact distribution. Dev is pinned to
`E2CWLM1AFB964P`; staging is pinned to `E2JDVEZ6EGD49J`. The tf-poc
distribution, OAC, function, hosted-zone, and certificate identifiers are
intentionally empty in `cdk.json`. They must come from the frontend shared
creator outputs; this substrate does not reuse the backend tf-poc zone or
certificate. Its site name is `frontend-tf-poc.seahaven.com`. While the
identifier set is empty, its boundary omits invalidation access and
`GetDistribution`/`GetDistributionConfig`, and invalidation create/read for
one exact distribution. Dev is pinned to `E2CWLM1AFB964P`; staging is pinned
to `E2JDVEZ6EGD49J`. The tf-poc distribution, OAC, function, hosted-zone, and
certificate identifiers are intentionally empty in `cdk.json`. They must come
from the frontend shared creator outputs; this substrate does not reuse the
backend tf-poc zone or certificate. Its site name is
`frontend-tf-poc.seahaven.com`. While the identifier set is empty, its
boundary omits distribution read and invalidation access and
`ShouldManageShocFrontendPocRoles` remains false even if its role gate is
mistakenly enabled.

View file

@ -640,6 +640,27 @@ export class ShocFrontendResources extends Construct {
Resource: `${siteBucketArn}/*`,
},
];
const wrapDistributionStatement = (
statement: Record<string, unknown>,
): unknown =>
environment.invalidationCondition === undefined
? statement
: cdk.Fn.conditionIf(
environment.invalidationCondition.logicalId,
statement,
cdk.Aws.NO_VALUE,
);
// GitHub verify and live-state summary call get-distribution. The identity
// policy already grants these; the boundary was the deny.
const readDistributionStatement = {
Sid: "ReadExactDistribution",
Effect: "Allow",
Action: [
"cloudfront:GetDistribution",
"cloudfront:GetDistributionConfig",
],
Resource: exactDistributionArn,
};
const invalidationStatement = {
Sid: "InvalidateExactDistribution",
Effect: "Allow",
@ -647,13 +668,8 @@ export class ShocFrontendResources extends Construct {
Resource: exactDistributionArn,
};
boundaryStatements.push(
environment.invalidationCondition === undefined
? invalidationStatement
: cdk.Fn.conditionIf(
environment.invalidationCondition.logicalId,
invalidationStatement,
cdk.Aws.NO_VALUE,
),
wrapDistributionStatement(readDistributionStatement),
wrapDistributionStatement(invalidationStatement),
);
const deployBoundary = new iam.CfnManagedPolicy(