mirror of
https://github.com/Sea-Haven-Industries/seahaven-org-baseline.git
synced 2026-09-30 05:43:17 +00:00
feat(iam): allow frontend HCP apply to own release pointer and invalidation (PLAT-188) (#143)
* feat(iam): allow frontend HCP apply to own release pointer and invalidation (PLAT-188) Plan and apply roles can read .release/current; apply can PutObject that key and CreateInvalidation on the exact distribution. * fix(iam): allow frontend HCP roles to tag the release pointer (PLAT-188) Terraform aws_s3_object lists object tags on every refresh, so plan and apply need GetObjectTagging and apply needs PutObjectTagging on the exact .release/current key.
This commit is contained in:
parent
0c6f307b61
commit
60b978aa2a
2 changed files with 32 additions and 2 deletions
10
README.md
10
README.md
|
|
@ -439,7 +439,10 @@ job:
|
|||
existing site resources only after a no-replacement plan. Apply-role writes
|
||||
are limited to ordinary tags, `PutRolePolicy` on the exact deploy role,
|
||||
`PutBucketPolicy` on the exact bucket, `UpdateDistribution` on the exact
|
||||
distribution, `UpdateFunction` and `PublishFunction` on the exact CloudFront
|
||||
distribution, `CreateInvalidation`/`GetInvalidation` on the exact
|
||||
distribution, `GetObject`/`GetObjectTagging`/`PutObject`/`PutObjectTagging`
|
||||
on `.release/current`,
|
||||
`UpdateFunction` and `PublishFunction` on the exact CloudFront
|
||||
function, and A/AAAA changes for the exact site name with
|
||||
CREATE/DELETE/UPSERT conditions.
|
||||
5. For a future tf-poc, first provision and inventory the site outside these
|
||||
|
|
@ -456,7 +459,10 @@ The apply roles explicitly deny role lifecycle/trust/boundary/managed-policy
|
|||
changes, `PassRole`, secret and parameter reads, CloudFront/S3 create and
|
||||
delete (including OAC mutation), and deletion of inline role or bucket
|
||||
policies. `UpdateDistribution` is allowed on the exact pinned distribution ARN.
|
||||
`UpdateFunction` and `PublishFunction` are allowed on the exact pinned function
|
||||
`CreateInvalidation` and `GetInvalidation` are allowed on that same ARN so the
|
||||
Terraform invalidation action can run. `GetObject`/`GetObjectTagging`/`PutObject`/`PutObjectTagging` on
|
||||
`.release/current` lets Terraform own the release pointer, including the
|
||||
tag list `aws_s3_object` refreshes on every plan. `UpdateFunction` and `PublishFunction` are allowed on the exact pinned function
|
||||
ARN so Phase 2 ownership tags can apply; create, delete, and OAC updates stay
|
||||
denied. IAM does not expose a condition key for an inline policy name, so
|
||||
`PutRolePolicy` is constrained to the exact target-role ARN and requires the
|
||||
|
|
|
|||
|
|
@ -113,6 +113,12 @@ const frontendReadPolicy = (
|
|||
],
|
||||
Resource: siteBucketArn,
|
||||
},
|
||||
{
|
||||
Sid: "ReadReleasePointerObject",
|
||||
Effect: "Allow",
|
||||
Action: ["s3:GetObject", "s3:GetObjectTagging", "s3:GetObjectVersion"],
|
||||
Resource: `${siteBucketArn}/.release/current`,
|
||||
},
|
||||
{
|
||||
Sid: "ReadExactCloudFrontResources",
|
||||
Effect: "Allow",
|
||||
|
|
@ -343,6 +349,24 @@ const frontendApplyPolicy = (
|
|||
Action: ["cloudfront:UpdateFunction", "cloudfront:PublishFunction"],
|
||||
Resource: functionArn(environment.functionName),
|
||||
},
|
||||
{
|
||||
Sid: "InvalidateExactDistribution",
|
||||
Effect: "Allow",
|
||||
Action: ["cloudfront:CreateInvalidation", "cloudfront:GetInvalidation"],
|
||||
Resource: distributionArn(environment.distributionId),
|
||||
},
|
||||
{
|
||||
Sid: "WriteReleasePointerObject",
|
||||
Effect: "Allow",
|
||||
Action: [
|
||||
"s3:GetObject",
|
||||
"s3:GetObjectTagging",
|
||||
"s3:GetObjectVersion",
|
||||
"s3:PutObject",
|
||||
"s3:PutObjectTagging",
|
||||
],
|
||||
Resource: `${bucketArn(environment.bucketName)}/.release/current`,
|
||||
},
|
||||
{
|
||||
Sid: "ReplaceExactDeployInlinePolicy",
|
||||
Effect: "Allow",
|
||||
|
|
|
|||
Loading…
Add table
Reference in a new issue