mirror of
https://github.com/Sea-Haven-Industries/seahaven-org-baseline.git
synced 2026-10-02 06:13:21 +00:00
chore(iam): remove backend tf-poc boundaries (#139)
Some checks failed
Some checks failed
This commit is contained in:
parent
4f0d84cddb
commit
6bc4f6e095
2 changed files with 15 additions and 112 deletions
26
README.md
26
README.md
|
|
@ -259,18 +259,24 @@ Prod/dev still carry, until PLAT-147 deletes those two stacks:
|
|||
External-dev still carries:
|
||||
|
||||
- external-dev-only deploy boundaries
|
||||
`shoc-backend-{tf-poc,dev,staging}-deploy-boundary`. Each is the maximum
|
||||
`shoc-backend-{dev,staging}-deploy-boundary`. Each is the maximum
|
||||
current policy for one exact `githubdeploy-shoc-backend-*` role. Dev
|
||||
temporarily retains its live broad `elasticbeanstalk-*` S3 grants so
|
||||
boundary attachment cannot regress deployment before the separately
|
||||
reviewed policy narrowing,
|
||||
- external-dev-only runtime boundaries
|
||||
`shoc-backend-{tf-poc,dev,staging}-runtime-boundary`. These retain only the
|
||||
`shoc-backend-{dev,staging}-runtime-boundary`. These retain only the
|
||||
account-scoped S3, environment health/log, and X-Ray portions of
|
||||
`AWSElasticBeanstalkWebTier`, plus each environment's exact secrets/KMS/STS
|
||||
data plane. They deliberately exclude the managed policy's 2026
|
||||
Bedrock/Marketplace additions.
|
||||
|
||||
The retired backend tf-poc deploy/runtime boundaries are no longer declared.
|
||||
Because their last managed definitions used `DeletionPolicy: Retain`, the
|
||||
external-dev stack update only removes CloudFormation ownership. Verify both
|
||||
policies still have zero attachments, then delete the retained physical
|
||||
policies in a separately approved post-deploy step.
|
||||
|
||||
**`seahaven-hcptf-iam-management` derives from `seahaven-cfn-exec-iam-management`
|
||||
but is deliberately stricter — it is not a mirror.** The 2026-07-30 security
|
||||
review confirmed the SAM copy's `Resource: "*"` role grants as a critical
|
||||
|
|
@ -321,16 +327,12 @@ automatic and unchanged.
|
|||
|
||||
`CreateOIDCProvider=false` is fixed in `bin/app.ts`; the external-dev
|
||||
account therefore creates neither the existing provider, SHOC roles, nor
|
||||
the prod/dev-only shared IAM policy. The base stack does create all six
|
||||
retained external-dev deploy/runtime boundary policies.
|
||||
the prod/dev-only shared IAM policy. The base stack does create the four
|
||||
retained backend dev/staging deploy/runtime boundary policies.
|
||||
2. Set `enableShocBackendPocRoles` to `true` in `cdk.json`, leave the live gate
|
||||
`false`, review the synthesized two-role addition, then run the normal
|
||||
external-dev stack update. This creates only the new tf-poc HCP plan/apply
|
||||
pair. The retained POC CDK stack references
|
||||
`shoc-backend-tf-poc-deploy-boundary` when it creates
|
||||
`githubdeploy-shoc-backend-tf-poc` and
|
||||
`shoc-backend-tf-poc-runtime-boundary` when it creates the POC runtime
|
||||
role; do not attach the generic account execution boundary to either role.
|
||||
pair.
|
||||
3. Prove both tf-poc HCP assumptions and the retained POC import rehearsal
|
||||
before touching the live-role ownership boundary.
|
||||
4. In a separately approved administrator/CDK migration, tag the existing HCP
|
||||
|
|
@ -344,10 +346,8 @@ automatic and unchanged.
|
|||
and attach `shoc-backend-dev-runtime-boundary` /
|
||||
`shoc-backend-staging-runtime-boundary` to the exact runtime roles. Verify
|
||||
the boundary ceilings before adding the matching manager tag to either
|
||||
target `githubdeploy-*` role. The POC CDK
|
||||
creates its deploy role with `HcpTerraformWorkspace=shoc-backend-tf-poc`;
|
||||
the substrate-created POC apply role already carries the same principal
|
||||
tag. Verify each effective deployment action before continuing. HCP remains
|
||||
target `githubdeploy-*` role. Verify each effective deployment action before
|
||||
continuing. HCP remains
|
||||
blocked while a target tag is missing/different or the target lacks its
|
||||
exact dedicated boundary, so a partial migration cannot authorize policy
|
||||
writes. Complete both runtime/deploy boundary attachments before workload
|
||||
|
|
|
|||
|
|
@ -2579,59 +2579,10 @@ Resources:
|
|||
# ---------------------------------------------------------------------------
|
||||
# SHOC backend GitHub deployment permissions boundaries (external-dev only)
|
||||
#
|
||||
# These are ceilings for the three exact githubdeploy roles, not grants.
|
||||
# These are ceilings for the dev and staging githubdeploy roles, not grants.
|
||||
# Existing dev/staging roles receive them through a separately approved
|
||||
# administrator/CDK action before HCP import. The retained POC CDK stack
|
||||
# attaches its boundary when it creates the POC deploy role.
|
||||
# administrator/CDK action before HCP import.
|
||||
# ---------------------------------------------------------------------------
|
||||
ShocBackendPocDeployBoundary:
|
||||
Type: AWS::IAM::ManagedPolicy
|
||||
Condition: IsExternalDevAccount
|
||||
DeletionPolicy: Retain
|
||||
UpdateReplacePolicy: Retain
|
||||
Properties:
|
||||
ManagedPolicyName: shoc-backend-tf-poc-deploy-boundary
|
||||
Description: Maximum deployment permissions for githubdeploy-shoc-backend-tf-poc.
|
||||
PolicyDocument:
|
||||
Version: "2012-10-17"
|
||||
Statement:
|
||||
- Sid: DescribeDeploymentResources
|
||||
Effect: Allow
|
||||
Action:
|
||||
- autoscaling:Describe*
|
||||
- ec2:Describe*
|
||||
- elasticbeanstalk:DescribeApplicationVersions
|
||||
- elasticbeanstalk:DescribeEnvironments
|
||||
- elasticbeanstalk:DescribeEvents
|
||||
- elasticloadbalancing:Describe*
|
||||
Resource: "*"
|
||||
- Sid: CreateApplicationVersion
|
||||
Effect: Allow
|
||||
Action: elasticbeanstalk:CreateApplicationVersion
|
||||
Resource:
|
||||
- arn:aws:elasticbeanstalk:us-east-1:396287094661:application/shoc-backend
|
||||
- arn:aws:elasticbeanstalk:us-east-1:396287094661:applicationversion/shoc-backend/*
|
||||
- Sid: UpdatePocEnvironment
|
||||
Effect: Allow
|
||||
Action: elasticbeanstalk:UpdateEnvironment
|
||||
Resource: arn:aws:elasticbeanstalk:us-east-1:396287094661:environment/shoc-backend/shoc-backend-tf-poc
|
||||
- Sid: UseBeanstalkBucket
|
||||
Effect: Allow
|
||||
Action:
|
||||
- s3:GetBucketLocation
|
||||
- s3:ListBucket
|
||||
Resource: arn:aws:s3:::elasticbeanstalk-us-east-1-396287094661
|
||||
- Sid: UploadApplicationVersion
|
||||
Effect: Allow
|
||||
Action: s3:PutObject
|
||||
Resource: arn:aws:s3:::elasticbeanstalk-us-east-1-396287094661/shoc-backend/*
|
||||
- Sid: DenyLiveEnvironments
|
||||
Effect: Deny
|
||||
Action: elasticbeanstalk:*
|
||||
Resource:
|
||||
- arn:aws:elasticbeanstalk:us-east-1:396287094661:environment/shoc-backend/shoc-backend-dev
|
||||
- arn:aws:elasticbeanstalk:us-east-1:396287094661:environment/shoc-backend/shoc-backend-staging
|
||||
|
||||
ShocBackendDevDeployBoundary:
|
||||
Type: AWS::IAM::ManagedPolicy
|
||||
Condition: IsExternalDevAccount
|
||||
|
|
@ -2764,54 +2715,6 @@ Resources:
|
|||
# AWSElasticBeanstalkWebTier while removing its 2026 Bedrock/Marketplace
|
||||
# additions. All S3/log/health resources are pinned to this account and the
|
||||
# exact SHOC environment; X-Ray APIs do not support resource scoping.
|
||||
ShocBackendPocRuntimeBoundary:
|
||||
Type: AWS::IAM::ManagedPolicy
|
||||
Condition: IsExternalDevAccount
|
||||
DeletionPolicy: Retain
|
||||
UpdateReplacePolicy: Retain
|
||||
Properties:
|
||||
ManagedPolicyName: shoc-backend-tf-poc-runtime-boundary
|
||||
Description: Maximum runtime permissions for the SHOC backend tf-poc instance role.
|
||||
PolicyDocument:
|
||||
Version: "2012-10-17"
|
||||
Statement:
|
||||
- Sid: ReadAppConfig
|
||||
Effect: Allow
|
||||
Action: secretsmanager:GetSecretValue
|
||||
Resource: arn:aws:secretsmanager:us-east-1:396287094661:secret:shoc/tf-poc/app-config-*
|
||||
- Sid: ElasticBeanstalkBucket
|
||||
Effect: Allow
|
||||
Action:
|
||||
- s3:Get*
|
||||
- s3:List*
|
||||
- s3:PutObject
|
||||
Resource:
|
||||
- arn:aws:s3:::elasticbeanstalk-us-east-1-396287094661
|
||||
- arn:aws:s3:::elasticbeanstalk-us-east-1-396287094661/*
|
||||
- Sid: ElasticBeanstalkHealth
|
||||
Effect: Allow
|
||||
Action: elasticbeanstalk:PutInstanceStatistics
|
||||
Resource:
|
||||
- arn:aws:elasticbeanstalk:us-east-1:396287094661:application/shoc-backend
|
||||
- arn:aws:elasticbeanstalk:us-east-1:396287094661:environment/shoc-backend/shoc-backend-tf-poc
|
||||
- Sid: ElasticBeanstalkLogs
|
||||
Effect: Allow
|
||||
Action:
|
||||
- logs:PutLogEvents
|
||||
- logs:CreateLogStream
|
||||
- logs:DescribeLogStreams
|
||||
- logs:DescribeLogGroups
|
||||
Resource: arn:aws:logs:us-east-1:396287094661:log-group:/aws/elasticbeanstalk/shoc-backend-tf-poc*
|
||||
- Sid: XRayTelemetry
|
||||
Effect: Allow
|
||||
Action:
|
||||
- xray:PutTraceSegments
|
||||
- xray:PutTelemetryRecords
|
||||
- xray:GetSamplingRules
|
||||
- xray:GetSamplingTargets
|
||||
- xray:GetSamplingStatisticSummaries
|
||||
Resource: "*"
|
||||
|
||||
ShocBackendDevRuntimeBoundary:
|
||||
Type: AWS::IAM::ManagedPolicy
|
||||
Condition: IsExternalDevAccount
|
||||
|
|
|
|||
Loading…
Add table
Reference in a new issue