chore(iam): remove backend tf-poc boundaries (#139)
Some checks failed
Deploy / deploy-management (push) Has been cancelled
Deploy / deploy-external-dev (push) Has been cancelled
Deploy / deploy-security (push) Has been cancelled
Deploy / deploy-dev (push) Has been cancelled
Deploy / deploy-prod (push) Has been cancelled

This commit is contained in:
Adam Moussa 2026-09-03 15:04:58 +00:00 • committed by GitHub
parent 4f0d84cddb
commit 6bc4f6e095
No known key found for this signature in database
GPG key ID: B5690EEEBB952194
2 changed files with 15 additions and 112 deletions

View file

@ -259,18 +259,24 @@ Prod/dev still carry, until PLAT-147 deletes those two stacks:
External-dev still carries:
- external-dev-only deploy boundaries
`shoc-backend-{tf-poc,dev,staging}-deploy-boundary`. Each is the maximum
`shoc-backend-{dev,staging}-deploy-boundary`. Each is the maximum
current policy for one exact `githubdeploy-shoc-backend-*` role. Dev
temporarily retains its live broad `elasticbeanstalk-*` S3 grants so
boundary attachment cannot regress deployment before the separately
reviewed policy narrowing,
- external-dev-only runtime boundaries
`shoc-backend-{tf-poc,dev,staging}-runtime-boundary`. These retain only the
`shoc-backend-{dev,staging}-runtime-boundary`. These retain only the
account-scoped S3, environment health/log, and X-Ray portions of
`AWSElasticBeanstalkWebTier`, plus each environment's exact secrets/KMS/STS
data plane. They deliberately exclude the managed policy's 2026
Bedrock/Marketplace additions.
The retired backend tf-poc deploy/runtime boundaries are no longer declared.
Because their last managed definitions used `DeletionPolicy: Retain`, the
external-dev stack update only removes CloudFormation ownership. Verify both
policies still have zero attachments, then delete the retained physical
policies in a separately approved post-deploy step.
**`seahaven-hcptf-iam-management` derives from `seahaven-cfn-exec-iam-management`
but is deliberately stricter — it is not a mirror.** The 2026-07-30 security
review confirmed the SAM copy's `Resource: "*"` role grants as a critical
@ -321,16 +327,12 @@ automatic and unchanged.
`CreateOIDCProvider=false` is fixed in `bin/app.ts`; the external-dev
account therefore creates neither the existing provider, SHOC roles, nor
the prod/dev-only shared IAM policy. The base stack does create all six
retained external-dev deploy/runtime boundary policies.
the prod/dev-only shared IAM policy. The base stack does create the four
retained backend dev/staging deploy/runtime boundary policies.
2. Set `enableShocBackendPocRoles` to `true` in `cdk.json`, leave the live gate
`false`, review the synthesized two-role addition, then run the normal
external-dev stack update. This creates only the new tf-poc HCP plan/apply
pair. The retained POC CDK stack references
`shoc-backend-tf-poc-deploy-boundary` when it creates
`githubdeploy-shoc-backend-tf-poc` and
`shoc-backend-tf-poc-runtime-boundary` when it creates the POC runtime
role; do not attach the generic account execution boundary to either role.
pair.
3. Prove both tf-poc HCP assumptions and the retained POC import rehearsal
before touching the live-role ownership boundary.
4. In a separately approved administrator/CDK migration, tag the existing HCP
@ -344,10 +346,8 @@ automatic and unchanged.
and attach `shoc-backend-dev-runtime-boundary` /
`shoc-backend-staging-runtime-boundary` to the exact runtime roles. Verify
the boundary ceilings before adding the matching manager tag to either
target `githubdeploy-*` role. The POC CDK
creates its deploy role with `HcpTerraformWorkspace=shoc-backend-tf-poc`;
the substrate-created POC apply role already carries the same principal
tag. Verify each effective deployment action before continuing. HCP remains
target `githubdeploy-*` role. Verify each effective deployment action before
continuing. HCP remains
blocked while a target tag is missing/different or the target lacks its
exact dedicated boundary, so a partial migration cannot authorize policy
writes. Complete both runtime/deploy boundary attachments before workload

View file

@ -2579,59 +2579,10 @@ Resources:
# ---------------------------------------------------------------------------
# SHOC backend GitHub deployment permissions boundaries (external-dev only)
#
# These are ceilings for the three exact githubdeploy roles, not grants.
# These are ceilings for the dev and staging githubdeploy roles, not grants.
# Existing dev/staging roles receive them through a separately approved
# administrator/CDK action before HCP import. The retained POC CDK stack
# attaches its boundary when it creates the POC deploy role.
# administrator/CDK action before HCP import.
# ---------------------------------------------------------------------------
ShocBackendPocDeployBoundary:
Type: AWS::IAM::ManagedPolicy
Condition: IsExternalDevAccount
DeletionPolicy: Retain
UpdateReplacePolicy: Retain
Properties:
ManagedPolicyName: shoc-backend-tf-poc-deploy-boundary
Description: Maximum deployment permissions for githubdeploy-shoc-backend-tf-poc.
PolicyDocument:
Version: "2012-10-17"
Statement:
- Sid: DescribeDeploymentResources
Effect: Allow
Action:
- autoscaling:Describe*
- ec2:Describe*
- elasticbeanstalk:DescribeApplicationVersions
- elasticbeanstalk:DescribeEnvironments
- elasticbeanstalk:DescribeEvents
- elasticloadbalancing:Describe*
Resource: "*"
- Sid: CreateApplicationVersion
Effect: Allow
Action: elasticbeanstalk:CreateApplicationVersion
Resource:
- arn:aws:elasticbeanstalk:us-east-1:396287094661:application/shoc-backend
- arn:aws:elasticbeanstalk:us-east-1:396287094661:applicationversion/shoc-backend/*
- Sid: UpdatePocEnvironment
Effect: Allow
Action: elasticbeanstalk:UpdateEnvironment
Resource: arn:aws:elasticbeanstalk:us-east-1:396287094661:environment/shoc-backend/shoc-backend-tf-poc
- Sid: UseBeanstalkBucket
Effect: Allow
Action:
- s3:GetBucketLocation
- s3:ListBucket
Resource: arn:aws:s3:::elasticbeanstalk-us-east-1-396287094661
- Sid: UploadApplicationVersion
Effect: Allow
Action: s3:PutObject
Resource: arn:aws:s3:::elasticbeanstalk-us-east-1-396287094661/shoc-backend/*
- Sid: DenyLiveEnvironments
Effect: Deny
Action: elasticbeanstalk:*
Resource:
- arn:aws:elasticbeanstalk:us-east-1:396287094661:environment/shoc-backend/shoc-backend-dev
- arn:aws:elasticbeanstalk:us-east-1:396287094661:environment/shoc-backend/shoc-backend-staging
ShocBackendDevDeployBoundary:
Type: AWS::IAM::ManagedPolicy
Condition: IsExternalDevAccount
@ -2764,54 +2715,6 @@ Resources:
# AWSElasticBeanstalkWebTier while removing its 2026 Bedrock/Marketplace
# additions. All S3/log/health resources are pinned to this account and the
# exact SHOC environment; X-Ray APIs do not support resource scoping.
ShocBackendPocRuntimeBoundary:
Type: AWS::IAM::ManagedPolicy
Condition: IsExternalDevAccount
DeletionPolicy: Retain
UpdateReplacePolicy: Retain
Properties:
ManagedPolicyName: shoc-backend-tf-poc-runtime-boundary
Description: Maximum runtime permissions for the SHOC backend tf-poc instance role.
PolicyDocument:
Version: "2012-10-17"
Statement:
- Sid: ReadAppConfig
Effect: Allow
Action: secretsmanager:GetSecretValue
Resource: arn:aws:secretsmanager:us-east-1:396287094661:secret:shoc/tf-poc/app-config-*
- Sid: ElasticBeanstalkBucket
Effect: Allow
Action:
- s3:Get*
- s3:List*
- s3:PutObject
Resource:
- arn:aws:s3:::elasticbeanstalk-us-east-1-396287094661
- arn:aws:s3:::elasticbeanstalk-us-east-1-396287094661/*
- Sid: ElasticBeanstalkHealth
Effect: Allow
Action: elasticbeanstalk:PutInstanceStatistics
Resource:
- arn:aws:elasticbeanstalk:us-east-1:396287094661:application/shoc-backend
- arn:aws:elasticbeanstalk:us-east-1:396287094661:environment/shoc-backend/shoc-backend-tf-poc
- Sid: ElasticBeanstalkLogs
Effect: Allow
Action:
- logs:PutLogEvents
- logs:CreateLogStream
- logs:DescribeLogStreams
- logs:DescribeLogGroups
Resource: arn:aws:logs:us-east-1:396287094661:log-group:/aws/elasticbeanstalk/shoc-backend-tf-poc*
- Sid: XRayTelemetry
Effect: Allow
Action:
- xray:PutTraceSegments
- xray:PutTelemetryRecords
- xray:GetSamplingRules
- xray:GetSamplingTargets
- xray:GetSamplingStatisticSummaries
Resource: "*"
ShocBackendDevRuntimeBoundary:
Type: AWS::IAM::ManagedPolicy
Condition: IsExternalDevAccount