mirror of
https://github.com/Sea-Haven-Industries/seahaven-org-baseline.git
synced 2026-10-07 11:28:55 +00:00
chore(iam): remove backend tf-poc boundaries (#139)
Some checks failed
Some checks failed
This commit is contained in:
parent
4f0d84cddb
commit
6bc4f6e095
2 changed files with 15 additions and 112 deletions
26
README.md
26
README.md
|
|
@ -259,18 +259,24 @@ Prod/dev still carry, until PLAT-147 deletes those two stacks:
|
||||||
External-dev still carries:
|
External-dev still carries:
|
||||||
|
|
||||||
- external-dev-only deploy boundaries
|
- external-dev-only deploy boundaries
|
||||||
`shoc-backend-{tf-poc,dev,staging}-deploy-boundary`. Each is the maximum
|
`shoc-backend-{dev,staging}-deploy-boundary`. Each is the maximum
|
||||||
current policy for one exact `githubdeploy-shoc-backend-*` role. Dev
|
current policy for one exact `githubdeploy-shoc-backend-*` role. Dev
|
||||||
temporarily retains its live broad `elasticbeanstalk-*` S3 grants so
|
temporarily retains its live broad `elasticbeanstalk-*` S3 grants so
|
||||||
boundary attachment cannot regress deployment before the separately
|
boundary attachment cannot regress deployment before the separately
|
||||||
reviewed policy narrowing,
|
reviewed policy narrowing,
|
||||||
- external-dev-only runtime boundaries
|
- external-dev-only runtime boundaries
|
||||||
`shoc-backend-{tf-poc,dev,staging}-runtime-boundary`. These retain only the
|
`shoc-backend-{dev,staging}-runtime-boundary`. These retain only the
|
||||||
account-scoped S3, environment health/log, and X-Ray portions of
|
account-scoped S3, environment health/log, and X-Ray portions of
|
||||||
`AWSElasticBeanstalkWebTier`, plus each environment's exact secrets/KMS/STS
|
`AWSElasticBeanstalkWebTier`, plus each environment's exact secrets/KMS/STS
|
||||||
data plane. They deliberately exclude the managed policy's 2026
|
data plane. They deliberately exclude the managed policy's 2026
|
||||||
Bedrock/Marketplace additions.
|
Bedrock/Marketplace additions.
|
||||||
|
|
||||||
|
The retired backend tf-poc deploy/runtime boundaries are no longer declared.
|
||||||
|
Because their last managed definitions used `DeletionPolicy: Retain`, the
|
||||||
|
external-dev stack update only removes CloudFormation ownership. Verify both
|
||||||
|
policies still have zero attachments, then delete the retained physical
|
||||||
|
policies in a separately approved post-deploy step.
|
||||||
|
|
||||||
**`seahaven-hcptf-iam-management` derives from `seahaven-cfn-exec-iam-management`
|
**`seahaven-hcptf-iam-management` derives from `seahaven-cfn-exec-iam-management`
|
||||||
but is deliberately stricter — it is not a mirror.** The 2026-07-30 security
|
but is deliberately stricter — it is not a mirror.** The 2026-07-30 security
|
||||||
review confirmed the SAM copy's `Resource: "*"` role grants as a critical
|
review confirmed the SAM copy's `Resource: "*"` role grants as a critical
|
||||||
|
|
@ -321,16 +327,12 @@ automatic and unchanged.
|
||||||
|
|
||||||
`CreateOIDCProvider=false` is fixed in `bin/app.ts`; the external-dev
|
`CreateOIDCProvider=false` is fixed in `bin/app.ts`; the external-dev
|
||||||
account therefore creates neither the existing provider, SHOC roles, nor
|
account therefore creates neither the existing provider, SHOC roles, nor
|
||||||
the prod/dev-only shared IAM policy. The base stack does create all six
|
the prod/dev-only shared IAM policy. The base stack does create the four
|
||||||
retained external-dev deploy/runtime boundary policies.
|
retained backend dev/staging deploy/runtime boundary policies.
|
||||||
2. Set `enableShocBackendPocRoles` to `true` in `cdk.json`, leave the live gate
|
2. Set `enableShocBackendPocRoles` to `true` in `cdk.json`, leave the live gate
|
||||||
`false`, review the synthesized two-role addition, then run the normal
|
`false`, review the synthesized two-role addition, then run the normal
|
||||||
external-dev stack update. This creates only the new tf-poc HCP plan/apply
|
external-dev stack update. This creates only the new tf-poc HCP plan/apply
|
||||||
pair. The retained POC CDK stack references
|
pair.
|
||||||
`shoc-backend-tf-poc-deploy-boundary` when it creates
|
|
||||||
`githubdeploy-shoc-backend-tf-poc` and
|
|
||||||
`shoc-backend-tf-poc-runtime-boundary` when it creates the POC runtime
|
|
||||||
role; do not attach the generic account execution boundary to either role.
|
|
||||||
3. Prove both tf-poc HCP assumptions and the retained POC import rehearsal
|
3. Prove both tf-poc HCP assumptions and the retained POC import rehearsal
|
||||||
before touching the live-role ownership boundary.
|
before touching the live-role ownership boundary.
|
||||||
4. In a separately approved administrator/CDK migration, tag the existing HCP
|
4. In a separately approved administrator/CDK migration, tag the existing HCP
|
||||||
|
|
@ -344,10 +346,8 @@ automatic and unchanged.
|
||||||
and attach `shoc-backend-dev-runtime-boundary` /
|
and attach `shoc-backend-dev-runtime-boundary` /
|
||||||
`shoc-backend-staging-runtime-boundary` to the exact runtime roles. Verify
|
`shoc-backend-staging-runtime-boundary` to the exact runtime roles. Verify
|
||||||
the boundary ceilings before adding the matching manager tag to either
|
the boundary ceilings before adding the matching manager tag to either
|
||||||
target `githubdeploy-*` role. The POC CDK
|
target `githubdeploy-*` role. Verify each effective deployment action before
|
||||||
creates its deploy role with `HcpTerraformWorkspace=shoc-backend-tf-poc`;
|
continuing. HCP remains
|
||||||
the substrate-created POC apply role already carries the same principal
|
|
||||||
tag. Verify each effective deployment action before continuing. HCP remains
|
|
||||||
blocked while a target tag is missing/different or the target lacks its
|
blocked while a target tag is missing/different or the target lacks its
|
||||||
exact dedicated boundary, so a partial migration cannot authorize policy
|
exact dedicated boundary, so a partial migration cannot authorize policy
|
||||||
writes. Complete both runtime/deploy boundary attachments before workload
|
writes. Complete both runtime/deploy boundary attachments before workload
|
||||||
|
|
|
||||||
|
|
@ -2579,59 +2579,10 @@ Resources:
|
||||||
# ---------------------------------------------------------------------------
|
# ---------------------------------------------------------------------------
|
||||||
# SHOC backend GitHub deployment permissions boundaries (external-dev only)
|
# SHOC backend GitHub deployment permissions boundaries (external-dev only)
|
||||||
#
|
#
|
||||||
# These are ceilings for the three exact githubdeploy roles, not grants.
|
# These are ceilings for the dev and staging githubdeploy roles, not grants.
|
||||||
# Existing dev/staging roles receive them through a separately approved
|
# Existing dev/staging roles receive them through a separately approved
|
||||||
# administrator/CDK action before HCP import. The retained POC CDK stack
|
# administrator/CDK action before HCP import.
|
||||||
# attaches its boundary when it creates the POC deploy role.
|
|
||||||
# ---------------------------------------------------------------------------
|
# ---------------------------------------------------------------------------
|
||||||
ShocBackendPocDeployBoundary:
|
|
||||||
Type: AWS::IAM::ManagedPolicy
|
|
||||||
Condition: IsExternalDevAccount
|
|
||||||
DeletionPolicy: Retain
|
|
||||||
UpdateReplacePolicy: Retain
|
|
||||||
Properties:
|
|
||||||
ManagedPolicyName: shoc-backend-tf-poc-deploy-boundary
|
|
||||||
Description: Maximum deployment permissions for githubdeploy-shoc-backend-tf-poc.
|
|
||||||
PolicyDocument:
|
|
||||||
Version: "2012-10-17"
|
|
||||||
Statement:
|
|
||||||
- Sid: DescribeDeploymentResources
|
|
||||||
Effect: Allow
|
|
||||||
Action:
|
|
||||||
- autoscaling:Describe*
|
|
||||||
- ec2:Describe*
|
|
||||||
- elasticbeanstalk:DescribeApplicationVersions
|
|
||||||
- elasticbeanstalk:DescribeEnvironments
|
|
||||||
- elasticbeanstalk:DescribeEvents
|
|
||||||
- elasticloadbalancing:Describe*
|
|
||||||
Resource: "*"
|
|
||||||
- Sid: CreateApplicationVersion
|
|
||||||
Effect: Allow
|
|
||||||
Action: elasticbeanstalk:CreateApplicationVersion
|
|
||||||
Resource:
|
|
||||||
- arn:aws:elasticbeanstalk:us-east-1:396287094661:application/shoc-backend
|
|
||||||
- arn:aws:elasticbeanstalk:us-east-1:396287094661:applicationversion/shoc-backend/*
|
|
||||||
- Sid: UpdatePocEnvironment
|
|
||||||
Effect: Allow
|
|
||||||
Action: elasticbeanstalk:UpdateEnvironment
|
|
||||||
Resource: arn:aws:elasticbeanstalk:us-east-1:396287094661:environment/shoc-backend/shoc-backend-tf-poc
|
|
||||||
- Sid: UseBeanstalkBucket
|
|
||||||
Effect: Allow
|
|
||||||
Action:
|
|
||||||
- s3:GetBucketLocation
|
|
||||||
- s3:ListBucket
|
|
||||||
Resource: arn:aws:s3:::elasticbeanstalk-us-east-1-396287094661
|
|
||||||
- Sid: UploadApplicationVersion
|
|
||||||
Effect: Allow
|
|
||||||
Action: s3:PutObject
|
|
||||||
Resource: arn:aws:s3:::elasticbeanstalk-us-east-1-396287094661/shoc-backend/*
|
|
||||||
- Sid: DenyLiveEnvironments
|
|
||||||
Effect: Deny
|
|
||||||
Action: elasticbeanstalk:*
|
|
||||||
Resource:
|
|
||||||
- arn:aws:elasticbeanstalk:us-east-1:396287094661:environment/shoc-backend/shoc-backend-dev
|
|
||||||
- arn:aws:elasticbeanstalk:us-east-1:396287094661:environment/shoc-backend/shoc-backend-staging
|
|
||||||
|
|
||||||
ShocBackendDevDeployBoundary:
|
ShocBackendDevDeployBoundary:
|
||||||
Type: AWS::IAM::ManagedPolicy
|
Type: AWS::IAM::ManagedPolicy
|
||||||
Condition: IsExternalDevAccount
|
Condition: IsExternalDevAccount
|
||||||
|
|
@ -2764,54 +2715,6 @@ Resources:
|
||||||
# AWSElasticBeanstalkWebTier while removing its 2026 Bedrock/Marketplace
|
# AWSElasticBeanstalkWebTier while removing its 2026 Bedrock/Marketplace
|
||||||
# additions. All S3/log/health resources are pinned to this account and the
|
# additions. All S3/log/health resources are pinned to this account and the
|
||||||
# exact SHOC environment; X-Ray APIs do not support resource scoping.
|
# exact SHOC environment; X-Ray APIs do not support resource scoping.
|
||||||
ShocBackendPocRuntimeBoundary:
|
|
||||||
Type: AWS::IAM::ManagedPolicy
|
|
||||||
Condition: IsExternalDevAccount
|
|
||||||
DeletionPolicy: Retain
|
|
||||||
UpdateReplacePolicy: Retain
|
|
||||||
Properties:
|
|
||||||
ManagedPolicyName: shoc-backend-tf-poc-runtime-boundary
|
|
||||||
Description: Maximum runtime permissions for the SHOC backend tf-poc instance role.
|
|
||||||
PolicyDocument:
|
|
||||||
Version: "2012-10-17"
|
|
||||||
Statement:
|
|
||||||
- Sid: ReadAppConfig
|
|
||||||
Effect: Allow
|
|
||||||
Action: secretsmanager:GetSecretValue
|
|
||||||
Resource: arn:aws:secretsmanager:us-east-1:396287094661:secret:shoc/tf-poc/app-config-*
|
|
||||||
- Sid: ElasticBeanstalkBucket
|
|
||||||
Effect: Allow
|
|
||||||
Action:
|
|
||||||
- s3:Get*
|
|
||||||
- s3:List*
|
|
||||||
- s3:PutObject
|
|
||||||
Resource:
|
|
||||||
- arn:aws:s3:::elasticbeanstalk-us-east-1-396287094661
|
|
||||||
- arn:aws:s3:::elasticbeanstalk-us-east-1-396287094661/*
|
|
||||||
- Sid: ElasticBeanstalkHealth
|
|
||||||
Effect: Allow
|
|
||||||
Action: elasticbeanstalk:PutInstanceStatistics
|
|
||||||
Resource:
|
|
||||||
- arn:aws:elasticbeanstalk:us-east-1:396287094661:application/shoc-backend
|
|
||||||
- arn:aws:elasticbeanstalk:us-east-1:396287094661:environment/shoc-backend/shoc-backend-tf-poc
|
|
||||||
- Sid: ElasticBeanstalkLogs
|
|
||||||
Effect: Allow
|
|
||||||
Action:
|
|
||||||
- logs:PutLogEvents
|
|
||||||
- logs:CreateLogStream
|
|
||||||
- logs:DescribeLogStreams
|
|
||||||
- logs:DescribeLogGroups
|
|
||||||
Resource: arn:aws:logs:us-east-1:396287094661:log-group:/aws/elasticbeanstalk/shoc-backend-tf-poc*
|
|
||||||
- Sid: XRayTelemetry
|
|
||||||
Effect: Allow
|
|
||||||
Action:
|
|
||||||
- xray:PutTraceSegments
|
|
||||||
- xray:PutTelemetryRecords
|
|
||||||
- xray:GetSamplingRules
|
|
||||||
- xray:GetSamplingTargets
|
|
||||||
- xray:GetSamplingStatisticSummaries
|
|
||||||
Resource: "*"
|
|
||||||
|
|
||||||
ShocBackendDevRuntimeBoundary:
|
ShocBackendDevRuntimeBoundary:
|
||||||
Type: AWS::IAM::ManagedPolicy
|
Type: AWS::IAM::ManagedPolicy
|
||||||
Condition: IsExternalDevAccount
|
Condition: IsExternalDevAccount
|
||||||
|
|
|
||||||
Loading…
Add table
Reference in a new issue