mirror of
https://github.com/Sea-Haven-Industries/seahaven-org-baseline.git
synced 2026-09-30 02:13:15 +00:00
feat(iam): allow PassRole to ECS tasks and EventBridge Scheduler (#151)
A first apply of Fargate and Scheduler targets cannot create those service-linked attachments while PassRole is Lambda-only.
This commit is contained in:
parent
960e4619b4
commit
7e41625e4b
5 changed files with 23 additions and 8 deletions
|
|
@ -527,7 +527,10 @@ projects `seahaven-mgmt`, `seahaven-prod`, `seahaven-dev`).
|
|||
`CreateRole` / `PutRolePolicy` / `AttachRolePolicy` /
|
||||
`PutRolePermissionsBoundary` on `tf-managed` roles require
|
||||
`iam:PermissionsBoundary` `StringLike` `policy/tf-managed/*` or
|
||||
`policy/seahaven-lambda-execution-boundary*`. `Null` false is not enough:
|
||||
`policy/seahaven-lambda-execution-boundary*`. `PassRole` on `tf-managed`
|
||||
roles is allowed to `lambda.amazonaws.com`, `ecs-tasks.amazonaws.com`,
|
||||
and `scheduler.amazonaws.com` so a first apply can create Fargate tasks
|
||||
and EventBridge Scheduler targets. `Null` false is not enough:
|
||||
it would accept `AdministratorAccess` as the ceiling. Must not mutate
|
||||
`githubdeploy-*`, `github-cfn-execution-role`, `cdk-hnb659fds-*`,
|
||||
`OrganizationAccountAccessRole`, `seahaven-*`. SCP
|
||||
|
|
|
|||
|
|
@ -140,14 +140,14 @@ data "aws_iam_policy_document" "hcptf_scoped_iam" {
|
|||
resources = ["arn:aws:iam::${local.account_id}:role/tf-managed/${local.stack_prefix}*"]
|
||||
}
|
||||
statement {
|
||||
sid = "PassExecRolesToLambda"
|
||||
sid = "PassExecRolesToCompute"
|
||||
effect = "Allow"
|
||||
actions = ["iam:PassRole"]
|
||||
resources = ["arn:aws:iam::${local.account_id}:role/tf-managed/${local.stack_prefix}*"]
|
||||
condition {
|
||||
test = "StringEquals"
|
||||
variable = "iam:PassedToService"
|
||||
values = ["lambda.amazonaws.com"]
|
||||
values = ["lambda.amazonaws.com", "ecs-tasks.amazonaws.com", "scheduler.amazonaws.com"]
|
||||
}
|
||||
}
|
||||
statement {
|
||||
|
|
|
|||
|
|
@ -86,13 +86,17 @@
|
|||
"Resource": "arn:aws:iam::__ACCOUNT_ID__:role/hcptf-*"
|
||||
},
|
||||
{
|
||||
"Sid": "PassTfManagedRolesToLambda",
|
||||
"Sid": "PassTfManagedRolesToCompute",
|
||||
"Effect": "Allow",
|
||||
"Action": "iam:PassRole",
|
||||
"Resource": "arn:aws:iam::__ACCOUNT_ID__:role/tf-managed/*",
|
||||
"Condition": {
|
||||
"StringEquals": {
|
||||
"iam:PassedToService": "lambda.amazonaws.com"
|
||||
"iam:PassedToService": [
|
||||
"lambda.amazonaws.com",
|
||||
"ecs-tasks.amazonaws.com",
|
||||
"scheduler.amazonaws.com"
|
||||
]
|
||||
}
|
||||
}
|
||||
},
|
||||
|
|
|
|||
|
|
@ -66,7 +66,11 @@
|
|||
"Resource": "arn:aws:iam::__ACCOUNT_ID__:role/tf-managed/__STACK_PREFIX__*",
|
||||
"Condition": {
|
||||
"StringEquals": {
|
||||
"iam:PassedToService": "lambda.amazonaws.com"
|
||||
"iam:PassedToService": [
|
||||
"lambda.amazonaws.com",
|
||||
"ecs-tasks.amazonaws.com",
|
||||
"scheduler.amazonaws.com"
|
||||
]
|
||||
}
|
||||
}
|
||||
},
|
||||
|
|
|
|||
|
|
@ -1837,8 +1837,12 @@ Resources:
|
|||
Resource: "*"
|
||||
|
||||
# ---------------------------------------------------------------------------
|
||||
# meal-order-manager-prod (PLAT-70) — HttpApi + 7 Lambdas + layer + DynamoDB
|
||||
# + S3 form/reports/artifacts + CloudFront/ACM/WAF + EventBridge + alarms.
|
||||
# meal-order-manager-prod (PLAT-70, imported to the app workspace in PLAT-146).
|
||||
# Live plan/apply IAM is terraform/hcp_iam.tf in meal-order-manager (ECS/ALB
|
||||
# as of PLAT-215). Do not mutate these CFN role policies; they are Retain
|
||||
# leftovers. githubdeploy-meal-order-manager OIDC lives in that app module.
|
||||
# ---------------------------------------------------------------------------
|
||||
# Original shape: HttpApi + Lambdas + DynamoDB + S3 + CloudFront.
|
||||
# Plan role: ViewOnly + plan-refresh sidecar. Apply role: HcptfIamManagement
|
||||
# + prefix-scoped service wildcards (no enumerated Get* lists).
|
||||
# ---------------------------------------------------------------------------
|
||||
|
|
|
|||
Loading…
Add table
Reference in a new issue