Merge pull request #77 from Sea-Haven-Industries/fix/hcptf-afi-s3-bucket-acl

fix(iam): afi hcptf plan refresh and artifact s3:* (PLAT-56)
This commit is contained in:
Adam Moussa 2026-08-05 12:57:39 -04:00 • committed by GitHub
commit 991cff8333
No known key found for this signature in database
GPG key ID: B5690EEEBB952194

View file

@ -377,10 +377,12 @@ Resources:
#
# First HCP Terraform workload. Trust subs are exact StringEquals on
# organization/project/workspace/run_phase — never StringLike, never a
# wildcarded run_phase. Plan role: ViewOnlyAccess only (never ReadOnlyAccess,
# which grants secretsmanager:GetSecretValue). Apply role: attaches the
# shared guardrail plus stack-scoped Lambda / layer / EventBridge / Logs.
# Prod-only (IsProdAccount): this template also deploys to seahaven-dev.
# wildcarded run_phase. Plan role: ViewOnlyAccess (never ReadOnlyAccess,
# which grants secretsmanager:GetSecretValue) PLUS a stack-scoped refresh
# inline policy — ViewOnlyAccess omits iam:GetRole and events:DescribeRule,
# which Terraform needs to refresh state after the first apply. Apply role:
# attaches the shared guardrail plus stack-scoped Lambda / layer /
# EventBridge / Logs / artifact-bucket. Prod-only (IsProdAccount).
# ---------------------------------------------------------------------------
HcptfAfiBackupMonitorPlanRole:
Type: AWS::IAM::Role
@ -400,6 +402,60 @@ Resources:
"app.terraform.io:sub": organization:seahaven:project:seahaven-prod:workspace:afi-backup-monitor-prod:run_phase:plan
ManagedPolicyArns:
- arn:aws:iam::aws:policy/job-function/ViewOnlyAccess
Policies:
- PolicyName: afi-backup-monitor-plan-refresh
PolicyDocument:
Version: "2012-10-17"
Statement:
- Sid: RefreshIamRoles
Effect: Allow
Action:
- iam:GetRole
- iam:GetRolePolicy
- iam:ListRolePolicies
- iam:ListAttachedRolePolicies
Resource:
- !Sub "arn:aws:iam::${AWS::AccountId}:role/tf-managed/afi-*"
- Sid: RefreshManagedPolicies
Effect: Allow
Action:
- iam:GetPolicy
- iam:GetPolicyVersion
Resource: "*"
- Sid: RefreshEventBridge
Effect: Allow
Action:
- events:DescribeRule
- events:ListTargetsByRule
- events:ListTagsForResource
Resource:
- !Sub "arn:aws:events:us-east-1:${AWS::AccountId}:rule/afi-*"
- Sid: RefreshLambda
Effect: Allow
Action:
- lambda:GetFunction
- lambda:GetFunctionConfiguration
- lambda:GetPolicy
- lambda:GetLayerVersion
- lambda:ListVersionsByFunction
- lambda:ListTags
Resource:
- !Sub "arn:aws:lambda:us-east-1:${AWS::AccountId}:function:afi-*"
- !Sub "arn:aws:lambda:us-east-1:${AWS::AccountId}:layer:afi-shared*"
- Sid: RefreshArtifactsBucket
Effect: Allow
Action:
- s3:Get*
- s3:ListBucket
Resource:
- !Sub "arn:aws:s3:::afi-backup-monitor-artifacts-${AWS::AccountId}"
- !Sub "arn:aws:s3:::afi-backup-monitor-artifacts-${AWS::AccountId}/*"
- Sid: RefreshLogs
Effect: Allow
Action:
- logs:DescribeLogGroups
- logs:ListTagsForResource
Resource: "*"
HcptfAfiBackupMonitorApplyRole:
Type: AWS::IAM::Role
@ -498,26 +554,14 @@ Resources:
Resource: "*"
# Artifact bucket for HCP plan/apply split: zip bytes travel in the
# plan via aws_s3_object content_base64 (local archive_file paths
# from the plan worker are not on the apply worker).
# from the plan worker are not on the apply worker). Action set is
# s3:* on this bucket only — the AWS provider reads many GetBucket*
# attributes (e.g. GetBucketAcl) after CreateBucket; enumerating
# them lags provider upgrades (PLAT-56 first-apply miss).
- Sid: LambdaArtifactsBucket
Effect: Allow
Action:
- s3:CreateBucket
- s3:DeleteBucket
- s3:GetBucketLocation
- s3:GetBucketPolicy
- s3:PutBucketPolicy
- s3:DeleteBucketPolicy
- s3:GetBucketVersioning
- s3:PutBucketVersioning
- s3:GetBucketPublicAccessBlock
- s3:PutBucketPublicAccessBlock
- s3:GetBucketTagging
- s3:PutBucketTagging
- s3:ListBucket
- s3:GetObject
- s3:PutObject
- s3:DeleteObject
- s3:*
Resource:
- !Sub "arn:aws:s3:::afi-backup-monitor-artifacts-${AWS::AccountId}"
- !Sub "arn:aws:s3:::afi-backup-monitor-artifacts-${AWS::AccountId}/*"