mirror of
https://github.com/Sea-Haven-Industries/seahaven-org-baseline.git
synced 2026-09-30 06:53:17 +00:00
Merge pull request #77 from Sea-Haven-Industries/fix/hcptf-afi-s3-bucket-acl
fix(iam): afi hcptf plan refresh and artifact s3:* (PLAT-56)
This commit is contained in:
commit
991cff8333
1 changed files with 65 additions and 21 deletions
|
|
@ -377,10 +377,12 @@ Resources:
|
|||
#
|
||||
# First HCP Terraform workload. Trust subs are exact StringEquals on
|
||||
# organization/project/workspace/run_phase — never StringLike, never a
|
||||
# wildcarded run_phase. Plan role: ViewOnlyAccess only (never ReadOnlyAccess,
|
||||
# which grants secretsmanager:GetSecretValue). Apply role: attaches the
|
||||
# shared guardrail plus stack-scoped Lambda / layer / EventBridge / Logs.
|
||||
# Prod-only (IsProdAccount): this template also deploys to seahaven-dev.
|
||||
# wildcarded run_phase. Plan role: ViewOnlyAccess (never ReadOnlyAccess,
|
||||
# which grants secretsmanager:GetSecretValue) PLUS a stack-scoped refresh
|
||||
# inline policy — ViewOnlyAccess omits iam:GetRole and events:DescribeRule,
|
||||
# which Terraform needs to refresh state after the first apply. Apply role:
|
||||
# attaches the shared guardrail plus stack-scoped Lambda / layer /
|
||||
# EventBridge / Logs / artifact-bucket. Prod-only (IsProdAccount).
|
||||
# ---------------------------------------------------------------------------
|
||||
HcptfAfiBackupMonitorPlanRole:
|
||||
Type: AWS::IAM::Role
|
||||
|
|
@ -400,6 +402,60 @@ Resources:
|
|||
"app.terraform.io:sub": organization:seahaven:project:seahaven-prod:workspace:afi-backup-monitor-prod:run_phase:plan
|
||||
ManagedPolicyArns:
|
||||
- arn:aws:iam::aws:policy/job-function/ViewOnlyAccess
|
||||
Policies:
|
||||
- PolicyName: afi-backup-monitor-plan-refresh
|
||||
PolicyDocument:
|
||||
Version: "2012-10-17"
|
||||
Statement:
|
||||
- Sid: RefreshIamRoles
|
||||
Effect: Allow
|
||||
Action:
|
||||
- iam:GetRole
|
||||
- iam:GetRolePolicy
|
||||
- iam:ListRolePolicies
|
||||
- iam:ListAttachedRolePolicies
|
||||
Resource:
|
||||
- !Sub "arn:aws:iam::${AWS::AccountId}:role/tf-managed/afi-*"
|
||||
- Sid: RefreshManagedPolicies
|
||||
Effect: Allow
|
||||
Action:
|
||||
- iam:GetPolicy
|
||||
- iam:GetPolicyVersion
|
||||
Resource: "*"
|
||||
- Sid: RefreshEventBridge
|
||||
Effect: Allow
|
||||
Action:
|
||||
- events:DescribeRule
|
||||
- events:ListTargetsByRule
|
||||
- events:ListTagsForResource
|
||||
Resource:
|
||||
- !Sub "arn:aws:events:us-east-1:${AWS::AccountId}:rule/afi-*"
|
||||
- Sid: RefreshLambda
|
||||
Effect: Allow
|
||||
Action:
|
||||
- lambda:GetFunction
|
||||
- lambda:GetFunctionConfiguration
|
||||
- lambda:GetPolicy
|
||||
- lambda:GetLayerVersion
|
||||
- lambda:ListVersionsByFunction
|
||||
- lambda:ListTags
|
||||
Resource:
|
||||
- !Sub "arn:aws:lambda:us-east-1:${AWS::AccountId}:function:afi-*"
|
||||
- !Sub "arn:aws:lambda:us-east-1:${AWS::AccountId}:layer:afi-shared*"
|
||||
- Sid: RefreshArtifactsBucket
|
||||
Effect: Allow
|
||||
Action:
|
||||
- s3:Get*
|
||||
- s3:ListBucket
|
||||
Resource:
|
||||
- !Sub "arn:aws:s3:::afi-backup-monitor-artifacts-${AWS::AccountId}"
|
||||
- !Sub "arn:aws:s3:::afi-backup-monitor-artifacts-${AWS::AccountId}/*"
|
||||
- Sid: RefreshLogs
|
||||
Effect: Allow
|
||||
Action:
|
||||
- logs:DescribeLogGroups
|
||||
- logs:ListTagsForResource
|
||||
Resource: "*"
|
||||
|
||||
HcptfAfiBackupMonitorApplyRole:
|
||||
Type: AWS::IAM::Role
|
||||
|
|
@ -498,26 +554,14 @@ Resources:
|
|||
Resource: "*"
|
||||
# Artifact bucket for HCP plan/apply split: zip bytes travel in the
|
||||
# plan via aws_s3_object content_base64 (local archive_file paths
|
||||
# from the plan worker are not on the apply worker).
|
||||
# from the plan worker are not on the apply worker). Action set is
|
||||
# s3:* on this bucket only — the AWS provider reads many GetBucket*
|
||||
# attributes (e.g. GetBucketAcl) after CreateBucket; enumerating
|
||||
# them lags provider upgrades (PLAT-56 first-apply miss).
|
||||
- Sid: LambdaArtifactsBucket
|
||||
Effect: Allow
|
||||
Action:
|
||||
- s3:CreateBucket
|
||||
- s3:DeleteBucket
|
||||
- s3:GetBucketLocation
|
||||
- s3:GetBucketPolicy
|
||||
- s3:PutBucketPolicy
|
||||
- s3:DeleteBucketPolicy
|
||||
- s3:GetBucketVersioning
|
||||
- s3:PutBucketVersioning
|
||||
- s3:GetBucketPublicAccessBlock
|
||||
- s3:PutBucketPublicAccessBlock
|
||||
- s3:GetBucketTagging
|
||||
- s3:PutBucketTagging
|
||||
- s3:ListBucket
|
||||
- s3:GetObject
|
||||
- s3:PutObject
|
||||
- s3:DeleteObject
|
||||
- s3:*
|
||||
Resource:
|
||||
- !Sub "arn:aws:s3:::afi-backup-monitor-artifacts-${AWS::AccountId}"
|
||||
- !Sub "arn:aws:s3:::afi-backup-monitor-artifacts-${AWS::AccountId}/*"
|
||||
|
|
|
|||
Loading…
Add table
Reference in a new issue