mirror of
https://github.com/Sea-Haven-Industries/seahaven-org-baseline.git
synced 2026-10-06 09:52:01 +00:00
fix(iam): allow frontend githubdeploy to read deploy SSM (PLAT-212)
HCP apply already writes /shoc-frontend-new/<env>/deploy/*, but the githubdeploy ceiling omitted GetParameter so Deploy Web cannot resolve bucket and distribution after origin moves to the bucket root.
This commit is contained in:
parent
0857174b6d
commit
ae46270912
2 changed files with 16 additions and 4 deletions
12
README.md
12
README.md
|
|
@ -419,9 +419,12 @@ trust SCP is 2,189 compact characters. Keep size assertions in every change.
|
|||
boundaries first.** The two live retained boundaries are
|
||||
`shoc-frontend-new-{dev,staging}-deploy-boundary`. Each permits only
|
||||
bucket location/list/version reads, object get/put/current and version delete,
|
||||
`GetDistribution`/`GetDistributionConfig`, and invalidation create/read for
|
||||
one exact distribution. Dev is pinned to `E2CWLM1AFB964P`; staging is pinned
|
||||
to `E2JDVEZ6EGD49J`. The frontend tf-poc rehearsal is retired: its site,
|
||||
`GetDistribution`/`GetDistributionConfig`, invalidation create/read for
|
||||
one exact distribution, and `GetParameter`/`GetParameters` on
|
||||
`/shoc-frontend-new/<env>/deploy/*`. Dev is pinned to `E2CWLM1AFB964P`; staging is pinned
|
||||
to `E2JDVEZ6EGD49J`. SCP `ProtectDeploymentPrincipalLifecycle` still denies
|
||||
`iam:UpdateRoleDescription` on `githubdeploy-*` for HCP apply roles; the
|
||||
frontend Terraform role must ignore description drift. The frontend tf-poc rehearsal is retired: its site,
|
||||
HCP workspace, and GitHub deploy role are gone. `enableShocFrontendPocRoles`
|
||||
is false and the five `shocFrontendPoc*` identifiers are empty, so
|
||||
`ShouldManageShocFrontendPocRoles` stays false. After the stack update,
|
||||
|
|
@ -472,7 +475,8 @@ job:
|
|||
The apply roles explicitly deny role lifecycle/boundary/managed-policy
|
||||
changes, `PassRole`, secret reads, CloudFront/S3 create and
|
||||
delete (including OAC mutation), and deletion of inline role or bucket
|
||||
policies. Live apply roles may `UpdateAssumeRolePolicy` only on the matching
|
||||
policies. `iam:UpdateRoleDescription` stays in that deny and in the OU SCP;
|
||||
HCP cannot change githubdeploy descriptions. Live apply roles may `UpdateAssumeRolePolicy` only on the matching
|
||||
`githubdeploy-shoc-frontend-new-<env>` role. `DenySecretAccess` still denies
|
||||
Secrets Manager and KMS decrypt; SSM GetParameter/GetParameters/GetParametersByPath
|
||||
are denied except `/shoc-frontend-new/<env>/deploy/*`, which plan and apply
|
||||
|
|
|
|||
|
|
@ -741,6 +741,14 @@ export class ShocFrontendResources extends Construct {
|
|||
wrapDistributionStatement(readDistributionStatement),
|
||||
wrapDistributionStatement(invalidationStatement),
|
||||
);
|
||||
if (isLiveFrontendEnvironment(environment)) {
|
||||
boundaryStatements.push({
|
||||
Sid: "ReadDeployParams",
|
||||
Effect: "Allow",
|
||||
Action: ["ssm:GetParameter", "ssm:GetParameters"],
|
||||
Resource: deployParameterArn(environment),
|
||||
});
|
||||
}
|
||||
|
||||
const deployBoundary = new iam.CfnManagedPolicy(
|
||||
this,
|
||||
|
|
|
|||
Loading…
Add table
Reference in a new issue