fix(iam): allow frontend githubdeploy to read deploy SSM (PLAT-212)

HCP apply already writes /shoc-frontend-new/<env>/deploy/*, but the
githubdeploy ceiling omitted GetParameter so Deploy Web cannot resolve
bucket and distribution after origin moves to the bucket root.
This commit is contained in:
Adam Moussa 2026-09-18 15:00:19 -04:00
parent 0857174b6d
commit ae46270912
No known key found for this signature in database
2 changed files with 16 additions and 4 deletions

View file

@ -419,9 +419,12 @@ trust SCP is 2,189 compact characters. Keep size assertions in every change.
boundaries first.** The two live retained boundaries are
`shoc-frontend-new-{dev,staging}-deploy-boundary`. Each permits only
bucket location/list/version reads, object get/put/current and version delete,
`GetDistribution`/`GetDistributionConfig`, and invalidation create/read for
one exact distribution. Dev is pinned to `E2CWLM1AFB964P`; staging is pinned
to `E2JDVEZ6EGD49J`. The frontend tf-poc rehearsal is retired: its site,
`GetDistribution`/`GetDistributionConfig`, invalidation create/read for
one exact distribution, and `GetParameter`/`GetParameters` on
`/shoc-frontend-new/<env>/deploy/*`. Dev is pinned to `E2CWLM1AFB964P`; staging is pinned
to `E2JDVEZ6EGD49J`. SCP `ProtectDeploymentPrincipalLifecycle` still denies
`iam:UpdateRoleDescription` on `githubdeploy-*` for HCP apply roles; the
frontend Terraform role must ignore description drift. The frontend tf-poc rehearsal is retired: its site,
HCP workspace, and GitHub deploy role are gone. `enableShocFrontendPocRoles`
is false and the five `shocFrontendPoc*` identifiers are empty, so
`ShouldManageShocFrontendPocRoles` stays false. After the stack update,
@ -472,7 +475,8 @@ job:
The apply roles explicitly deny role lifecycle/boundary/managed-policy
changes, `PassRole`, secret reads, CloudFront/S3 create and
delete (including OAC mutation), and deletion of inline role or bucket
policies. Live apply roles may `UpdateAssumeRolePolicy` only on the matching
policies. `iam:UpdateRoleDescription` stays in that deny and in the OU SCP;
HCP cannot change githubdeploy descriptions. Live apply roles may `UpdateAssumeRolePolicy` only on the matching
`githubdeploy-shoc-frontend-new-<env>` role. `DenySecretAccess` still denies
Secrets Manager and KMS decrypt; SSM GetParameter/GetParameters/GetParametersByPath
are denied except `/shoc-frontend-new/<env>/deploy/*`, which plan and apply

View file

@ -741,6 +741,14 @@ export class ShocFrontendResources extends Construct {
wrapDistributionStatement(readDistributionStatement),
wrapDistributionStatement(invalidationStatement),
);
if (isLiveFrontendEnvironment(environment)) {
boundaryStatements.push({
Sid: "ReadDeployParams",
Effect: "Allow",
Action: ["ssm:GetParameter", "ssm:GetParameters"],
Resource: deployParameterArn(environment),
});
}
const deployBoundary = new iam.CfnManagedPolicy(
this,