From ae4627091290141722965e65292ad6454e18c807 Mon Sep 17 00:00:00 2001 From: Adam Moussa Date: Fri, 18 Sep 2026 15:00:19 -0400 Subject: [PATCH] fix(iam): allow frontend githubdeploy to read deploy SSM (PLAT-212) HCP apply already writes /shoc-frontend-new//deploy/*, but the githubdeploy ceiling omitted GetParameter so Deploy Web cannot resolve bucket and distribution after origin moves to the bucket root. --- README.md | 12 ++++++++---- lib/terraform-substrate/shoc-frontend-resources.ts | 8 ++++++++ 2 files changed, 16 insertions(+), 4 deletions(-) diff --git a/README.md b/README.md index 7fe0ccd..5313bc8 100644 --- a/README.md +++ b/README.md @@ -419,9 +419,12 @@ trust SCP is 2,189 compact characters. Keep size assertions in every change. boundaries first.** The two live retained boundaries are `shoc-frontend-new-{dev,staging}-deploy-boundary`. Each permits only bucket location/list/version reads, object get/put/current and version delete, -`GetDistribution`/`GetDistributionConfig`, and invalidation create/read for -one exact distribution. Dev is pinned to `E2CWLM1AFB964P`; staging is pinned -to `E2JDVEZ6EGD49J`. The frontend tf-poc rehearsal is retired: its site, +`GetDistribution`/`GetDistributionConfig`, invalidation create/read for +one exact distribution, and `GetParameter`/`GetParameters` on +`/shoc-frontend-new//deploy/*`. Dev is pinned to `E2CWLM1AFB964P`; staging is pinned +to `E2JDVEZ6EGD49J`. SCP `ProtectDeploymentPrincipalLifecycle` still denies +`iam:UpdateRoleDescription` on `githubdeploy-*` for HCP apply roles; the +frontend Terraform role must ignore description drift. The frontend tf-poc rehearsal is retired: its site, HCP workspace, and GitHub deploy role are gone. `enableShocFrontendPocRoles` is false and the five `shocFrontendPoc*` identifiers are empty, so `ShouldManageShocFrontendPocRoles` stays false. After the stack update, @@ -472,7 +475,8 @@ job: The apply roles explicitly deny role lifecycle/boundary/managed-policy changes, `PassRole`, secret reads, CloudFront/S3 create and delete (including OAC mutation), and deletion of inline role or bucket -policies. Live apply roles may `UpdateAssumeRolePolicy` only on the matching +policies. `iam:UpdateRoleDescription` stays in that deny and in the OU SCP; +HCP cannot change githubdeploy descriptions. Live apply roles may `UpdateAssumeRolePolicy` only on the matching `githubdeploy-shoc-frontend-new-` role. `DenySecretAccess` still denies Secrets Manager and KMS decrypt; SSM GetParameter/GetParameters/GetParametersByPath are denied except `/shoc-frontend-new//deploy/*`, which plan and apply diff --git a/lib/terraform-substrate/shoc-frontend-resources.ts b/lib/terraform-substrate/shoc-frontend-resources.ts index 8fca5ac..980edf8 100644 --- a/lib/terraform-substrate/shoc-frontend-resources.ts +++ b/lib/terraform-substrate/shoc-frontend-resources.ts @@ -741,6 +741,14 @@ export class ShocFrontendResources extends Construct { wrapDistributionStatement(readDistributionStatement), wrapDistributionStatement(invalidationStatement), ); + if (isLiveFrontendEnvironment(environment)) { + boundaryStatements.push({ + Sid: "ReadDeployParams", + Effect: "Allow", + Action: ["ssm:GetParameter", "ssm:GetParameters"], + Resource: deployParameterArn(environment), + }); + } const deployBoundary = new iam.CfnManagedPolicy( this,