ci(iam): fail when Access Analyzer credentials are missing (PLAT-234)

The policy-check role trust now matches pull request and merge queue
subjects. A failed assume must fail the job instead of skipping
ValidatePolicy and CheckNoNewAccess.

Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com>
This commit is contained in:
Cursor Agent 2026-09-28 18:30:43 +00:00
parent ac65a23d9f
commit c8cf533c66
No known key found for this signature in database

View file

@ -43,16 +43,10 @@ jobs:
(cd /tmp/iam-base && npx cdk synth org-governance -o /tmp/iam-base-out --quiet)
- name: Configure AWS credentials
id: aws-creds
continue-on-error: true
uses: aws-actions/configure-aws-credentials@e1253824e5c10ff9df46874f81ed3ec929e19cfd # v6.3.0
with:
role-to-assume: arn:aws:iam::328440206208:role/githubdeploy-seahaven-org-baseline-policy-check
aws-region: us-east-1 # pragma: allowlist secret
- name: Note skipped analyzer credentials
if: steps.aws-creds.outcome != 'success'
run: echo "::warning title=Access Analyzer skipped::OIDC assume-role did not succeed, so ValidatePolicy and CheckNoNewAccess did not run. The skip stays until githubdeploy-seahaven-org-baseline-policy-check is deployed."
- name: Check IAM policies
run: python3 scripts/check_iam_policies.py --cdk-out cdk.out --base-cdk-out /tmp/iam-base-out --base-repo /tmp/iam-base --self-test