From cc068f3c8d935366be82cf8c58a3947c2138424a Mon Sep 17 00:00:00 2001 From: Adam Moussa <166072409+amoussa1229@users.noreply.github.com> Date: Mon, 28 Sep 2026 19:30:14 +0000 Subject: [PATCH] chore(terraform-substrate): forget deleted openswe traces roles (PLAT-147) (#163) The IAM roles are already gone. Removing the logical IDs while DeletionPolicy stays Retain lets CloudFormation drop them without updating missing roles. --- .../terraform-substrate.template.yaml | 226 +----------------- 1 file changed, 5 insertions(+), 221 deletions(-) diff --git a/lib/terraform-substrate/terraform-substrate.template.yaml b/lib/terraform-substrate/terraform-substrate.template.yaml index f67ecc7..4c7ccbb 100644 --- a/lib/terraform-substrate/terraform-substrate.template.yaml +++ b/lib/terraform-substrate/terraform-substrate.template.yaml @@ -75,9 +75,11 @@ Description: >- # # PER-WORKSPACE ROLE ACCUMULATOR — CLOSED FOR PROD/DEV # Do not append new hcptf- pairs for prod or dev. App Terraform owns -# those roles (PLAT-144/PLAT-146). The eight existing prod pairs stay here -# with DeletionPolicy: Retain until each is imported, then a Retain-remove -# update forgets them, then the prod/dev stacks delete (PLAT-147). External-dev +# those roles (PLAT-144/PLAT-146). Six prod pairs stay here with +# DeletionPolicy: Retain until the Retain-remove, then the prod/dev stacks +# delete (PLAT-147). hcptf-sh-openswe-traces and -plan are omitted: the IAM +# roles are already gone (PLAT-196), so this update forgets the logical IDs. +# seahaven-site lives in seahaven-site-hcptf. External-dev # SHOC roles below remain in this template (PLAT-148). All remaining subs are # exact StringEquals (never StringLike, never a wildcarded run_phase). # @@ -970,224 +972,6 @@ Resources: - dynamodb:ListTables Resource: "*" - # --------------------------------------------------------------------------- - # Per-workspace hcptf-* roles for sh-openswe-traces-prod (PLAT-73). - # - # Storage / IAM-user stack — NOT Lambda/EventBridge. Deviations from the - # Lambda apply-role pattern (documented on PLAT-73): - # - No seahaven-lambda-execution-boundary widen (no Lambda exec roles). - # - No lambda:*/events:*/artifact-bucket statements. - # - Explicit IAM user CRUD (seahaven-hcptf-iam-management is role-path-only). - # - Stack-scoped s3:* on account-suffixed data + log buckets. - # - KMS manage for alias/sh-openswe-traces CMK. - # - Secrets Manager shell lifecycle on exact secret name (no Get/Put value). - # --------------------------------------------------------------------------- - HcptfShOpensweTracesPlanRole: - Type: AWS::IAM::Role - Condition: IsProdAccount - DeletionPolicy: Retain - UpdateReplacePolicy: Retain - Properties: - RoleName: hcptf-sh-openswe-traces-plan - AssumeRolePolicyDocument: - Version: "2012-10-17" - Statement: - - Effect: Allow - Principal: - Federated: !Sub "arn:aws:iam::${AWS::AccountId}:oidc-provider/app.terraform.io" - Action: sts:AssumeRoleWithWebIdentity - Condition: - StringEquals: - "app.terraform.io:aud": aws.workload.identity - "app.terraform.io:sub": organization:seahaven:project:seahaven-prod:workspace:sh-openswe-traces-prod:run_phase:plan - ManagedPolicyArns: - - arn:aws:iam::aws:policy/job-function/ViewOnlyAccess - Policies: - - PolicyName: sh-openswe-traces-plan-refresh - PolicyDocument: - Version: "2012-10-17" - Statement: - - Sid: RefreshIamUser - Effect: Allow - Action: - - iam:GetUser - - iam:GetUserPolicy - - iam:ListUserPolicies - - iam:ListAttachedUserPolicies - - iam:ListUserTags - - iam:GetAccessKeyLastUsed - - iam:ListAccessKeys - Resource: - - !Sub "arn:aws:iam::${AWS::AccountId}:user/sh-openswe-langsmith-export" - - Sid: RefreshManagedPolicies - Effect: Allow - Action: - - iam:GetPolicy - - iam:GetPolicyVersion - Resource: "*" - - Sid: RefreshBuckets - Effect: Allow - Action: - - s3:Get* - - s3:ListBucket - Resource: - - !Sub "arn:aws:s3:::sh-openswe-traces-${AWS::AccountId}" - - !Sub "arn:aws:s3:::sh-openswe-traces-${AWS::AccountId}/*" - - !Sub "arn:aws:s3:::sh-openswe-traces-logs-${AWS::AccountId}" - - !Sub "arn:aws:s3:::sh-openswe-traces-logs-${AWS::AccountId}/*" - - Sid: RefreshKms - Effect: Allow - Action: - - kms:Describe* - - kms:GetKeyPolicy - - kms:GetKeyRotationStatus - - kms:ListResourceTags - - kms:ListAliases - Resource: "*" - - Sid: RefreshSecret - Effect: Allow - Action: - - secretsmanager:DescribeSecret - - secretsmanager:GetResourcePolicy - - secretsmanager:ListSecretVersionIds - Resource: - - !Sub "arn:aws:secretsmanager:us-east-1:${AWS::AccountId}:secret:sh-openswe/langsmith-export-s3-*" - - HcptfShOpensweTracesApplyRole: - Type: AWS::IAM::Role - Condition: IsProdAccount - DeletionPolicy: Retain - UpdateReplacePolicy: Retain - Properties: - RoleName: hcptf-sh-openswe-traces - AssumeRolePolicyDocument: - Version: "2012-10-17" - Statement: - - Effect: Allow - Principal: - Federated: !Sub "arn:aws:iam::${AWS::AccountId}:oidc-provider/app.terraform.io" - Action: sts:AssumeRoleWithWebIdentity - Condition: - StringEquals: - "app.terraform.io:aud": aws.workload.identity - "app.terraform.io:sub": organization:seahaven:project:seahaven-prod:workspace:sh-openswe-traces-prod:run_phase:apply - ManagedPolicyArns: - - !Ref HcptfIamManagementPolicy - Policies: - - PolicyName: sh-openswe-traces-services - PolicyDocument: - Version: "2012-10-17" - Statement: - - Sid: TracesBuckets - Effect: Allow - Action: - - s3:* - Resource: - - !Sub "arn:aws:s3:::sh-openswe-traces-${AWS::AccountId}" - - !Sub "arn:aws:s3:::sh-openswe-traces-${AWS::AccountId}/*" - - !Sub "arn:aws:s3:::sh-openswe-traces-logs-${AWS::AccountId}" - - !Sub "arn:aws:s3:::sh-openswe-traces-logs-${AWS::AccountId}/*" - # CreateKey is account-level; pin via RequestTag matching the - # app provider default_tags (Project=sh-openswe-traces). Key - # admin after create requires the same ResourceTag — no - # unconstrained PutKeyPolicy/DisableKey on unrelated CMKs. - - Sid: TracesKmsCreate - Effect: Allow - Action: - - kms:CreateKey - Resource: "*" - Condition: - StringEquals: - "aws:RequestTag/Project": sh-openswe-traces - - Sid: TracesKmsList - Effect: Allow - Action: - - kms:ListAliases - Resource: "*" - - Sid: TracesKmsAlias - Effect: Allow - Action: - - kms:CreateAlias - - kms:UpdateAlias - - kms:DeleteAlias - Resource: - - !Sub "arn:aws:kms:us-east-1:${AWS::AccountId}:alias/sh-openswe-traces" - - Sid: TracesKmsKey - Effect: Allow - Action: - - kms:TagResource - - kms:UntagResource - - kms:ScheduleKeyDeletion - - kms:CancelKeyDeletion - - kms:EnableKeyRotation - - kms:DisableKeyRotation - - kms:PutKeyPolicy - - kms:DescribeKey - - kms:GetKeyPolicy - - kms:GetKeyRotationStatus - - kms:ListResourceTags - - kms:EnableKey - - kms:DisableKey - # Alias attach/detach also authorizes against the key ARN. - - kms:CreateAlias - - kms:UpdateAlias - - kms:DeleteAlias - Resource: "*" - Condition: - StringEquals: - "aws:ResourceTag/Project": sh-openswe-traces - - Sid: ExportIamUser - Effect: Allow - Action: - - iam:CreateUser - - iam:DeleteUser - - iam:GetUser - - iam:TagUser - - iam:UntagUser - - iam:UpdateUser - - iam:PutUserPolicy - - iam:DeleteUserPolicy - - iam:GetUserPolicy - - iam:ListUserPolicies - - iam:ListAttachedUserPolicies - - iam:ListUserTags - - iam:ListAccessKeys - Resource: - - !Sub "arn:aws:iam::${AWS::AccountId}:user/sh-openswe-langsmith-export" - # CreateUser is authorized against the user ARN that will exist; - # ListUsers is a collection action on "*". - - Sid: ExportIamUserList - Effect: Allow - Action: - - iam:ListUsers - - iam:GetAccountSummary - Resource: "*" - # Shell lifecycle only — no GetSecretValue / PutSecretValue / - # UpdateSecret so apply never renders or overwrites key material - # in HCP state or run logs. CreateSecret is only on - # ExportSecretCreate with an exact Name pin (not this ARN - # prefix, which would also match longer secret names). - - Sid: ExportSecretShell - Effect: Allow - Action: - - secretsmanager:DeleteSecret - - secretsmanager:DescribeSecret - - secretsmanager:GetResourcePolicy - - secretsmanager:PutResourcePolicy - - secretsmanager:DeleteResourcePolicy - - secretsmanager:TagResource - - secretsmanager:UntagResource - Resource: - - !Sub "arn:aws:secretsmanager:us-east-1:${AWS::AccountId}:secret:sh-openswe/langsmith-export-s3-*" - - Sid: ExportSecretCreate - Effect: Allow - Action: - - secretsmanager:CreateSecret - Resource: "*" - Condition: - StringEquals: - "secretsmanager:Name": sh-openswe/langsmith-export-s3 - # --------------------------------------------------------------------------- # procurement-ingest (PLAT-86) — plan + apply roles for workspace # procurement-ingest-prod. Import-in-place of three former CDK stacks