mirror of
https://github.com/Sea-Haven-Industries/seahaven-org-baseline.git
synced 2026-09-30 04:33:15 +00:00
chore(terraform-substrate): forget deleted openswe traces roles (PLAT-147) (#163)
The IAM roles are already gone. Removing the logical IDs while DeletionPolicy stays Retain lets CloudFormation drop them without updating missing roles.
This commit is contained in:
parent
faa199771f
commit
cc068f3c8d
1 changed files with 5 additions and 221 deletions
|
|
@ -75,9 +75,11 @@ Description: >-
|
|||
#
|
||||
# PER-WORKSPACE ROLE ACCUMULATOR — CLOSED FOR PROD/DEV
|
||||
# Do not append new hcptf-<stack> pairs for prod or dev. App Terraform owns
|
||||
# those roles (PLAT-144/PLAT-146). The eight existing prod pairs stay here
|
||||
# with DeletionPolicy: Retain until each is imported, then a Retain-remove
|
||||
# update forgets them, then the prod/dev stacks delete (PLAT-147). External-dev
|
||||
# those roles (PLAT-144/PLAT-146). Six prod pairs stay here with
|
||||
# DeletionPolicy: Retain until the Retain-remove, then the prod/dev stacks
|
||||
# delete (PLAT-147). hcptf-sh-openswe-traces and -plan are omitted: the IAM
|
||||
# roles are already gone (PLAT-196), so this update forgets the logical IDs.
|
||||
# seahaven-site lives in seahaven-site-hcptf. External-dev
|
||||
# SHOC roles below remain in this template (PLAT-148). All remaining subs are
|
||||
# exact StringEquals (never StringLike, never a wildcarded run_phase).
|
||||
#
|
||||
|
|
@ -970,224 +972,6 @@ Resources:
|
|||
- dynamodb:ListTables
|
||||
Resource: "*"
|
||||
|
||||
# ---------------------------------------------------------------------------
|
||||
# Per-workspace hcptf-* roles for sh-openswe-traces-prod (PLAT-73).
|
||||
#
|
||||
# Storage / IAM-user stack — NOT Lambda/EventBridge. Deviations from the
|
||||
# Lambda apply-role pattern (documented on PLAT-73):
|
||||
# - No seahaven-lambda-execution-boundary widen (no Lambda exec roles).
|
||||
# - No lambda:*/events:*/artifact-bucket statements.
|
||||
# - Explicit IAM user CRUD (seahaven-hcptf-iam-management is role-path-only).
|
||||
# - Stack-scoped s3:* on account-suffixed data + log buckets.
|
||||
# - KMS manage for alias/sh-openswe-traces CMK.
|
||||
# - Secrets Manager shell lifecycle on exact secret name (no Get/Put value).
|
||||
# ---------------------------------------------------------------------------
|
||||
HcptfShOpensweTracesPlanRole:
|
||||
Type: AWS::IAM::Role
|
||||
Condition: IsProdAccount
|
||||
DeletionPolicy: Retain
|
||||
UpdateReplacePolicy: Retain
|
||||
Properties:
|
||||
RoleName: hcptf-sh-openswe-traces-plan
|
||||
AssumeRolePolicyDocument:
|
||||
Version: "2012-10-17"
|
||||
Statement:
|
||||
- Effect: Allow
|
||||
Principal:
|
||||
Federated: !Sub "arn:aws:iam::${AWS::AccountId}:oidc-provider/app.terraform.io"
|
||||
Action: sts:AssumeRoleWithWebIdentity
|
||||
Condition:
|
||||
StringEquals:
|
||||
"app.terraform.io:aud": aws.workload.identity
|
||||
"app.terraform.io:sub": organization:seahaven:project:seahaven-prod:workspace:sh-openswe-traces-prod:run_phase:plan
|
||||
ManagedPolicyArns:
|
||||
- arn:aws:iam::aws:policy/job-function/ViewOnlyAccess
|
||||
Policies:
|
||||
- PolicyName: sh-openswe-traces-plan-refresh
|
||||
PolicyDocument:
|
||||
Version: "2012-10-17"
|
||||
Statement:
|
||||
- Sid: RefreshIamUser
|
||||
Effect: Allow
|
||||
Action:
|
||||
- iam:GetUser
|
||||
- iam:GetUserPolicy
|
||||
- iam:ListUserPolicies
|
||||
- iam:ListAttachedUserPolicies
|
||||
- iam:ListUserTags
|
||||
- iam:GetAccessKeyLastUsed
|
||||
- iam:ListAccessKeys
|
||||
Resource:
|
||||
- !Sub "arn:aws:iam::${AWS::AccountId}:user/sh-openswe-langsmith-export"
|
||||
- Sid: RefreshManagedPolicies
|
||||
Effect: Allow
|
||||
Action:
|
||||
- iam:GetPolicy
|
||||
- iam:GetPolicyVersion
|
||||
Resource: "*"
|
||||
- Sid: RefreshBuckets
|
||||
Effect: Allow
|
||||
Action:
|
||||
- s3:Get*
|
||||
- s3:ListBucket
|
||||
Resource:
|
||||
- !Sub "arn:aws:s3:::sh-openswe-traces-${AWS::AccountId}"
|
||||
- !Sub "arn:aws:s3:::sh-openswe-traces-${AWS::AccountId}/*"
|
||||
- !Sub "arn:aws:s3:::sh-openswe-traces-logs-${AWS::AccountId}"
|
||||
- !Sub "arn:aws:s3:::sh-openswe-traces-logs-${AWS::AccountId}/*"
|
||||
- Sid: RefreshKms
|
||||
Effect: Allow
|
||||
Action:
|
||||
- kms:Describe*
|
||||
- kms:GetKeyPolicy
|
||||
- kms:GetKeyRotationStatus
|
||||
- kms:ListResourceTags
|
||||
- kms:ListAliases
|
||||
Resource: "*"
|
||||
- Sid: RefreshSecret
|
||||
Effect: Allow
|
||||
Action:
|
||||
- secretsmanager:DescribeSecret
|
||||
- secretsmanager:GetResourcePolicy
|
||||
- secretsmanager:ListSecretVersionIds
|
||||
Resource:
|
||||
- !Sub "arn:aws:secretsmanager:us-east-1:${AWS::AccountId}:secret:sh-openswe/langsmith-export-s3-*"
|
||||
|
||||
HcptfShOpensweTracesApplyRole:
|
||||
Type: AWS::IAM::Role
|
||||
Condition: IsProdAccount
|
||||
DeletionPolicy: Retain
|
||||
UpdateReplacePolicy: Retain
|
||||
Properties:
|
||||
RoleName: hcptf-sh-openswe-traces
|
||||
AssumeRolePolicyDocument:
|
||||
Version: "2012-10-17"
|
||||
Statement:
|
||||
- Effect: Allow
|
||||
Principal:
|
||||
Federated: !Sub "arn:aws:iam::${AWS::AccountId}:oidc-provider/app.terraform.io"
|
||||
Action: sts:AssumeRoleWithWebIdentity
|
||||
Condition:
|
||||
StringEquals:
|
||||
"app.terraform.io:aud": aws.workload.identity
|
||||
"app.terraform.io:sub": organization:seahaven:project:seahaven-prod:workspace:sh-openswe-traces-prod:run_phase:apply
|
||||
ManagedPolicyArns:
|
||||
- !Ref HcptfIamManagementPolicy
|
||||
Policies:
|
||||
- PolicyName: sh-openswe-traces-services
|
||||
PolicyDocument:
|
||||
Version: "2012-10-17"
|
||||
Statement:
|
||||
- Sid: TracesBuckets
|
||||
Effect: Allow
|
||||
Action:
|
||||
- s3:*
|
||||
Resource:
|
||||
- !Sub "arn:aws:s3:::sh-openswe-traces-${AWS::AccountId}"
|
||||
- !Sub "arn:aws:s3:::sh-openswe-traces-${AWS::AccountId}/*"
|
||||
- !Sub "arn:aws:s3:::sh-openswe-traces-logs-${AWS::AccountId}"
|
||||
- !Sub "arn:aws:s3:::sh-openswe-traces-logs-${AWS::AccountId}/*"
|
||||
# CreateKey is account-level; pin via RequestTag matching the
|
||||
# app provider default_tags (Project=sh-openswe-traces). Key
|
||||
# admin after create requires the same ResourceTag — no
|
||||
# unconstrained PutKeyPolicy/DisableKey on unrelated CMKs.
|
||||
- Sid: TracesKmsCreate
|
||||
Effect: Allow
|
||||
Action:
|
||||
- kms:CreateKey
|
||||
Resource: "*"
|
||||
Condition:
|
||||
StringEquals:
|
||||
"aws:RequestTag/Project": sh-openswe-traces
|
||||
- Sid: TracesKmsList
|
||||
Effect: Allow
|
||||
Action:
|
||||
- kms:ListAliases
|
||||
Resource: "*"
|
||||
- Sid: TracesKmsAlias
|
||||
Effect: Allow
|
||||
Action:
|
||||
- kms:CreateAlias
|
||||
- kms:UpdateAlias
|
||||
- kms:DeleteAlias
|
||||
Resource:
|
||||
- !Sub "arn:aws:kms:us-east-1:${AWS::AccountId}:alias/sh-openswe-traces"
|
||||
- Sid: TracesKmsKey
|
||||
Effect: Allow
|
||||
Action:
|
||||
- kms:TagResource
|
||||
- kms:UntagResource
|
||||
- kms:ScheduleKeyDeletion
|
||||
- kms:CancelKeyDeletion
|
||||
- kms:EnableKeyRotation
|
||||
- kms:DisableKeyRotation
|
||||
- kms:PutKeyPolicy
|
||||
- kms:DescribeKey
|
||||
- kms:GetKeyPolicy
|
||||
- kms:GetKeyRotationStatus
|
||||
- kms:ListResourceTags
|
||||
- kms:EnableKey
|
||||
- kms:DisableKey
|
||||
# Alias attach/detach also authorizes against the key ARN.
|
||||
- kms:CreateAlias
|
||||
- kms:UpdateAlias
|
||||
- kms:DeleteAlias
|
||||
Resource: "*"
|
||||
Condition:
|
||||
StringEquals:
|
||||
"aws:ResourceTag/Project": sh-openswe-traces
|
||||
- Sid: ExportIamUser
|
||||
Effect: Allow
|
||||
Action:
|
||||
- iam:CreateUser
|
||||
- iam:DeleteUser
|
||||
- iam:GetUser
|
||||
- iam:TagUser
|
||||
- iam:UntagUser
|
||||
- iam:UpdateUser
|
||||
- iam:PutUserPolicy
|
||||
- iam:DeleteUserPolicy
|
||||
- iam:GetUserPolicy
|
||||
- iam:ListUserPolicies
|
||||
- iam:ListAttachedUserPolicies
|
||||
- iam:ListUserTags
|
||||
- iam:ListAccessKeys
|
||||
Resource:
|
||||
- !Sub "arn:aws:iam::${AWS::AccountId}:user/sh-openswe-langsmith-export"
|
||||
# CreateUser is authorized against the user ARN that will exist;
|
||||
# ListUsers is a collection action on "*".
|
||||
- Sid: ExportIamUserList
|
||||
Effect: Allow
|
||||
Action:
|
||||
- iam:ListUsers
|
||||
- iam:GetAccountSummary
|
||||
Resource: "*"
|
||||
# Shell lifecycle only — no GetSecretValue / PutSecretValue /
|
||||
# UpdateSecret so apply never renders or overwrites key material
|
||||
# in HCP state or run logs. CreateSecret is only on
|
||||
# ExportSecretCreate with an exact Name pin (not this ARN
|
||||
# prefix, which would also match longer secret names).
|
||||
- Sid: ExportSecretShell
|
||||
Effect: Allow
|
||||
Action:
|
||||
- secretsmanager:DeleteSecret
|
||||
- secretsmanager:DescribeSecret
|
||||
- secretsmanager:GetResourcePolicy
|
||||
- secretsmanager:PutResourcePolicy
|
||||
- secretsmanager:DeleteResourcePolicy
|
||||
- secretsmanager:TagResource
|
||||
- secretsmanager:UntagResource
|
||||
Resource:
|
||||
- !Sub "arn:aws:secretsmanager:us-east-1:${AWS::AccountId}:secret:sh-openswe/langsmith-export-s3-*"
|
||||
- Sid: ExportSecretCreate
|
||||
Effect: Allow
|
||||
Action:
|
||||
- secretsmanager:CreateSecret
|
||||
Resource: "*"
|
||||
Condition:
|
||||
StringEquals:
|
||||
"secretsmanager:Name": sh-openswe/langsmith-export-s3
|
||||
|
||||
# ---------------------------------------------------------------------------
|
||||
# procurement-ingest (PLAT-86) — plan + apply roles for workspace
|
||||
# procurement-ingest-prod. Import-in-place of three former CDK stacks
|
||||
|
|
|
|||
Loading…
Add table
Reference in a new issue