fix(iam): let the site plan role describe SSM parameters

This commit is contained in:
Adam Moussa 2026-09-25 12:18:31 -04:00
parent 38ed1bfe00
commit ce6b59b552
No known key found for this signature in database
2 changed files with 10 additions and 4 deletions

View file

@ -56,10 +56,8 @@ jobs:
uses: Sea-Haven-Industries/.github/.github/workflows/cd-cdk.yaml@e5691d8a7f96ac4d5a841a82975ff0a4354d53ac # v1.0.7
with:
node-version: "24"
# seahaven-site-hcptf stays off this list until `cdk import` adopts the
# live roles. A create fails, and a failed create blocks the import.
# Add the id here in the change that follows a successful import.
stacks: "prod-baseline dynamodb-cmk-prod alarm-topic-prod deploy-substrate-prod terraform-substrate-prod app-web-acl-prod"
# seahaven-site-hcptf was imported after the roles left terraform-substrate.
stacks: "prod-baseline dynamodb-cmk-prod alarm-topic-prod deploy-substrate-prod terraform-substrate-prod app-web-acl-prod seahaven-site-hcptf"
stack-name: "seahaven-prod-baseline"
secrets:
deploy-role-arn: ${{ secrets.AWS_DEPLOY_ROLE_ARN_PROD }}

View file

@ -459,6 +459,14 @@ function planPolicy(
Action: ["ssm:GetParameter", "ssm:GetParameters", "ssm:ListTagsForResource"],
Resource: [wafParam, deployParams],
},
{
// DescribeParameters accepts only Resource "*". The AWS provider
// calls it while refreshing aws_ssm_parameter.
Sid: "DescribeParameters",
Effect: "Allow",
Action: "ssm:DescribeParameters",
Resource: "*",
},
{
Sid: "RefreshWafWebAcl",
Effect: "Allow",