diff --git a/.github/workflows/deploy.yaml b/.github/workflows/deploy.yaml index 7c14f45..7588331 100644 --- a/.github/workflows/deploy.yaml +++ b/.github/workflows/deploy.yaml @@ -56,10 +56,8 @@ jobs: uses: Sea-Haven-Industries/.github/.github/workflows/cd-cdk.yaml@e5691d8a7f96ac4d5a841a82975ff0a4354d53ac # v1.0.7 with: node-version: "24" - # seahaven-site-hcptf stays off this list until `cdk import` adopts the - # live roles. A create fails, and a failed create blocks the import. - # Add the id here in the change that follows a successful import. - stacks: "prod-baseline dynamodb-cmk-prod alarm-topic-prod deploy-substrate-prod terraform-substrate-prod app-web-acl-prod" + # seahaven-site-hcptf was imported after the roles left terraform-substrate. + stacks: "prod-baseline dynamodb-cmk-prod alarm-topic-prod deploy-substrate-prod terraform-substrate-prod app-web-acl-prod seahaven-site-hcptf" stack-name: "seahaven-prod-baseline" secrets: deploy-role-arn: ${{ secrets.AWS_DEPLOY_ROLE_ARN_PROD }} diff --git a/lib/seahaven-site-hcptf-stack.ts b/lib/seahaven-site-hcptf-stack.ts index a3b44af..8126a3a 100644 --- a/lib/seahaven-site-hcptf-stack.ts +++ b/lib/seahaven-site-hcptf-stack.ts @@ -459,6 +459,14 @@ function planPolicy( Action: ["ssm:GetParameter", "ssm:GetParameters", "ssm:ListTagsForResource"], Resource: [wafParam, deployParams], }, + { + // DescribeParameters accepts only Resource "*". The AWS provider + // calls it while refreshing aws_ssm_parameter. + Sid: "DescribeParameters", + Effect: "Allow", + Action: "ssm:DescribeParameters", + Resource: "*", + }, { Sid: "RefreshWafWebAcl", Effect: "Allow",