mirror of
https://github.com/Sea-Haven-Industries/seahaven-org-baseline.git
synced 2026-10-04 14:51:58 +00:00
feat(iam): allow frontend tf-poc HCP apply destroy (PLAT-193)
This commit is contained in:
parent
3c54df6341
commit
d4232ba045
2 changed files with 97 additions and 22 deletions
11
README.md
11
README.md
|
|
@ -457,9 +457,14 @@ job:
|
||||||
a false gate as rollback after CloudFormation owns a role.
|
a false gate as rollback after CloudFormation owns a role.
|
||||||
|
|
||||||
The apply roles explicitly deny role lifecycle/trust/boundary/managed-policy
|
The apply roles explicitly deny role lifecycle/trust/boundary/managed-policy
|
||||||
changes, `PassRole`, secret and parameter reads, CloudFront/S3 create and
|
changes, `PassRole`, secret and parameter reads, CloudFront/S3 create, and
|
||||||
delete (including OAC mutation), and deletion of inline role or bucket
|
(for dev and staging) CloudFront/S3 delete including OAC mutation and bucket
|
||||||
policies. `UpdateDistribution` is allowed on the exact pinned distribution ARN.
|
policy deletion. The tf-poc apply role is the exception: it keeps create
|
||||||
|
denied and allows destroy of the exact rehearsal bucket (including object
|
||||||
|
versions), distribution `E73KH1SPNFL00`, OAC `E14MP8Z5YRWO93`, function
|
||||||
|
`us-east-1shocfrontendtfpocSpaRewrite4B1A4F5F`, and A/AAAA in
|
||||||
|
`Z10433621DH3UOWM8663D`. It still does not delete `githubdeploy-*`; SCP
|
||||||
|
`ProtectDeploymentPrincipalLifecycle` denies that for HCP principals. `UpdateDistribution` is allowed on the exact pinned distribution ARN.
|
||||||
`CreateInvalidation` and `GetInvalidation` are allowed on that same ARN so the
|
`CreateInvalidation` and `GetInvalidation` are allowed on that same ARN so the
|
||||||
Terraform invalidation action can run. `GetObject`/`GetObjectTagging`/`PutObject`/`PutObjectTagging` on
|
Terraform invalidation action can run. `GetObject`/`GetObjectTagging`/`PutObject`/`PutObjectTagging` on
|
||||||
`.release/current` lets Terraform own the release pointer, including the
|
`.release/current` lets Terraform own the release pointer, including the
|
||||||
|
|
|
||||||
|
|
@ -230,6 +230,93 @@ const frontendReadPolicy = (
|
||||||
};
|
};
|
||||||
};
|
};
|
||||||
|
|
||||||
|
const infrastructureReplacementDenyActions = (
|
||||||
|
environment: FrontendEnvironment,
|
||||||
|
): string[] => {
|
||||||
|
const createOnly = [
|
||||||
|
"cloudfront:CreateDistribution",
|
||||||
|
"cloudfront:CreateFunction",
|
||||||
|
"cloudfront:CreateOriginAccessControl",
|
||||||
|
"s3:CreateBucket",
|
||||||
|
];
|
||||||
|
if (environment.key === "tf-poc") {
|
||||||
|
// Destroy needs Delete* and the Put/Delete calls Terraform uses to
|
||||||
|
// remove versioning, encryption, ownership, and public-access configs.
|
||||||
|
return createOnly;
|
||||||
|
}
|
||||||
|
return [
|
||||||
|
...createOnly,
|
||||||
|
"cloudfront:DeleteDistribution",
|
||||||
|
"cloudfront:DeleteFunction",
|
||||||
|
"cloudfront:DeleteOriginAccessControl",
|
||||||
|
"cloudfront:UpdateOriginAccessControl",
|
||||||
|
"s3:DeleteBucket",
|
||||||
|
"s3:DeleteBucketEncryption",
|
||||||
|
"s3:DeleteBucketOwnershipControls",
|
||||||
|
"s3:DeleteBucketPolicy",
|
||||||
|
"s3:DeleteBucketPublicAccessBlock",
|
||||||
|
"s3:PutBucketOwnershipControls",
|
||||||
|
"s3:PutBucketPublicAccessBlock",
|
||||||
|
"s3:PutBucketVersioning",
|
||||||
|
"s3:PutEncryptionConfiguration",
|
||||||
|
];
|
||||||
|
};
|
||||||
|
|
||||||
|
const frontendPocDestroyStatements = (
|
||||||
|
environment: FrontendEnvironment,
|
||||||
|
): Record<string, unknown>[] => {
|
||||||
|
if (environment.key !== "tf-poc") {
|
||||||
|
return [];
|
||||||
|
}
|
||||||
|
const siteBucketArn = bucketArn(environment.bucketName);
|
||||||
|
return [
|
||||||
|
{
|
||||||
|
Sid: "DestroyExactPocBucket",
|
||||||
|
Effect: "Allow",
|
||||||
|
Action: [
|
||||||
|
"s3:DeleteBucket",
|
||||||
|
"s3:DeleteBucketEncryption",
|
||||||
|
"s3:DeleteBucketOwnershipControls",
|
||||||
|
"s3:DeleteBucketPolicy",
|
||||||
|
"s3:DeleteBucketPublicAccessBlock",
|
||||||
|
"s3:GetBucketVersioning",
|
||||||
|
"s3:ListBucket",
|
||||||
|
"s3:ListBucketVersions",
|
||||||
|
"s3:PutBucketOwnershipControls",
|
||||||
|
"s3:PutBucketPublicAccessBlock",
|
||||||
|
"s3:PutBucketVersioning",
|
||||||
|
"s3:PutEncryptionConfiguration",
|
||||||
|
],
|
||||||
|
Resource: siteBucketArn,
|
||||||
|
},
|
||||||
|
{
|
||||||
|
Sid: "DestroyExactPocBucketObjects",
|
||||||
|
Effect: "Allow",
|
||||||
|
Action: [
|
||||||
|
"s3:DeleteObject",
|
||||||
|
"s3:DeleteObjectVersion",
|
||||||
|
"s3:GetObject",
|
||||||
|
"s3:GetObjectVersion",
|
||||||
|
],
|
||||||
|
Resource: `${siteBucketArn}/*`,
|
||||||
|
},
|
||||||
|
{
|
||||||
|
Sid: "DestroyExactPocCloudFront",
|
||||||
|
Effect: "Allow",
|
||||||
|
Action: [
|
||||||
|
"cloudfront:DeleteDistribution",
|
||||||
|
"cloudfront:DeleteFunction",
|
||||||
|
"cloudfront:DeleteOriginAccessControl",
|
||||||
|
],
|
||||||
|
Resource: [
|
||||||
|
distributionArn(environment.distributionId),
|
||||||
|
functionArn(environment.functionName),
|
||||||
|
originAccessControlArn(environment.originAccessControlId),
|
||||||
|
],
|
||||||
|
},
|
||||||
|
];
|
||||||
|
};
|
||||||
|
|
||||||
const frontendApplyPolicy = (
|
const frontendApplyPolicy = (
|
||||||
environment: FrontendEnvironment,
|
environment: FrontendEnvironment,
|
||||||
): Record<string, unknown> => ({
|
): Record<string, unknown> => ({
|
||||||
|
|
@ -269,25 +356,7 @@ const frontendApplyPolicy = (
|
||||||
{
|
{
|
||||||
Sid: "DenyInfrastructureReplacement",
|
Sid: "DenyInfrastructureReplacement",
|
||||||
Effect: "Deny",
|
Effect: "Deny",
|
||||||
Action: [
|
Action: infrastructureReplacementDenyActions(environment),
|
||||||
"cloudfront:CreateDistribution",
|
|
||||||
"cloudfront:CreateFunction",
|
|
||||||
"cloudfront:CreateOriginAccessControl",
|
|
||||||
"cloudfront:DeleteDistribution",
|
|
||||||
"cloudfront:DeleteFunction",
|
|
||||||
"cloudfront:DeleteOriginAccessControl",
|
|
||||||
"cloudfront:UpdateOriginAccessControl",
|
|
||||||
"s3:CreateBucket",
|
|
||||||
"s3:DeleteBucket",
|
|
||||||
"s3:DeleteBucketEncryption",
|
|
||||||
"s3:DeleteBucketOwnershipControls",
|
|
||||||
"s3:DeleteBucketPolicy",
|
|
||||||
"s3:DeleteBucketPublicAccessBlock",
|
|
||||||
"s3:PutBucketOwnershipControls",
|
|
||||||
"s3:PutBucketPublicAccessBlock",
|
|
||||||
"s3:PutBucketVersioning",
|
|
||||||
"s3:PutEncryptionConfiguration",
|
|
||||||
],
|
|
||||||
Resource: "*",
|
Resource: "*",
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
|
|
@ -403,6 +472,7 @@ const frontendApplyPolicy = (
|
||||||
},
|
},
|
||||||
},
|
},
|
||||||
},
|
},
|
||||||
|
...frontendPocDestroyStatements(environment),
|
||||||
],
|
],
|
||||||
});
|
});
|
||||||
|
|
||||||
|
|
|
||||||
Loading…
Add table
Reference in a new issue