diff --git a/lib/org-governance-stack.ts b/lib/org-governance-stack.ts index c897b1b..ce4dc9a 100644 --- a/lib/org-governance-stack.ts +++ b/lib/org-governance-stack.ts @@ -260,7 +260,7 @@ export class OrgGovernanceStack extends cdk.Stack { name: "protect-privileged-roles", type: "SERVICE_CONTROL_POLICY", description: - "prod/nonprod: protect break-glass, CDK exec, githubdeploy, and hcptf-bootstrap roles", + "prod/nonprod: protect break-glass, CDK exec, githubdeploy, hcptf-bootstrap, and /platform/ roles", targetIds: [prodOu.attrId, nonprodOu.attrId], content: scpContent("protect-privileged-roles"), }); @@ -338,6 +338,31 @@ export class OrgGovernanceStack extends cdk.Stack { }, }, }, + { + Sid: "ProtectPlatformPath", + Effect: "Deny", + Action: [ + "iam:CreateRole", + "iam:UpdateAssumeRolePolicy", + "iam:AttachRolePolicy", + "iam:DetachRolePolicy", + "iam:PutRolePolicy", + "iam:DeleteRolePolicy", + "iam:DeleteRole", + "iam:UpdateRole", + "iam:TagRole", + "iam:UntagRole", + ], + Resource: "arn:aws:iam::*:role/platform/*", + Condition: { + ArnNotLike: { + "aws:PrincipalArn": [ + "arn:aws:iam::*:role/OrganizationAccountAccessRole", + "arn:aws:iam::*:role/aws-reserved/sso.amazonaws.com/*/AWSReservedSSO_Platform_*", + ], + }, + }, + }, { Sid: "ProtectDelegatedAdminMembership", Effect: "Deny", diff --git a/lib/scp/protect-privileged-roles.json b/lib/scp/protect-privileged-roles.json index 202ec22..1b76198 100644 --- a/lib/scp/protect-privileged-roles.json +++ b/lib/scp/protect-privileged-roles.json @@ -31,6 +31,31 @@ ] } } + }, + { + "Sid": "ProtectPlatformPath", + "Effect": "Deny", + "Action": [ + "iam:CreateRole", + "iam:UpdateAssumeRolePolicy", + "iam:AttachRolePolicy", + "iam:DetachRolePolicy", + "iam:PutRolePolicy", + "iam:DeleteRolePolicy", + "iam:DeleteRole", + "iam:UpdateRole", + "iam:TagRole", + "iam:UntagRole" + ], + "Resource": "arn:aws:iam::*:role/platform/*", + "Condition": { + "ArnNotLike": { + "aws:PrincipalArn": [ + "arn:aws:iam::*:role/OrganizationAccountAccessRole", + "arn:aws:iam::*:role/aws-reserved/sso.amazonaws.com/*/AWSReservedSSO_Platform_*" + ] + } + } } ] } diff --git a/scripts/create-hcptf-bootstrap-roles.sh b/scripts/create-hcptf-bootstrap-roles.sh index 72ed30a..3197d70 100755 --- a/scripts/create-hcptf-bootstrap-roles.sh +++ b/scripts/create-hcptf-bootstrap-roles.sh @@ -239,10 +239,14 @@ create_or_update_role() { aws iam update-assume-role-policy --role-name "$name" --policy-document "file://${trust_file}" fi else - echo " $name: create" + echo " $name: create on /platform/" + # Path is create-only. IAM cannot move an existing role onto /platform/. + # Prod and dev already have hcptf-bootstrap and hcptf-bootstrap-plan, so + # this branch does not run for them. Do not delete and recreate to set a path. if [[ "$DRY_RUN" -eq 0 ]]; then aws iam create-role \ --role-name "$name" \ + --path /platform/ \ --assume-role-policy-document "file://${trust_file}" \ --description "HCP Terraform ${name} (PLAT-145). Console/CLI owned. Manual apply only." \ --tags Key=Project,Value=hcp-bootstrap Key=Owner,Value=adam@seahavenind.com Key=ManagedBy,Value=cli