mirror of
https://github.com/Sea-Haven-Industries/seahaven-org-baseline.git
synced 2026-10-05 15:11:58 +00:00
feat(scp): deny iam changes on role/platform unless the platform principal (PLAT-233)
Adds ProtectPlatformPath beside the existing name denies in the prod/nonprod SCP and the security OU copy. New hcptf-bootstrap creates use /platform/. Existing roles are not recreated. Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com>
This commit is contained in:
parent
d80295c005
commit
e3adfc3cdc
3 changed files with 56 additions and 2 deletions
|
|
@ -260,7 +260,7 @@ export class OrgGovernanceStack extends cdk.Stack {
|
||||||
name: "protect-privileged-roles",
|
name: "protect-privileged-roles",
|
||||||
type: "SERVICE_CONTROL_POLICY",
|
type: "SERVICE_CONTROL_POLICY",
|
||||||
description:
|
description:
|
||||||
"prod/nonprod: protect break-glass, CDK exec, githubdeploy, and hcptf-bootstrap roles",
|
"prod/nonprod: protect break-glass, CDK exec, githubdeploy, hcptf-bootstrap, and /platform/ roles",
|
||||||
targetIds: [prodOu.attrId, nonprodOu.attrId],
|
targetIds: [prodOu.attrId, nonprodOu.attrId],
|
||||||
content: scpContent("protect-privileged-roles"),
|
content: scpContent("protect-privileged-roles"),
|
||||||
});
|
});
|
||||||
|
|
@ -338,6 +338,31 @@ export class OrgGovernanceStack extends cdk.Stack {
|
||||||
},
|
},
|
||||||
},
|
},
|
||||||
},
|
},
|
||||||
|
{
|
||||||
|
Sid: "ProtectPlatformPath",
|
||||||
|
Effect: "Deny",
|
||||||
|
Action: [
|
||||||
|
"iam:CreateRole",
|
||||||
|
"iam:UpdateAssumeRolePolicy",
|
||||||
|
"iam:AttachRolePolicy",
|
||||||
|
"iam:DetachRolePolicy",
|
||||||
|
"iam:PutRolePolicy",
|
||||||
|
"iam:DeleteRolePolicy",
|
||||||
|
"iam:DeleteRole",
|
||||||
|
"iam:UpdateRole",
|
||||||
|
"iam:TagRole",
|
||||||
|
"iam:UntagRole",
|
||||||
|
],
|
||||||
|
Resource: "arn:aws:iam::*:role/platform/*",
|
||||||
|
Condition: {
|
||||||
|
ArnNotLike: {
|
||||||
|
"aws:PrincipalArn": [
|
||||||
|
"arn:aws:iam::*:role/OrganizationAccountAccessRole",
|
||||||
|
"arn:aws:iam::*:role/aws-reserved/sso.amazonaws.com/*/AWSReservedSSO_Platform_*",
|
||||||
|
],
|
||||||
|
},
|
||||||
|
},
|
||||||
|
},
|
||||||
{
|
{
|
||||||
Sid: "ProtectDelegatedAdminMembership",
|
Sid: "ProtectDelegatedAdminMembership",
|
||||||
Effect: "Deny",
|
Effect: "Deny",
|
||||||
|
|
|
||||||
|
|
@ -31,6 +31,31 @@
|
||||||
]
|
]
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"Sid": "ProtectPlatformPath",
|
||||||
|
"Effect": "Deny",
|
||||||
|
"Action": [
|
||||||
|
"iam:CreateRole",
|
||||||
|
"iam:UpdateAssumeRolePolicy",
|
||||||
|
"iam:AttachRolePolicy",
|
||||||
|
"iam:DetachRolePolicy",
|
||||||
|
"iam:PutRolePolicy",
|
||||||
|
"iam:DeleteRolePolicy",
|
||||||
|
"iam:DeleteRole",
|
||||||
|
"iam:UpdateRole",
|
||||||
|
"iam:TagRole",
|
||||||
|
"iam:UntagRole"
|
||||||
|
],
|
||||||
|
"Resource": "arn:aws:iam::*:role/platform/*",
|
||||||
|
"Condition": {
|
||||||
|
"ArnNotLike": {
|
||||||
|
"aws:PrincipalArn": [
|
||||||
|
"arn:aws:iam::*:role/OrganizationAccountAccessRole",
|
||||||
|
"arn:aws:iam::*:role/aws-reserved/sso.amazonaws.com/*/AWSReservedSSO_Platform_*"
|
||||||
|
]
|
||||||
|
}
|
||||||
|
}
|
||||||
}
|
}
|
||||||
]
|
]
|
||||||
}
|
}
|
||||||
|
|
|
||||||
|
|
@ -239,10 +239,14 @@ create_or_update_role() {
|
||||||
aws iam update-assume-role-policy --role-name "$name" --policy-document "file://${trust_file}"
|
aws iam update-assume-role-policy --role-name "$name" --policy-document "file://${trust_file}"
|
||||||
fi
|
fi
|
||||||
else
|
else
|
||||||
echo " $name: create"
|
echo " $name: create on /platform/"
|
||||||
|
# Path is create-only. IAM cannot move an existing role onto /platform/.
|
||||||
|
# Prod and dev already have hcptf-bootstrap and hcptf-bootstrap-plan, so
|
||||||
|
# this branch does not run for them. Do not delete and recreate to set a path.
|
||||||
if [[ "$DRY_RUN" -eq 0 ]]; then
|
if [[ "$DRY_RUN" -eq 0 ]]; then
|
||||||
aws iam create-role \
|
aws iam create-role \
|
||||||
--role-name "$name" \
|
--role-name "$name" \
|
||||||
|
--path /platform/ \
|
||||||
--assume-role-policy-document "file://${trust_file}" \
|
--assume-role-policy-document "file://${trust_file}" \
|
||||||
--description "HCP Terraform ${name} (PLAT-145). Console/CLI owned. Manual apply only." \
|
--description "HCP Terraform ${name} (PLAT-145). Console/CLI owned. Manual apply only." \
|
||||||
--tags Key=Project,Value=hcp-bootstrap Key=Owner,Value=adam@seahavenind.com Key=ManagedBy,Value=cli
|
--tags Key=Project,Value=hcp-bootstrap Key=Owner,Value=adam@seahavenind.com Key=ManagedBy,Value=cli
|
||||||
|
|
|
||||||
Loading…
Add table
Reference in a new issue