mirror of
https://github.com/Sea-Haven-Industries/seahaven-org-baseline.git
synced 2026-10-06 12:11:58 +00:00
fix(iam): add plan-role refresh reads for afi terraform state
ViewOnlyAccess omits iam:GetRole and events:DescribeRule; without a scoped refresh policy, HCP plans fail after the first partial apply.
This commit is contained in:
parent
3512214d14
commit
f4292832fe
1 changed files with 60 additions and 4 deletions
|
|
@ -377,10 +377,12 @@ Resources:
|
||||||
#
|
#
|
||||||
# First HCP Terraform workload. Trust subs are exact StringEquals on
|
# First HCP Terraform workload. Trust subs are exact StringEquals on
|
||||||
# organization/project/workspace/run_phase — never StringLike, never a
|
# organization/project/workspace/run_phase — never StringLike, never a
|
||||||
# wildcarded run_phase. Plan role: ViewOnlyAccess only (never ReadOnlyAccess,
|
# wildcarded run_phase. Plan role: ViewOnlyAccess (never ReadOnlyAccess,
|
||||||
# which grants secretsmanager:GetSecretValue). Apply role: attaches the
|
# which grants secretsmanager:GetSecretValue) PLUS a stack-scoped refresh
|
||||||
# shared guardrail plus stack-scoped Lambda / layer / EventBridge / Logs.
|
# inline policy — ViewOnlyAccess omits iam:GetRole and events:DescribeRule,
|
||||||
# Prod-only (IsProdAccount): this template also deploys to seahaven-dev.
|
# which Terraform needs to refresh state after the first apply. Apply role:
|
||||||
|
# attaches the shared guardrail plus stack-scoped Lambda / layer /
|
||||||
|
# EventBridge / Logs / artifact-bucket. Prod-only (IsProdAccount).
|
||||||
# ---------------------------------------------------------------------------
|
# ---------------------------------------------------------------------------
|
||||||
HcptfAfiBackupMonitorPlanRole:
|
HcptfAfiBackupMonitorPlanRole:
|
||||||
Type: AWS::IAM::Role
|
Type: AWS::IAM::Role
|
||||||
|
|
@ -400,6 +402,60 @@ Resources:
|
||||||
"app.terraform.io:sub": organization:seahaven:project:seahaven-prod:workspace:afi-backup-monitor-prod:run_phase:plan
|
"app.terraform.io:sub": organization:seahaven:project:seahaven-prod:workspace:afi-backup-monitor-prod:run_phase:plan
|
||||||
ManagedPolicyArns:
|
ManagedPolicyArns:
|
||||||
- arn:aws:iam::aws:policy/job-function/ViewOnlyAccess
|
- arn:aws:iam::aws:policy/job-function/ViewOnlyAccess
|
||||||
|
Policies:
|
||||||
|
- PolicyName: afi-backup-monitor-plan-refresh
|
||||||
|
PolicyDocument:
|
||||||
|
Version: "2012-10-17"
|
||||||
|
Statement:
|
||||||
|
- Sid: RefreshIamRoles
|
||||||
|
Effect: Allow
|
||||||
|
Action:
|
||||||
|
- iam:GetRole
|
||||||
|
- iam:GetRolePolicy
|
||||||
|
- iam:ListRolePolicies
|
||||||
|
- iam:ListAttachedRolePolicies
|
||||||
|
Resource:
|
||||||
|
- !Sub "arn:aws:iam::${AWS::AccountId}:role/tf-managed/afi-*"
|
||||||
|
- Sid: RefreshManagedPolicies
|
||||||
|
Effect: Allow
|
||||||
|
Action:
|
||||||
|
- iam:GetPolicy
|
||||||
|
- iam:GetPolicyVersion
|
||||||
|
Resource: "*"
|
||||||
|
- Sid: RefreshEventBridge
|
||||||
|
Effect: Allow
|
||||||
|
Action:
|
||||||
|
- events:DescribeRule
|
||||||
|
- events:ListTargetsByRule
|
||||||
|
- events:ListTagsForResource
|
||||||
|
Resource:
|
||||||
|
- !Sub "arn:aws:events:us-east-1:${AWS::AccountId}:rule/afi-*"
|
||||||
|
- Sid: RefreshLambda
|
||||||
|
Effect: Allow
|
||||||
|
Action:
|
||||||
|
- lambda:GetFunction
|
||||||
|
- lambda:GetFunctionConfiguration
|
||||||
|
- lambda:GetPolicy
|
||||||
|
- lambda:GetLayerVersion
|
||||||
|
- lambda:ListVersionsByFunction
|
||||||
|
- lambda:ListTags
|
||||||
|
Resource:
|
||||||
|
- !Sub "arn:aws:lambda:us-east-1:${AWS::AccountId}:function:afi-*"
|
||||||
|
- !Sub "arn:aws:lambda:us-east-1:${AWS::AccountId}:layer:afi-shared*"
|
||||||
|
- Sid: RefreshArtifactsBucket
|
||||||
|
Effect: Allow
|
||||||
|
Action:
|
||||||
|
- s3:Get*
|
||||||
|
- s3:ListBucket
|
||||||
|
Resource:
|
||||||
|
- !Sub "arn:aws:s3:::afi-backup-monitor-artifacts-${AWS::AccountId}"
|
||||||
|
- !Sub "arn:aws:s3:::afi-backup-monitor-artifacts-${AWS::AccountId}/*"
|
||||||
|
- Sid: RefreshLogs
|
||||||
|
Effect: Allow
|
||||||
|
Action:
|
||||||
|
- logs:DescribeLogGroups
|
||||||
|
- logs:ListTagsForResource
|
||||||
|
Resource: "*"
|
||||||
|
|
||||||
HcptfAfiBackupMonitorApplyRole:
|
HcptfAfiBackupMonitorApplyRole:
|
||||||
Type: AWS::IAM::Role
|
Type: AWS::IAM::Role
|
||||||
|
|
|
||||||
Loading…
Add table
Reference in a new issue