diff --git a/.github/workflows/ci.yaml b/.github/workflows/ci.yaml index 264f5f8..51cacfc 100644 --- a/.github/workflows/ci.yaml +++ b/.github/workflows/ci.yaml @@ -43,16 +43,10 @@ jobs: (cd /tmp/iam-base && npx cdk synth org-governance -o /tmp/iam-base-out --quiet) - name: Configure AWS credentials - id: aws-creds - continue-on-error: true uses: aws-actions/configure-aws-credentials@e1253824e5c10ff9df46874f81ed3ec929e19cfd # v6.3.0 with: role-to-assume: arn:aws:iam::328440206208:role/githubdeploy-seahaven-org-baseline-policy-check aws-region: us-east-1 # pragma: allowlist secret - - name: Note skipped analyzer credentials - if: steps.aws-creds.outcome != 'success' - run: echo "::warning title=Access Analyzer skipped::OIDC assume-role did not succeed, so ValidatePolicy and CheckNoNewAccess did not run. The skip stays until githubdeploy-seahaven-org-baseline-policy-check is deployed." - - name: Check IAM policies run: python3 scripts/check_iam_policies.py --cdk-out cdk.out --base-cdk-out /tmp/iam-base-out --base-repo /tmp/iam-base --self-test