From faa199771f099f70e7e431d62f4c337c77895d5c Mon Sep 17 00:00:00 2001 From: Adam Moussa <166072409+amoussa1229@users.noreply.github.com> Date: Mon, 28 Sep 2026 18:38:21 +0000 Subject: [PATCH] ci(iam): fail when Access Analyzer credentials are missing (PLAT-234) (#162) The policy-check role trust now matches pull request and merge queue subjects. A failed assume must fail the job instead of skipping ValidatePolicy and CheckNoNewAccess. Co-authored-by: Cursor Agent Co-authored-by: Adam Moussa --- .github/workflows/ci.yaml | 6 ------ 1 file changed, 6 deletions(-) diff --git a/.github/workflows/ci.yaml b/.github/workflows/ci.yaml index 264f5f8..51cacfc 100644 --- a/.github/workflows/ci.yaml +++ b/.github/workflows/ci.yaml @@ -43,16 +43,10 @@ jobs: (cd /tmp/iam-base && npx cdk synth org-governance -o /tmp/iam-base-out --quiet) - name: Configure AWS credentials - id: aws-creds - continue-on-error: true uses: aws-actions/configure-aws-credentials@e1253824e5c10ff9df46874f81ed3ec929e19cfd # v6.3.0 with: role-to-assume: arn:aws:iam::328440206208:role/githubdeploy-seahaven-org-baseline-policy-check aws-region: us-east-1 # pragma: allowlist secret - - name: Note skipped analyzer credentials - if: steps.aws-creds.outcome != 'success' - run: echo "::warning title=Access Analyzer skipped::OIDC assume-role did not succeed, so ValidatePolicy and CheckNoNewAccess did not run. The skip stays until githubdeploy-seahaven-org-baseline-policy-check is deployed." - - name: Check IAM policies run: python3 scripts/check_iam_policies.py --cdk-out cdk.out --base-cdk-out /tmp/iam-base-out --base-repo /tmp/iam-base --self-test