mirror of
https://github.com/Sea-Haven-Industries/seahaven-org-baseline.git
synced 2026-09-30 05:43:17 +00:00
ci(iam): fail when Access Analyzer credentials are missing (PLAT-234) (#162)
The policy-check role trust now matches pull request and merge queue subjects. A failed assume must fail the job instead of skipping ValidatePolicy and CheckNoNewAccess. Co-authored-by: Cursor Agent <cursoragent@cursor.com> Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com>
This commit is contained in:
parent
ac65a23d9f
commit
faa199771f
1 changed files with 0 additions and 6 deletions
6
.github/workflows/ci.yaml
vendored
6
.github/workflows/ci.yaml
vendored
|
|
@ -43,16 +43,10 @@ jobs:
|
|||
(cd /tmp/iam-base && npx cdk synth org-governance -o /tmp/iam-base-out --quiet)
|
||||
|
||||
- name: Configure AWS credentials
|
||||
id: aws-creds
|
||||
continue-on-error: true
|
||||
uses: aws-actions/configure-aws-credentials@e1253824e5c10ff9df46874f81ed3ec929e19cfd # v6.3.0
|
||||
with:
|
||||
role-to-assume: arn:aws:iam::328440206208:role/githubdeploy-seahaven-org-baseline-policy-check
|
||||
aws-region: us-east-1 # pragma: allowlist secret
|
||||
|
||||
- name: Note skipped analyzer credentials
|
||||
if: steps.aws-creds.outcome != 'success'
|
||||
run: echo "::warning title=Access Analyzer skipped::OIDC assume-role did not succeed, so ValidatePolicy and CheckNoNewAccess did not run. The skip stays until githubdeploy-seahaven-org-baseline-policy-check is deployed."
|
||||
|
||||
- name: Check IAM policies
|
||||
run: python3 scripts/check_iam_policies.py --cdk-out cdk.out --base-cdk-out /tmp/iam-base-out --base-repo /tmp/iam-base --self-test
|
||||
|
|
|
|||
Loading…
Add table
Reference in a new issue