ci(iam): fail when Access Analyzer credentials are missing (PLAT-234) (#162)
Some checks are pending
Deploy / deploy-management (push) Waiting to run
Deploy / deploy-external-dev (push) Waiting to run
Deploy / deploy-security (push) Waiting to run
Deploy / deploy-dev (push) Waiting to run
Deploy / deploy-prod (push) Waiting to run

The policy-check role trust now matches pull request and merge queue
subjects. A failed assume must fail the job instead of skipping
ValidatePolicy and CheckNoNewAccess.

Co-authored-by: Cursor Agent <cursoragent@cursor.com>
Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com>
This commit is contained in:
Adam Moussa 2026-09-28 18:38:21 +00:00 • committed by GitHub
parent ac65a23d9f
commit faa199771f
No known key found for this signature in database
GPG key ID: B5690EEEBB952194

View file

@ -43,16 +43,10 @@ jobs:
(cd /tmp/iam-base && npx cdk synth org-governance -o /tmp/iam-base-out --quiet)
- name: Configure AWS credentials
id: aws-creds
continue-on-error: true
uses: aws-actions/configure-aws-credentials@e1253824e5c10ff9df46874f81ed3ec929e19cfd # v6.3.0
with:
role-to-assume: arn:aws:iam::328440206208:role/githubdeploy-seahaven-org-baseline-policy-check
aws-region: us-east-1 # pragma: allowlist secret
- name: Note skipped analyzer credentials
if: steps.aws-creds.outcome != 'success'
run: echo "::warning title=Access Analyzer skipped::OIDC assume-role did not succeed, so ValidatePolicy and CheckNoNewAccess did not run. The skip stays until githubdeploy-seahaven-org-baseline-policy-check is deployed."
- name: Check IAM policies
run: python3 scripts/check_iam_policies.py --cdk-out cdk.out --base-cdk-out /tmp/iam-base-out --base-repo /tmp/iam-base --self-test