Commit graph

8 commits

Author SHA1 Message Date
Adam Moussa
960e4619b4
fix(iam): allow frontend HCP apply to write deploy SSM and githubdeploy trust (PLAT-212) (#150)
Some checks failed
Deploy / deploy-management (push) Has been cancelled
Deploy / deploy-external-dev (push) Has been cancelled
Deploy / deploy-security (push) Has been cancelled
Deploy / deploy-dev (push) Has been cancelled
Deploy / deploy-prod (push) Has been cancelled
* fix(iam): allow frontend HCP apply to write deploy SSM and githubdeploy trust (PLAT-212)

* fix(iam): grant frontend HCP plan named SSM describe and tag reads (PLAT-212)

* fix(iam): allow frontend githubdeploy to read deploy SSM (PLAT-212)

HCP apply already writes /shoc-frontend-new/<env>/deploy/*, but the
githubdeploy ceiling omitted GetParameter so Deploy Web cannot resolve
bucket and distribution after origin moves to the bucket root.

* fix(iam): allow staging HCP apply to update the SHOC backend EB stack (PLAT-213)

* fix(iam): allow staging HCP apply to use the Elastic Beanstalk bucket (PLAT-213)

* fix(iam): allow staging HCP apply to copy the current release zip (PLAT-213)

* fix(iam): allow staging HCP apply versioned ACLs on EB env objects (PLAT-213)

* fix(iam): give staging HCP apply the proven Elastic Beanstalk bucket grants (PLAT-213)

* fix(iam): allow staging HCP apply to write CloudFormation template buckets (PLAT-213)

* fix(iam): let staging HCP apply read Elastic Beanstalk service templates (PLAT-213)
2026-09-18 21:37:05 +00:00
Adam Moussa
a492a45e07
chore(iam): remove frontend tf-poc substrate after teardown (PLAT-194) (#146)
Some checks failed
Deploy / deploy-management (push) Has been cancelled
Deploy / deploy-external-dev (push) Has been cancelled
Deploy / deploy-security (push) Has been cancelled
Deploy / deploy-dev (push) Has been cancelled
Deploy / deploy-prod (push) Has been cancelled
2026-09-11 22:17:00 +00:00
Adam Moussa
5d613c73bc
feat(iam): allow frontend tf-poc HCP apply destroy (PLAT-193) (#145) 2026-09-11 21:46:59 +00:00
Adam Moussa
3c54df6341
fix(iam): allow GitHub frontend deploy roles to GetDistribution (PLAT-192) (#144)
Some checks are pending
Deploy / deploy-management (push) Waiting to run
Deploy / deploy-external-dev (push) Waiting to run
Deploy / deploy-security (push) Waiting to run
Deploy / deploy-dev (push) Waiting to run
Deploy / deploy-prod (push) Waiting to run
Verify and live-state summary call get-distribution; the identity policy already granted it, but the permissions boundary denied the action.
2026-09-11 19:37:24 +00:00
Adam Moussa
60b978aa2a
feat(iam): allow frontend HCP apply to own release pointer and invalidation (PLAT-188) (#143)
Some checks are pending
Deploy / deploy-management (push) Waiting to run
Deploy / deploy-external-dev (push) Waiting to run
Deploy / deploy-security (push) Waiting to run
Deploy / deploy-dev (push) Waiting to run
Deploy / deploy-prod (push) Waiting to run
* feat(iam): allow frontend HCP apply to own release pointer and invalidation (PLAT-188)

Plan and apply roles can read .release/current; apply can PutObject that key and CreateInvalidation on the exact distribution.

* fix(iam): allow frontend HCP roles to tag the release pointer (PLAT-188)

Terraform aws_s3_object lists object tags on every refresh, so plan and apply need GetObjectTagging and apply needs PutObjectTagging on the exact .release/current key.
2026-09-11 17:37:42 +00:00
Adam Moussa
0c6f307b61
feat(iam): allow frontend HCP apply to update exact CloudFront resources (PLAT-187) (#142)
Some checks are pending
Deploy / deploy-management (push) Waiting to run
Deploy / deploy-external-dev (push) Waiting to run
Deploy / deploy-security (push) Waiting to run
Deploy / deploy-dev (push) Waiting to run
Deploy / deploy-prod (push) Waiting to run
* feat(iam): allow frontend HCP apply to update exact CloudFront resources (PLAT-187)

Phase 2 ownership tags cannot apply while UpdateDistribution and UpdateFunction are denied on *. Allow those two actions only on the pinned distribution and function ARNs.

* fix(iam): allow PublishFunction on exact frontend CloudFront functions (PLAT-187)

The AWS provider publishes after UpdateFunction, including tag-only applies, so denying PublishFunction on * still blocked Phase 2 function updates.
2026-09-11 15:08:21 +00:00
Adam Moussa
6d5811f08e
fix(iam): codify live terraform-substrate IAM (PLAT-142) (#135)
Some checks are pending
Deploy / deploy-management (push) Waiting to run
Deploy / deploy-external-dev (push) Waiting to run
Deploy / deploy-security (push) Waiting to run
Deploy / deploy-dev (push) Waiting to run
Deploy / deploy-prod (push) Waiting to run
* fix(iam): allow frontend import plan to read deploy boundaries

* fix(iam): grant backend apply role EB UpdateEnvironment follow-on perms
2026-09-01 00:16:34 +00:00
Adam Moussa
6a0713f49d
feat(iam): add frontend Terraform substrate (#133)
Some checks are pending
Deploy / deploy-management (push) Waiting to run
Deploy / deploy-external-dev (push) Waiting to run
Deploy / deploy-security (push) Waiting to run
Deploy / deploy-dev (push) Waiting to run
Deploy / deploy-prod (push) Waiting to run
* feat(iam): add frontend Terraform substrate

* fix(iam): align frontend Terraform substrate

* feat(iam): enable frontend live Terraform roles
2026-08-31 02:25:47 +00:00