Commit graph

1 commit

Author SHA1 Message Date
Adam Moussa
a43ec1f0f5
feat(hcptf): add hcptf-mta-sts apply and plan roles to seahaven-hcptf (PLAT-243) (#178)
Some checks are pending
Deploy / deploy-management (push) Waiting to run
Deploy / deploy-external-dev (push) Waiting to run
Deploy / deploy-security (push) Waiting to run
Deploy / deploy-dev (push) Waiting to run
Deploy / deploy-prod (push) Waiting to run
* feat(hcptf): add hcptf-mta-sts apply and plan roles to seahaven-hcptf

New MtaStsRoles construct nested in the prod seahaven-hcptf stack for the
mta-sts-prod HCP workspace. Fresh roles, plain create, Retain on every
resource. Trust is StringEquals on the exact workspace sub per run phase.

Managed policies at /tf-managed/:
- mta-sts-hcptf-iam: manage only githubdeploy-mta-sts and its boundary;
  CreateRole requires that boundary; DenySelfMutation on hcptf-*,
  githubdeploy-*, cdk, OrganizationAccountAccessRole, seahaven-*
- mta-sts-hcptf-services: S3 on mta-sts-prod-*, CloudFront, ACM scoped
  to Project=mta-sts, SSM /mta-sts/deploy/* and the WAF ACL parameter,
  GitHub OIDC provider read
- mta-sts-hcptf-plan: enumerated refresh reads beside ViewOnlyAccess

Outputs MtaStsApplyRoleArn and MtaStsPlanRoleArn. README lists mta-sts
with the other prod exec roles that live in this stack.

* fix(hcptf): scope mta-sts CreatePolicy and plan policy reads to the boundary ARN

CreateDeployBoundary now names the boundary ARN as its Resource instead of
"*", keeping the BoundaryFor request-tag condition as a second gate.

The plan sidecar's GetPolicy, GetPolicyVersion, ListPolicyVersions, and
ListPolicyTags are merged into one RefreshDeployBoundary statement on the
boundary ARN. The boundary is the only managed policy in Terraform state,
and ViewOnlyAccess does not carry GetPolicy or GetPolicyVersion.

* fix(hcptf): replace cloudfront:* in mta-sts services policy with tag-gated grants

CloudFrontManage granted cloudfront:* on every CloudFront resource in the
account. Split into:

- CloudFrontRead: the Get and ListTagsForResource calls Terraform makes
- CloudFrontCreateTagged: CreateDistribution and TagResource on the
  distribution ARN type, gated on request tag Project=mta-sts
- CloudFrontManageTagged: Update, Delete, Tag, Untag, and CreateInvalidation
  gated on resource tag Project=mta-sts
- CloudFrontOac: Create, Update, Delete on the origin-access-control ARN
  type; OACs do not support tags

A distribution another workspace owns cannot be mutated by this role. The
workspace provider must set Project=mta-sts in default_tags.

* fix(hcptf): close mta-sts TagResource bypass and trim ACM and plan reads

CloudFrontCreateTagged keeps cloudfront:TagResource, which
CreateDistributionWithTags requires before the distribution has tags, but
adds Null aws:ResourceTag/Project so it applies only to a distribution with
no Project tag yet. An existing distribution owned by another workspace can
no longer be re-tagged into CloudFrontManageTagged's scope.

ACM is trimmed to what aws_acm_certificate calls: RequestCertificate,
DescribeCertificate, ListTagsForCertificate, AddTagsToCertificate,
RemoveTagsFromCertificate, DeleteCertificate. GetCertificate,
RenewCertificate, and ListCertificates are dropped from both roles.

RefreshDeployRole reads only githubdeploy-mta-sts; the two CFN-owned exec
roles are not in Terraform state.

* fix(hcptf): give CloudFront create actions Resource "*" in mta-sts services policy

cloudfront:CreateDistribution and cloudfront:CreateOriginAccessControl have
no resource type in the service authorization reference and only match
Resource "*". Scoping them to the distribution and OAC ARN types would have
implicitly denied the first apply. TagResource at create time stays on the
distribution ARN type with the RequestTag and Null ResourceTag conditions,
and OAC update and delete stay on the OAC ARN type.

Verified with iam simulate-custom-policy: CreateDistribution with request
tag Project=mta-sts allowed; TagResource, UpdateDistribution, and
DeleteDistribution on a distribution tagged Project=seahaven-site denied.
2026-10-05 18:42:33 +00:00