Commit graph

39 commits

Author SHA1 Message Date
Adam Moussa
db9465deda
fix(iam): allow shoc-backend HCP apply to write deploy SSM and matching githubdeploy trust (PLAT-148) (#148)
* fix(iam): allow shoc-backend HCP apply to write deploy SSM and matching githubdeploy trust (PLAT-148)

* fix(iam): grant shoc-backend staging plan named inventory reads (PLAT-148)

* fix(iam): allow staging githubdeploy to GetObject release zips (PLAT-148)

* fix(iam): allow staging githubdeploy to write EB processed extensions (PLAT-148)

* fix(iam): allow staging githubdeploy GetObjectAcl on release zips (PLAT-148)

* fix(iam): grant staging githubdeploy named S3 reads on EB resources prefix (PLAT-148)

* fix(iam): allow staging githubdeploy to delete EB version cache objects (PLAT-148)

* fix(iam): scope staging githubdeploy S3 object access to the EB bucket (PLAT-148)

* fix(iam): allow staging githubdeploy PutObjectVersionAcl on EB artifacts (PLAT-148)

* fix(iam): allow staging githubdeploy GetBucketPolicy on the EB bucket (PLAT-148)

* fix(iam): scope staging githubdeploy S3 objects to SHOC and staging EB prefixes (PLAT-148)
2026-09-18 18:13:01 +00:00
Adam Moussa
6bc4f6e095
chore(iam): remove backend tf-poc boundaries (#139)
Some checks failed
Deploy / deploy-management (push) Has been cancelled
Deploy / deploy-external-dev (push) Has been cancelled
Deploy / deploy-security (push) Has been cancelled
Deploy / deploy-dev (push) Has been cancelled
Deploy / deploy-prod (push) Has been cancelled
2026-09-03 15:04:58 +00:00
Adam Moussa
b02f52b805
feat(iam): lock app-owned HCP IAM and add bootstrap SCP (PLAT-143) (#137)
* feat(iam): lock app-owned HCP IAM and add bootstrap SCP (PLAT-143)

* fix(iam): pin HCP boundary ARNs and bootstrap trust window (PLAT-143)

Null on iam:PermissionsBoundary accepted any ceiling, including AdministratorAccess. Import apply cannot self-mutate hcptf-* while bootstrap trust is iam-bootstrap only; add a time-boxed exact StringEquals workspace grant instead of StringLike.
2026-09-02 15:22:48 +00:00
Adam Moussa
35dc61b806
feat(iam): allow tf-poc HCP apply destroy (#136)
Some checks are pending
Deploy / deploy-management (push) Waiting to run
Deploy / deploy-external-dev (push) Waiting to run
Deploy / deploy-security (push) Waiting to run
Deploy / deploy-dev (push) Waiting to run
Deploy / deploy-prod (push) Waiting to run
2026-09-01 16:14:06 +00:00
Adam Moussa
6d5811f08e
fix(iam): codify live terraform-substrate IAM (PLAT-142) (#135)
Some checks are pending
Deploy / deploy-management (push) Waiting to run
Deploy / deploy-external-dev (push) Waiting to run
Deploy / deploy-security (push) Waiting to run
Deploy / deploy-dev (push) Waiting to run
Deploy / deploy-prod (push) Waiting to run
* fix(iam): allow frontend import plan to read deploy boundaries

* fix(iam): grant backend apply role EB UpdateEnvironment follow-on perms
2026-09-01 00:16:34 +00:00
Adam Moussa
559eed1e98
fix(iam): allow backend Terraform refresh (PLAT-141) (#134)
Some checks are pending
Deploy / deploy-management (push) Waiting to run
Deploy / deploy-external-dev (push) Waiting to run
Deploy / deploy-security (push) Waiting to run
Deploy / deploy-dev (push) Waiting to run
Deploy / deploy-prod (push) Waiting to run
* fix(iam): allow backend import plan reads

* fix(iam): authorize backend EB refresh

* fix(iam): authorize backend EB ownership check
2026-08-31 17:04:00 +00:00
Adam Moussa
08191ded4c
chore(iam): finalize backend role ownership (#132)
Some checks are pending
Deploy / deploy-management (push) Waiting to run
Deploy / deploy-external-dev (push) Waiting to run
Deploy / deploy-security (push) Waiting to run
Deploy / deploy-dev (push) Waiting to run
Deploy / deploy-prod (push) Waiting to run
* chore(iam): finalize backend role ownership

* fix(iam): complete backend import permissions
2026-08-30 20:12:54 +00:00
Adam Moussa
dba0871587
feat(iam): add external-dev backend Terraform substrate (#131)
Some checks are pending
Deploy / deploy-management (push) Waiting to run
Deploy / deploy-external-dev (push) Waiting to run
Deploy / deploy-security (push) Waiting to run
Deploy / deploy-dev (push) Waiting to run
Deploy / deploy-prod (push) Waiting to run
* feat(iam): add external-dev backend terraform substrate

* fix(iam): require boundaries for SHOC policy writes
2026-08-29 21:04:40 +00:00
Adam Moussa
ee233379dd
fix(iam): allow paychex worker ledger dynamodb (#130)
Some checks failed
Deploy / deploy-management (push) Has been cancelled
Deploy / deploy-external-dev (push) Has been cancelled
Deploy / deploy-security (push) Has been cancelled
Deploy / deploy-dev (push) Has been cancelled
Deploy / deploy-prod (push) Has been cancelled
HCP plan/apply and the paychex Lambda boundary need the paychex-worker-ledger table ARN so PLAT-123 can create and use the identity ledger.
2026-08-28 16:11:23 +00:00
Adam Moussa
2f5e5e6e66
fix(iam): drop unscoped door-unlock domain create (#127)
CreateDomainName cannot be hostname-pinned, and mgmt still holds doorunlock.seahaven.com. Attach the domain at cutover instead of granting collection POST.
2026-08-27 23:03:35 +00:00
Adam Moussa
23d954369d
fix(iam): allow door-unlock apply to create api domain (#126)
Some checks are pending
Deploy / deploy-management (push) Waiting to run
Deploy / deploy-external-dev (push) Waiting to run
Deploy / deploy-security (push) Waiting to run
Deploy / deploy-dev (push) Waiting to run
Deploy / deploy-prod (push) Waiting to run
CreateDomainName authorizes against the /domainnames collection, so the hostname-pinned ARN cannot complete first apply.
2026-08-27 22:43:48 +00:00
Adam Moussa
28a064966b
fix(iam): allow door-unlock plan to read 3cx secret metadata (#125)
The AWS secrets data source calls GetResourcePolicy; the first HCP plan failed without it on the three exact 3CX ARNs.
2026-08-27 22:16:11 +00:00
Adam Moussa
e5e7980508
feat(iam): add paychex-integrations hcptf roles and boundary (PLAT-120) (#124)
* feat(iam): add paychex-integrations hcptf roles and boundary

* fix(iam): split paychex plan lambda list onto Resource *
2026-08-27 21:50:11 +00:00
Adam Moussa
689ec147a3
feat(iam): add door-unlock-api hcptf roles and boundary (PLAT-76) (#123)
Some checks are pending
Deploy / deploy-management (push) Waiting to run
Deploy / deploy-external-dev (push) Waiting to run
Deploy / deploy-security (push) Waiting to run
Deploy / deploy-dev (push) Waiting to run
Deploy / deploy-prod (push) Waiting to run
* feat(iam): add door-unlock-api hcptf roles and boundary

Give HCP Terraform a prod plan/apply pair, a per-workload Lambda boundary with exact SSM and 3CX ARNs, and API access-log delivery so PLAT-76 can leave the mgmt CDK stack.

* fix(iam): pin door-unlock apigw domain and ssm reads

Stop the apply role from managing every HTTP API custom domain, and keep SecureString door-unlock parameters off HCP plan and apply GetParameter.
2026-08-27 21:26:27 +00:00
9bffddfd7b
fix(iam): allow site plan role to describe CF function (PLAT-106) 2026-08-20 15:22:09 -04:00
5fa4267798
chore(iam): drop PascalCase WO Dynamo and alarm ARNs 2026-08-14 11:58:41 -04:00
0f84d7808b
feat(iam): add per-workload lambda execution boundaries
Shared seahaven-lambda-execution-boundary stays unchanged for live roles.
New named policies plus an enumerated StringEquals allow-list unblock the
next PLAT-71 widen without growing the 6144-character shared document.
2026-08-13 16:47:53 -04:00
b76d0578e0
fix(iam): drop PutResourcePolicy from meal-order apply role
Pre-grant delivery.logs write via MealOrderApiAccessLogResourcePolicy on
substrate so the HCP apply role cannot mutate account-wide log resource
policies.
2026-08-10 14:57:17 -04:00
e10462d25e
fix(iam): allow API GW Log Delivery on meal-order apply role 2026-08-10 14:47:30 -04:00
6bb2d54814
fix(iam): allow PassRole to apigateway for meal-order authorizer 2026-08-10 13:46:12 -04:00
1bb5e79ea0
fix(iam): allow ssm:ListTagsForResource on meal-order plan role 2026-08-10 13:23:56 -04:00
Adam Moussa
f44b88732e
fix(iam): allow ssm:DescribeParameters for meal-order hcptf roles (#99)
Some checks failed
Deploy / deploy-management (push) Has been cancelled
Deploy / deploy-external-dev (push) Has been cancelled
Deploy / deploy-security (push) Has been cancelled
Deploy / deploy-dev (push) Has been cancelled
Deploy / deploy-prod (push) Has been cancelled
2026-08-08 00:11:48 +00:00
Adam Moussa
44b672ae9a
feat(iam): add hcptf roles and boundary widen for meal-order-manager (PLAT-70) (#97)
* feat(iam): add hcptf roles and boundary widen for meal-order-manager

Append plan/apply OIDC roles for meal-order-manager-prod and widen the lambda execution boundary with exact prod secret ARN and data-plane statements.

* fix(iam): make meal-order plan role Lambda refresh read-only

Replace plan-role lambda:* with Get*/List* so plan-phase credentials cannot mutate functions or layers.
2026-08-07 19:36:20 -04:00
Adam Moussa
a6f22880db
feat(waf): add seahaven-prod shared CloudFront WebACL (PLAT-92) (#96)
Some checks are pending
Deploy / deploy-management (push) Waiting to run
Deploy / deploy-external-dev (push) Waiting to run
Deploy / deploy-security (push) Waiting to run
Deploy / deploy-dev (push) Waiting to run
Deploy / deploy-prod (push) Waiting to run
* feat(waf): add seahaven-prod shared CloudFront WebACL stack

Stand up AppWebAcl in a thin prod stack and widen seahaven-site HCP
roles to read the SSM ARN so CloudFront can associate the ACL in-account.

* fix(deploy): add app-web-acl-prod to deploy.yaml
2026-08-07 17:07:04 -04:00
Adam Moussa
35461d9267
feat(iam): add hcptf-seahaven-site plan/apply roles (PLAT-91) (#89)
Some checks are pending
Deploy / deploy-management (push) Waiting to run
Deploy / deploy-external-dev (push) Waiting to run
Deploy / deploy-security (push) Waiting to run
Deploy / deploy-dev (push) Waiting to run
Deploy / deploy-prod (push) Waiting to run
* feat(iam): add hcptf-seahaven-site plan/apply roles

Static-site HCP substrate for seahaven-site-prod plus boundary widen for
the TF-managed content-deploy role (S3 origin + CloudFront invalidate).

* fix(iam): allow seahaven-site HCP roles to read GitHub OIDC provider

Plan refresh needs iam:GetOpenIDConnectProvider for the content-deploy
role trust data source (PLAT-91 first-plan AccessDenied).
2026-08-07 15:09:57 -04:00
Adam Moussa
ff77ffd421
fix(iam): allow HCP procurement-ingest kebab WO Dynamo tables (#88)
Some checks are pending
Deploy / deploy-management (push) Waiting to run
Deploy / deploy-external-dev (push) Waiting to run
Deploy / deploy-security (push) Waiting to run
Deploy / deploy-dev (push) Waiting to run
Deploy / deploy-prod (push) Waiting to run
Widen hcptf-procurement-ingest apply and plan-refresh DynamoDB/CloudWatch
ARN pins for work-orders and work-order-comments (PLAT-11 rename).
2026-08-07 13:53:42 -04:00
202103041c
fix(iam): allow API GW and ESM tagging for procurement-ingest
Provider default_tags need apigateway /tags/* and unconditioned ESM
TagResource after import-in-place.
2026-08-07 11:09:06 -04:00
a5997f878b
fix(iam): widen procurement-ingest plan refresh for import
Add GetEventSourceMapping, SSM GetParameter pins, and Resource "*" for
kms:ListAliases so the first HCP import plan can refresh.
2026-08-07 11:00:49 -04:00
Adam Moussa
a5fa0b16a3
feat(iam): add hcptf roles and boundary for procurement-ingest (PLAT-86) (#85)
* feat(iam): add hcptf roles and boundary for procurement-ingest

* fix(iam): tighten procurement-ingest apply and plan scopes

Replace kms:* and secret-value writes on shell statements; split IAM
collection APIs onto Resource "*".
2026-08-07 10:41:12 -04:00
Adam Moussa
69f31842cb
feat(iam): add hcptf roles for sh-openswe-traces-prod (PLAT-73) (#80)
Some checks are pending
Deploy / deploy-management (push) Waiting to run
Deploy / deploy-external-dev (push) Waiting to run
Deploy / deploy-security (push) Waiting to run
Deploy / deploy-dev (push) Waiting to run
Deploy / deploy-prod (push) Waiting to run
* feat(iam): add hcptf roles for sh-openswe-traces-prod

Storage/IAM-user apply and plan roles for the HCP workspace. No Lambda
boundary widen; explicit IAM user CRUD because hcptf-iam-management is
role-path-only.

* fix(iam): pin CreateSecret to exact export secret name

Remove CreateSecret and UpdateSecret from the ARN-prefix shell grant so
apply cannot create longer-named secrets or overwrite SecretString.
2026-08-05 22:46:32 +00:00
Adam Moussa
fc64b03e3d
feat(iam): hcptf front-integrations roles and boundary (PLAT-72) (#81)
* feat(iam): add hcptf front-integrations roles and boundary widen

Add plan/apply OIDC roles for front-integrations-prod and widen the
Lambda execution boundary with exact prod secret ARNs plus DynamoDB
CRUD on front-sla-alerts.

* fix(iam): restrict front-integrations plan role to lambda Get/List

Keep mutate APIs on the apply role so a compromised plan-phase
OIDC session cannot update or delete front-* functions.
2026-08-05 18:33:31 -04:00
Adam Moussa
9ee4d4a3d7
docs(iam): codify hcp terraform migration checklist from PLAT-56 (#79)
Some checks are pending
Deploy / deploy-management (push) Waiting to run
Deploy / deploy-external-dev (push) Waiting to run
Deploy / deploy-security (push) Waiting to run
Deploy / deploy-dev (push) Waiting to run
Deploy / deploy-prod (push) Waiting to run
Expand the README playbook to steps 0–10 and document the required
plan-refresh sidecar plus prefix-scoped apply-role wildcards so the
next workload copies afi patterns instead of relearning first-apply misses.
2026-08-05 16:14:16 -04:00
46829fc2c1
fix(iam): use lambda:* and events:* on afi hcptf apply scope
Provider refresh needs GetFunctionCodeSigningConfig and similar reads;
keep blast radius on afi-* function/layer/rule ARNs only.
2026-08-05 12:59:19 -04:00
f4292832fe
fix(iam): add plan-role refresh reads for afi terraform state
ViewOnlyAccess omits iam:GetRole and events:DescribeRule; without a
scoped refresh policy, HCP plans fail after the first partial apply.
2026-08-05 12:57:23 -04:00
3512214d14
fix(iam): allow s3:* on afi artifact bucket for provider reads
First HCP apply failed on s3:GetBucketAcl after CreateBucket; scope
remains the single artifact bucket ARN.
2026-08-05 12:56:24 -04:00
Adam Moussa
4e1cf4c0bd
feat(iam): add hcptf roles/boundary widen - afi-backup-monitor (PLAT-56) (#76)
* feat(iam): add hcptf roles and boundary widen for afi-backup-monitor

Provision plan/apply OIDC roles for workspace afi-backup-monitor-prod
and widen the prod Lambda boundary with the two exact secret ARNs.

* fix(iam): split DescribeLogGroups and allow afi artifact bucket

logs:DescribeLogGroups cannot be resource-scoped; grant it on *. Add
S3 permissions for the HCP Lambda artifact bucket used by PLAT-56.
2026-08-05 12:44:52 -04:00
08a1d41b05
docs(iam): resolve confirmed review findings from both INFRA-186 gates
Cross-family round 1 plus the /sh-security-review verifier confirmed 11
findings on the floor reduction, all documentation defects; no policy
statement changes. The one HIGH: the Terraform migration checklist never
widened the boundary, so a Lambda-bearing Terraform migration would deploy
green and lose every data-plane call at first invoke. Checklist step 2 now
carries the widening requirement, step 3 verifies deployed boundary content,
and the terraform-substrate header no longer reads as 'Terraform path
unaffected'. Also corrected: Description is a REPLACEMENT property (a
Description edit wedges the custom-named policy and CFN's remedy is the
forbidden rename), the sanctioned-source contradiction, the false
AWSLambdaVPCAccessExecutionRole parity claim, the KMS log-group category
error, stale size numbers (691/5,453), the same-PR widening contradiction,
per-workload residue text, a LoggingConfig silent-log-loss note, the
us-east-1 region pin rationale, and ENI DoS deferral now tracked as
INFRA-200.
2026-07-31 13:44:21 -04:00
981960433f
fix(iam): scope Terraform guardrail role writes to a Terraform-owned path
Security review (6 detectors + proof-or-kill verifier) confirmed 1 critical and
1 high in the first revision, both inherited by mirroring the SAM copy's
Resource "*" role grants:

- C1 (critical): iam:UpdateAssumeRolePolicy on "*" with DenySelfMutation
  covering only three name patterns lets the principal repoint the
  AdministratorAccess CDK bootstrap role's trust policy to an external account.
- C2 (high): the SAM justification for role/* (SAM auto-roles land at path /
  with no settable RolePath) does not transfer -- Terraform's aws_iam_role
  supports path.

Fixes, closing the class at the root rather than by denylist:
- All role writes, boundary sets and PassRole confined to role/tf-managed/*;
  reads split into a separate statement that keeps Resource "*".
- DenySelfMutation extended to cdk-hnb659fds-*, OrganizationAccountAccessRole
  and seahaven-* as defense in depth.
- OIDC provider made conditional (CreateOIDCProvider), mirroring the sibling
  substrate, so a first-create rollback is recoverable rather than wedging the
  stack in ROLLBACK_COMPLETE against a Retained orphan.
- README corrected: the guardrail policy is NOT Retain (only the provider is),
  so the Deny backstops do not survive a stack delete.

checkov CKV_AWS_109 no longer fires on this template, so no suppression is
needed. The template header records every divergence from the SAM copy.
2026-07-30 16:55:45 -04:00
ea27635ef2
feat(iac): add per-account HCP Terraform deploy substrate for prod and dev
New stack seahaven-terraform-substrate (instances terraform-substrate-prod +
terraform-substrate-dev): app.terraform.io OIDC provider and the shared
boundary-gated guardrail policy seahaven-hcptf-iam-management that
per-workspace Terraform apply roles attach at migration time. No roles are
pre-provisioned (accumulator pattern, parallel to githubdeploy-*).

Guardrail statements mirror seahaven-cfn-exec-iam-management byte-identically
except DenySelfMutation, whose scope extends to hcptf-* alongside the
GitHub-substrate principals. Explicit stack dependency on the same-account
deploy-substrate stack (boundary ARN appears only in Condition strings, so
CFN infers no edge).
2026-07-30 16:31:34 -04:00