import * as cdk from "aws-cdk-lib"; import * as identitystore from "aws-cdk-lib/aws-identitystore"; import * as sso from "aws-cdk-lib/aws-sso"; import { Construct } from "constructs"; const IDENTITY_CENTER_INSTANCE_ARN = "arn:aws:sso:::instance/ssoins-722321f42ca610e4"; const IDENTITY_STORE_ID = "d-9067ec8e26"; const MANAGEMENT_ACCOUNT_ID = "328440206208"; /** * Identity Center group and permission set for platform operators (SEC-37). * * Assigned only to the management account. ReadOnlyAccess plus * sts:AssumeRole on OrganizationAccountAccessRole, so the existing * bootstrap and teardown scripts keep working after a person uses this * set. Those scripts still assume OrganizationAccountAccessRole directly. * Retarget them only after this set is deployed and a real sign-in has * assumed the member role. * * This is not an SCP exemption. /platform/ path denies exempt the * reserved SSO role name AWSReservedSSO_Platform_* once the set exists. */ export class PlatformAccessStack extends cdk.Stack { constructor(scope: Construct, id: string, props?: cdk.StackProps) { super(scope, id, props); const group = new identitystore.CfnGroup(this, "PlatformGroup", { identityStoreId: IDENTITY_STORE_ID, displayName: "platform", description: "Platform operators. Management account only. Assumes OrganizationAccountAccessRole for bootstrap.", }); const permissionSet = new sso.CfnPermissionSet(this, "PlatformPermissionSet", { instanceArn: IDENTITY_CENTER_INSTANCE_ARN, name: "Platform", description: "Read-only in the management account, plus assume OrganizationAccountAccessRole.", sessionDuration: "PT8H", managedPolicies: ["arn:aws:iam::aws:policy/ReadOnlyAccess"], inlinePolicy: { Version: "2012-10-17", Statement: [ { Sid: "AssumeOrganizationAccountAccessRole", Effect: "Allow", Action: "sts:AssumeRole", Resource: "arn:aws:iam::*:role/OrganizationAccountAccessRole", }, ], }, }); new sso.CfnAssignment(this, "PlatformManagementAssignment", { instanceArn: IDENTITY_CENTER_INSTANCE_ARN, permissionSetArn: permissionSet.attrPermissionSetArn, principalId: group.attrGroupId, principalType: "GROUP", targetId: MANAGEMENT_ACCOUNT_ID, targetType: "AWS_ACCOUNT", }); } }