mirror of
https://github.com/Sea-Haven-Industries/seahaven-org-baseline.git
synced 2026-09-30 06:53:17 +00:00
The policy-check role trust now matches pull request and merge queue subjects. A failed assume must fail the job instead of skipping ValidatePolicy and CheckNoNewAccess. Co-authored-by: Cursor Agent <cursoragent@cursor.com> Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com>
52 lines
1.6 KiB
YAML
52 lines
1.6 KiB
YAML
name: CI
|
|
on:
|
|
pull_request:
|
|
branches: [main]
|
|
merge_group:
|
|
|
|
permissions:
|
|
contents: read
|
|
|
|
jobs:
|
|
ci:
|
|
uses: Sea-Haven-Industries/.github/.github/workflows/ci-typescript-cdk.yaml@e5691d8a7f96ac4d5a841a82975ff0a4354d53ac # v1.0.7
|
|
with:
|
|
node-version: "24"
|
|
|
|
iam-policy-check:
|
|
runs-on: ubuntu-latest
|
|
timeout-minutes: 30
|
|
permissions:
|
|
id-token: write
|
|
contents: read
|
|
steps:
|
|
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
|
with:
|
|
fetch-depth: 0
|
|
|
|
- uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0
|
|
with:
|
|
node-version: "24"
|
|
cache: npm
|
|
|
|
- name: Install dependencies
|
|
run: npm ci
|
|
|
|
- name: Synthesize organization policies
|
|
run: npx cdk synth org-governance -o cdk.out --quiet
|
|
|
|
- name: Synthesize base-branch organization policies
|
|
run: |
|
|
git fetch origin main
|
|
git worktree add --detach /tmp/iam-base origin/main
|
|
npm ci --prefix /tmp/iam-base
|
|
(cd /tmp/iam-base && npx cdk synth org-governance -o /tmp/iam-base-out --quiet)
|
|
|
|
- name: Configure AWS credentials
|
|
uses: aws-actions/configure-aws-credentials@e1253824e5c10ff9df46874f81ed3ec929e19cfd # v6.3.0
|
|
with:
|
|
role-to-assume: arn:aws:iam::328440206208:role/githubdeploy-seahaven-org-baseline-policy-check
|
|
aws-region: us-east-1 # pragma: allowlist secret
|
|
|
|
- name: Check IAM policies
|
|
run: python3 scripts/check_iam_policies.py --cdk-out cdk.out --base-cdk-out /tmp/iam-base-out --base-repo /tmp/iam-base --self-test
|