mirror of
https://github.com/Sea-Haven-Industries/seahaven-org-baseline.git
synced 2026-10-03 20:03:13 +00:00
Prod HCP exec roles for seahaven-site now live in the same stack as payments-dashboard so role ownership is one stack.
1520 lines
71 KiB
YAML
1520 lines
71 KiB
YAML
AWSTemplateFormatVersion: "2010-09-09"
|
|
Description: >-
|
|
Per-account HCP Terraform deploy substrate for Sea Haven Industries:
|
|
the app.terraform.io OIDC identity provider and the shared boundary-gated
|
|
IAM guardrail policy used by prod/dev apply roles, plus exact per-workspace
|
|
role pairs appended at each stack's migration time. External-dev SHOC roles
|
|
use environment-scoped inline policies instead of the shared IAM manager.
|
|
|
|
# PROVENANCE / DESIGN SOURCE
|
|
# Authored fresh 2026-07-30 (the mgmt Terraform POC's CLI-created provider and
|
|
# hcptf-* roles were rolled back the same day, so there is no deployed source
|
|
# to vendor). HcptfIamManagementPolicy DERIVES FROM the reviewed
|
|
# seahaven-cfn-exec-iam-management pattern in
|
|
# lib/deploy-substrate/deploy-substrate.template.yaml (boundary-gated
|
|
# CreateRole/AttachRolePolicy/PutRolePolicy/PutRolePermissionsBoundary +
|
|
# DenyBoundaryTampering / DenyBoundaryPolicyEdit / DenySelfMutation) but is
|
|
# DELIBERATELY STRICTER — it is NOT a byte-identical mirror. Do not "reconcile"
|
|
# the two by copying this file's statements back, or vice versa; the divergences
|
|
# below are load-bearing and were required by the 2026-07-30 security review
|
|
# (findings C1-C5, one confirmed critical + one high):
|
|
#
|
|
# 1. ROLE PATH SCOPING (review finding C2). The SAM copy's Resource
|
|
# `role/*` on the boundary-gated statements is justified there by SAM
|
|
# auto-generating execution roles at path / with no settable RolePath —
|
|
# a path condition would break every SAM deploy. THAT RATIONALE DOES NOT
|
|
# TRANSFER: Terraform's aws_iam_role supports `path` and `name_prefix`.
|
|
# So every role-WRITE statement here is scoped to the Terraform-owned path
|
|
# `role/tf-managed/*`. Terraform configs MUST set path = "/tf-managed/" on
|
|
# every role they create; a role created anywhere else is denied. The path
|
|
# is deliberately NOT `hcptf-*`, which would collide with the substrate's
|
|
# own hcptf-* apply/plan roles under DenySelfMutation's wildcard.
|
|
# 2. READ AND WRITE SPLIT (review findings C1, C3, C4). The SAM copy's
|
|
# IAMRoleReadAndDelete grants iam:UpdateAssumeRolePolicy / DeleteRole /
|
|
# DetachRolePolicy / DeleteRolePolicy / UpdateRole on Resource "*"
|
|
# unconditioned — a confirmed privilege-escalation primitive (repoint the
|
|
# AdministratorAccess CDK bootstrap role's trust policy, then assume it
|
|
# cross-account) that DenySelfMutation's three name patterns do not cover.
|
|
# Here those actions are split: reads stay on "*" (Terraform data sources
|
|
# need them), every destructive/mutating action is confined to
|
|
# `role/tf-managed/*`. This closes the escalation at the root instead of
|
|
# chasing it with a denylist.
|
|
# 3. PASSROLE SCOPING (review finding C5). The SAM copy passes any role to
|
|
# Lambda (its comment claims SAM-role scoping the Resource does not
|
|
# express). Here PassRole is confined to `role/tf-managed/*`, so one
|
|
# workspace cannot attach another workspace's execution role to a function
|
|
# it controls — that path performs no IAM write and would otherwise evade
|
|
# every boundary gate and Deny in this document.
|
|
# 4. DENYSELFMUTATION SCOPE. Extended beyond the substrate's own principals to
|
|
# cdk-hnb659fds-* (AdministratorAccess bootstrap roles),
|
|
# OrganizationAccountAccessRole, and seahaven-* (detective-control roles
|
|
# such as the Config recorder role, which no SCP on prod/nonprod protects
|
|
# from iam:DeleteRole). Defense in depth behind the path scoping above.
|
|
#
|
|
# The SAM copy retains its adjudicated accepted risks because SAM's constraints
|
|
# are real; this file has no such excuse. KNOWN OPEN ITEM (pre-existing, not
|
|
# introduced here): the org's ProtectPrivilegedRoles SCP encodes exactly the
|
|
# protection in (4) but is attached ONLY to the security OU — extending it to
|
|
# prod/nonprod is the durable org-level fix and is tracked separately.
|
|
#
|
|
# COUPLING (frozen, PLAT-143/PLAT-149): the enumerated StringEquals list below
|
|
# is the last prod/dev HCP allow-list this document will carry. Do not append
|
|
# another seahaven-lambda-execution-boundary-<workload> ARN here. New HCP
|
|
# Lambda ceilings are policy/tf-managed/<stack> created by hcptf-bootstrap
|
|
# (CLI, PLAT-145). CreatePolicy lives only on that bootstrap role. Do not
|
|
# put ArnLike on this list, and do not add ArnLike to the SAM copy in
|
|
# deploy-substrate (PLAT-52 AC1: githubdeploy-seahaven-org-baseline can
|
|
# CreatePolicy via CFN). Existing eight workloads keep these ARNs until their
|
|
# consumer Terraform imports detach seahaven-hcptf-iam-management and this
|
|
# stack is deleted in prod/dev (PLAT-147). External-dev SHOC roles below do
|
|
# not attach this policy.
|
|
#
|
|
# SIZE BUDGET: this document is at the 6,144-character wall (4693 compact /
|
|
# 10 statements after eight workload ARNs). That accumulator is why prod/dev
|
|
# per-workspace IAM is leaving this file. Do not grow it.
|
|
#
|
|
# PER-WORKSPACE ROLE ACCUMULATOR — CLOSED FOR PROD/DEV
|
|
# Do not append new hcptf-<stack> pairs for prod or dev. App Terraform owns
|
|
# those roles (PLAT-144/PLAT-146). The six imported prod pairs are removed
|
|
# here. Their previous DeletionPolicy is Retain, so CloudFormation forgets
|
|
# them (PLAT-147). hcptf-sh-openswe-traces was already forgotten.
|
|
# seahaven-site lives in seahaven-hcptf. External-dev
|
|
# SHOC roles below remain in this template (PLAT-148). All remaining subs are
|
|
# exact StringEquals (never StringLike, never a wildcarded run_phase).
|
|
#
|
|
# This template is deployed via lib/terraform-substrate-stack.ts
|
|
# (cloudformation-include) as stack seahaven-terraform-substrate, once per
|
|
# member account that hosts Terraform-managed workloads (currently
|
|
# seahaven-prod 011934824531, seahaven-dev 710827005802, and external-dev
|
|
# 396287094661; NEVER mgmt — mgmt stays SAM until its stacks migrate out).
|
|
|
|
Parameters:
|
|
CreateOIDCProvider:
|
|
Type: String
|
|
Default: "true"
|
|
AllowedValues: ["true", "false"]
|
|
Description: >-
|
|
Set to false if the app.terraform.io OIDC provider already exists in this
|
|
account. An account holds exactly ONE provider per URL, so an unconditional
|
|
create collides. Because the provider is Retain, a FIRST-create rollback
|
|
(caused by any other resource in this stack failing) leaves the provider
|
|
behind as an orphan and the stack in ROLLBACK_COMPLETE — which cannot be
|
|
updated. Recovery: delete the stack, then either
|
|
`aws iam delete-open-id-connect-provider --open-id-connect-provider-arn
|
|
arn:aws:iam::<acct>:oidc-provider/app.terraform.io` before retrying, or
|
|
redeploy with this parameter false. Same idempotency affordance the sibling
|
|
deploy-substrate template carries for the GitHub provider.
|
|
EnableShocBackendPocRoles:
|
|
Type: String
|
|
Default: "false"
|
|
AllowedValues: ["true", "false"]
|
|
Description: >-
|
|
External-dev tf-poc gate. Keep false for the base-stack create, then set
|
|
true on the reviewed normal update that creates the new tf-poc role pair.
|
|
EnableShocBackendLiveRoles:
|
|
Type: String
|
|
Default: "false"
|
|
AllowedValues: ["true", "false"]
|
|
Description: >-
|
|
External-dev live-role collision guard. Keep false until the four existing
|
|
dev/staging roles have been removed from Terraform state with destroy=false.
|
|
Set true only in the CloudFormation IMPORT change set that adopts them.
|
|
|
|
Conditions:
|
|
ShouldCreateOIDCProvider: !Equals [!Ref CreateOIDCProvider, "true"]
|
|
# Per-workspace hcptf-* roles for afi-backup-monitor-prod (PLAT-56) must only
|
|
# exist in seahaven-prod. The same template deploys to seahaven-dev; creating
|
|
# prod-workspace trust there would leave dead credentials in the wrong account.
|
|
IsProdAccount: !Equals [!Ref "AWS::AccountId", "011934824531"]
|
|
IsExternalDevAccount: !Equals [!Ref "AWS::AccountId", "396287094661"]
|
|
IsSharedIamManagementAccount: !Or
|
|
- !Equals [!Ref "AWS::AccountId", "011934824531"]
|
|
- !Equals [!Ref "AWS::AccountId", "710827005802"]
|
|
ShouldManageShocBackendPocRoles: !And
|
|
- !Condition IsExternalDevAccount
|
|
- !Equals [!Ref EnableShocBackendPocRoles, "true"]
|
|
ShouldManageShocBackendLiveRoles: !And
|
|
- !Condition IsExternalDevAccount
|
|
- !Equals [!Ref EnableShocBackendLiveRoles, "true"]
|
|
|
|
Resources:
|
|
|
|
# ---------------------------------------------------------------------------
|
|
# HCP Terraform OIDC provider
|
|
#
|
|
# Created by default: Phase-0 checks (2026-07-30) confirmed neither prod nor
|
|
# dev has an app.terraform.io provider (the mgmt POC's copy was deleted in the
|
|
# same-day rollback and never existed in the member accounts). An account
|
|
# holds exactly ONE provider per URL — see the parameter above for the
|
|
# first-create rollback trap this condition exists to make recoverable.
|
|
# ---------------------------------------------------------------------------
|
|
TerraformCloudOIDCProvider:
|
|
Type: AWS::IAM::OIDCProvider
|
|
Condition: ShouldCreateOIDCProvider
|
|
Properties:
|
|
Url: https://app.terraform.io
|
|
ClientIdList:
|
|
# Default audience of HCP Terraform dynamic provider credentials
|
|
# (TFC_AWS_WORKLOAD_IDENTITY_AUDIENCE). Trust policies pin this via
|
|
# StringEquals on app.terraform.io:aud.
|
|
- aws.workload.identity
|
|
ThumbprintList:
|
|
# AWS ignores thumbprints for issuers signed by a trusted root CA
|
|
# (app.terraform.io qualifies) and secures trust via the CA bundle;
|
|
# the property is populated because CloudFormation requires a value.
|
|
# This is the thumbprint HashiCorp's own AWS setup documentation uses.
|
|
- 9e99a48a9960b14926bb7f3b02e22da2b0ab7280
|
|
# Every future hcptf-* role trusts this provider. Retain so deleting the
|
|
# stack can never delete the account's Terraform federation anchor out
|
|
# from under live workspaces.
|
|
DeletionPolicy: Retain
|
|
UpdateReplacePolicy: Retain
|
|
|
|
# ---------------------------------------------------------------------------
|
|
# Shared boundary-gated IAM guardrail policy (attached managed policy)
|
|
#
|
|
# Attached by every per-workspace Terraform APPLY role (hcptf-<stack>);
|
|
# NEVER by plan roles (hcptf-<stack>-plan are read-only and hold no IAM
|
|
# writes at all). Defined once here so all apply roles carry the identical
|
|
# reviewed escalation control instead of per-role copies that can drift.
|
|
#
|
|
# PRIMARY ESCALATION CONTROL (same design as INFRA-97 on the SAM side):
|
|
# every iam:CreateRole / AttachRolePolicy / PutRolePolicy is conditioned on
|
|
# the target role carrying seahaven-lambda-execution-boundary, so a role
|
|
# created by a Terraform apply can never exceed the boundary ceiling. The
|
|
# POC security review confirmed the unconditioned alternative is critical:
|
|
# iam:PutRolePolicy on Lambda exec roles + lambda:UpdateFunctionCode reads
|
|
# every secret in the account.
|
|
# ---------------------------------------------------------------------------
|
|
HcptfIamManagementPolicy:
|
|
Type: AWS::IAM::ManagedPolicy
|
|
Condition: IsSharedIamManagementAccount
|
|
Properties:
|
|
# Fixed name: future hcptf-* roles reference it by ARN, and a rename
|
|
# would detach-and-replace mid-update. Treat a rename as a coordinated
|
|
# migration, not an edit.
|
|
ManagedPolicyName: seahaven-hcptf-iam-management
|
|
Description: >-
|
|
Boundary-gated IAM role lifecycle for per-workspace Terraform apply
|
|
roles (hcptf-*), plus the explicit Deny backstops that keep the
|
|
permissions boundary from being detached or rewritten and the deploy
|
|
substrates' own principals from being mutated. Mirrors
|
|
seahaven-cfn-exec-iam-management; reconcile changes across both.
|
|
PolicyDocument:
|
|
Version: "2012-10-17"
|
|
Statement:
|
|
# Create role — MUST attach boundary AND land on the Terraform-owned
|
|
# path. Two independent gates: the boundary caps what the role can do,
|
|
# the path caps which roles this policy can touch at all. Terraform
|
|
# configs set path = "/tf-managed/" on every aws_iam_role.
|
|
- Sid: IAMCreateRoleWithBoundary
|
|
Effect: Allow
|
|
Action:
|
|
- iam:CreateRole
|
|
Resource:
|
|
- !Sub "arn:aws:iam::${AWS::AccountId}:role/tf-managed/*"
|
|
Condition:
|
|
StringEquals:
|
|
"iam:PermissionsBoundary": &acceptableLambdaBoundaries
|
|
- !Sub "arn:aws:iam::${AWS::AccountId}:policy/seahaven-lambda-execution-boundary"
|
|
- !Sub "arn:aws:iam::${AWS::AccountId}:policy/seahaven-lambda-execution-boundary-afi-backup-monitor"
|
|
- !Sub "arn:aws:iam::${AWS::AccountId}:policy/seahaven-lambda-execution-boundary-front-integrations"
|
|
- !Sub "arn:aws:iam::${AWS::AccountId}:policy/seahaven-lambda-execution-boundary-procurement-ingest"
|
|
- !Sub "arn:aws:iam::${AWS::AccountId}:policy/seahaven-lambda-execution-boundary-meal-order-manager"
|
|
- !Sub "arn:aws:iam::${AWS::AccountId}:policy/seahaven-lambda-execution-boundary-seahaven-site"
|
|
- !Sub "arn:aws:iam::${AWS::AccountId}:policy/seahaven-lambda-execution-boundary-seahaven-door-unlock-api"
|
|
- !Sub "arn:aws:iam::${AWS::AccountId}:policy/seahaven-lambda-execution-boundary-paychex-integrations"
|
|
|
|
# Attach managed policies — MUST have boundary already on role
|
|
- Sid: IAMAttachPolicyWithBoundary
|
|
Effect: Allow
|
|
Action:
|
|
- iam:AttachRolePolicy
|
|
Resource:
|
|
- !Sub "arn:aws:iam::${AWS::AccountId}:role/tf-managed/*"
|
|
Condition:
|
|
StringEquals:
|
|
"iam:PermissionsBoundary": *acceptableLambdaBoundaries
|
|
|
|
# Put inline policy — MUST have boundary already on role
|
|
- Sid: IAMPutRolePolicyWithBoundary
|
|
Effect: Allow
|
|
Action:
|
|
- iam:PutRolePolicy
|
|
Resource:
|
|
- !Sub "arn:aws:iam::${AWS::AccountId}:role/tf-managed/*"
|
|
Condition:
|
|
StringEquals:
|
|
"iam:PermissionsBoundary": *acceptableLambdaBoundaries
|
|
|
|
# Boundary management — SET only, never DELETE. For a delete, the
|
|
# iam:PermissionsBoundary condition key resolves to the boundary
|
|
# CURRENTLY on the target role, so a StringEquals grant would match
|
|
# exactly the roles the gate protects and self-defeat it (verified
|
|
# live against the mgmt SAM copy 2026-07-27). Terraform never needs
|
|
# the delete: it SETS the boundary on roles it creates, and destroy
|
|
# calls DeleteRole.
|
|
# Path-scoped as well as boundary-pinned: the condition constrains WHICH
|
|
# boundary may be set, not WHICH role receives it. Unscoped (as in the
|
|
# SAM copy) this is a one-way denial-of-service — applying the Lambda
|
|
# runtime boundary to the CDK bootstrap execution role collapses its
|
|
# permissions, and DenyBoundaryTampering below then blocks removal by
|
|
# this same principal (2026-07-30 review finding C3).
|
|
- Sid: IAMPutPermissionsBoundary
|
|
Effect: Allow
|
|
Action:
|
|
- iam:PutRolePermissionsBoundary
|
|
Resource:
|
|
- !Sub "arn:aws:iam::${AWS::AccountId}:role/tf-managed/*"
|
|
Condition:
|
|
StringEquals:
|
|
"iam:PermissionsBoundary": *acceptableLambdaBoundaries
|
|
|
|
# Explicit Deny backstop (AWS's NoBoundaryPolicyEdit/NoBoundaryDelete
|
|
# delegation pattern). A Deny is required, not merely omitting the
|
|
# Allow — any future Allow added to an apply role silently reopens
|
|
# the escalation otherwise.
|
|
- Sid: DenyBoundaryTampering
|
|
Effect: Deny
|
|
Action:
|
|
- iam:DeleteRolePermissionsBoundary
|
|
- iam:DeleteUserPermissionsBoundary
|
|
Resource:
|
|
- !Sub "arn:aws:iam::${AWS::AccountId}:role/*"
|
|
- !Sub "arn:aws:iam::${AWS::AccountId}:user/*"
|
|
|
|
# Whole seahaven-* policy family: this policy carries the Denies, so
|
|
# it is a higher-value target than the boundary it protects. Safe to
|
|
# scope broadly — no Terraform stack manages a seahaven-* managed
|
|
# policy, and apply roles hold no iam:CreatePolicy.
|
|
- Sid: DenyBoundaryPolicyEdit
|
|
Effect: Deny
|
|
Action:
|
|
- iam:CreatePolicyVersion
|
|
- iam:SetDefaultPolicyVersion
|
|
- iam:DeletePolicyVersion
|
|
- iam:DeletePolicy
|
|
Resource:
|
|
- !Sub "arn:aws:iam::${AWS::AccountId}:policy/seahaven-*"
|
|
|
|
# Self-protection for BOTH deploy substrates' principals. Without
|
|
# this the control is one API call from being undone —
|
|
# IAMRoleReadAndDelete below grants iam:DetachRolePolicy on
|
|
# Resource "*" unconditioned, so an apply role could detach this
|
|
# very policy from itself. Scope covers the Terraform substrate's
|
|
# own roles (hcptf-*) AND the GitHub Actions substrate's
|
|
# (github-cfn-execution-role, githubdeploy-*): a Terraform apply
|
|
# never legitimately manages any of them — hcptf-* roles are
|
|
# managed by THIS stack via the CDK bootstrap execution role, the
|
|
# GitHub-side roles by their own substrate/onboarding — so the Deny
|
|
# costs nothing operationally and closes the same
|
|
# UpdateAssumeRolePolicy-on-* repoint risk the SAM-side review
|
|
# flagged, for every substrate principal reachable from this path.
|
|
- Sid: DenySelfMutation
|
|
Effect: Deny
|
|
Action:
|
|
- iam:AttachRolePolicy
|
|
- iam:DeleteRole
|
|
- iam:DeleteRolePolicy
|
|
- iam:DeleteRolePermissionsBoundary
|
|
- iam:DetachRolePolicy
|
|
- iam:PutRolePolicy
|
|
- iam:PutRolePermissionsBoundary
|
|
- iam:UpdateAssumeRolePolicy
|
|
- iam:UpdateRole
|
|
- iam:UpdateRoleDescription
|
|
Resource:
|
|
- !Sub "arn:aws:iam::${AWS::AccountId}:role/hcptf-*"
|
|
- !Sub "arn:aws:iam::${AWS::AccountId}:role/github-cfn-execution-role"
|
|
- !Sub "arn:aws:iam::${AWS::AccountId}:role/githubdeploy-*"
|
|
# Extended beyond the SAM copy's three patterns (2026-07-30 review
|
|
# findings C1/C3/C4). cdk-hnb659fds-* carries AdministratorAccess
|
|
# and deploys this very stack; OrganizationAccountAccessRole is the
|
|
# org break-glass path; seahaven-* covers detective-control roles
|
|
# (e.g. the Config recorder role) that the protect-security-baseline
|
|
# SCP does NOT shield from iam:DeleteRole. Defense in depth — the
|
|
# path scoping on the write statements is the primary control.
|
|
- !Sub "arn:aws:iam::${AWS::AccountId}:role/cdk-hnb659fds-*"
|
|
- !Sub "arn:aws:iam::${AWS::AccountId}:role/OrganizationAccountAccessRole"
|
|
- !Sub "arn:aws:iam::${AWS::AccountId}:role/seahaven-*"
|
|
|
|
# READ-ONLY on every role/policy in the account. Terraform data sources
|
|
# and refresh legitimately need to read arbitrary roles; none of these
|
|
# actions can modify anything, so Resource "*" is safe here.
|
|
- Sid: IAMReadOnly
|
|
Effect: Allow
|
|
Action:
|
|
- iam:GetRole
|
|
- iam:GetRolePolicy
|
|
- iam:ListAttachedRolePolicies
|
|
- iam:ListRolePolicies
|
|
- iam:ListRoles
|
|
- iam:GetPolicy
|
|
- iam:GetPolicyVersion
|
|
- iam:ListPolicies
|
|
- iam:ListPolicyVersions
|
|
Resource: "*"
|
|
|
|
# DESTRUCTIVE / MUTATING role actions — confined to the Terraform-owned
|
|
# path. The SAM copy grants these on Resource "*" unconditioned, which
|
|
# the 2026-07-30 review confirmed as a critical escalation primitive
|
|
# (finding C1): iam:UpdateAssumeRolePolicy on "*" lets the principal
|
|
# repoint the AdministratorAccess CDK bootstrap role's trust policy to
|
|
# an external account and assume it. Path scoping closes that at the
|
|
# root rather than enumerating protected names.
|
|
- Sid: IAMRoleWriteScoped
|
|
Effect: Allow
|
|
Action:
|
|
- iam:DeleteRole
|
|
- iam:DeleteRolePolicy
|
|
- iam:DetachRolePolicy
|
|
- iam:TagRole
|
|
- iam:UntagRole
|
|
- iam:UpdateRole
|
|
- iam:UpdateRoleDescription
|
|
- iam:UpdateAssumeRolePolicy
|
|
Resource:
|
|
- !Sub "arn:aws:iam::${AWS::AccountId}:role/tf-managed/*"
|
|
|
|
# PassRole — Terraform passes the execution roles it created (which are
|
|
# on the tf-managed path, boundary-gated above) to the Lambda service.
|
|
# Path-scoped, not role/*: unscoped, one workspace's apply role could
|
|
# attach ANOTHER workspace's or a SAM stack's execution role to a
|
|
# function it controls and run arbitrary code as that identity — a path
|
|
# that performs no IAM write and so evades every boundary gate and Deny
|
|
# in this document (2026-07-30 review finding C5). Other target services
|
|
# (scheduler, apigateway, ...) are NOT granted: a stack that needs one
|
|
# adds a scoped PassRole statement to its own apply role at migration.
|
|
- Sid: IAMPassRole
|
|
Effect: Allow
|
|
Action:
|
|
- iam:PassRole
|
|
Resource:
|
|
- !Sub "arn:aws:iam::${AWS::AccountId}:role/tf-managed/*"
|
|
Condition:
|
|
StringEquals:
|
|
"iam:PassedToService": "lambda.amazonaws.com"
|
|
|
|
# ---------------------------------------------------------------------------
|
|
# SHOC backend GitHub deployment permissions boundaries (external-dev only)
|
|
#
|
|
# These are ceilings for the dev and staging githubdeploy roles, not grants.
|
|
# Existing dev/staging roles receive them through a separately approved
|
|
# administrator/CDK action before HCP import.
|
|
# ---------------------------------------------------------------------------
|
|
ShocBackendDevDeployBoundary:
|
|
Type: AWS::IAM::ManagedPolicy
|
|
Condition: IsExternalDevAccount
|
|
DeletionPolicy: Retain
|
|
UpdateReplacePolicy: Retain
|
|
Properties:
|
|
ManagedPolicyName: shoc-backend-dev-deploy-boundary
|
|
Description: Maximum deployment permissions for githubdeploy-shoc-backend-dev.
|
|
PolicyDocument:
|
|
Version: "2012-10-17"
|
|
Statement:
|
|
- Sid: DescribeDeploymentResources
|
|
Effect: Allow
|
|
Action:
|
|
- autoscaling:Describe*
|
|
- ec2:Describe*
|
|
- elasticbeanstalk:DescribeApplicationVersions
|
|
- elasticbeanstalk:DescribeEnvironments
|
|
- elasticbeanstalk:DescribeEvents
|
|
- elasticloadbalancing:Describe*
|
|
Resource: "*"
|
|
- Sid: CreateApplicationVersion
|
|
Effect: Allow
|
|
Action: elasticbeanstalk:CreateApplicationVersion
|
|
Resource:
|
|
- arn:aws:elasticbeanstalk:us-east-1:396287094661:application/shoc-backend
|
|
- arn:aws:elasticbeanstalk:us-east-1:396287094661:applicationversion/shoc-backend/*
|
|
- Sid: UpdateDevEnvironment
|
|
Effect: Allow
|
|
Action: elasticbeanstalk:UpdateEnvironment
|
|
Resource: arn:aws:elasticbeanstalk:us-east-1:396287094661:environment/shoc-backend/shoc-backend-dev
|
|
- Sid: ManageDevEnvironmentStack
|
|
Effect: Allow
|
|
Action:
|
|
- cloudformation:CancelUpdateStack
|
|
- cloudformation:DescribeStackEvents
|
|
- cloudformation:DescribeStackResource
|
|
- cloudformation:DescribeStackResources
|
|
- cloudformation:DescribeStacks
|
|
- cloudformation:GetTemplate
|
|
- cloudformation:ListStackResources
|
|
- cloudformation:UpdateStack
|
|
Resource: arn:aws:cloudformation:us-east-1:396287094661:stack/awseb-e-hehnrqjjrt-stack/*
|
|
- Sid: ManageDevEnvironmentAsg
|
|
Effect: Allow
|
|
Action:
|
|
- autoscaling:PutNotificationConfiguration
|
|
- autoscaling:ResumeProcesses
|
|
- autoscaling:SuspendProcesses
|
|
Resource: arn:aws:autoscaling:us-east-1:396287094661:autoScalingGroup:*:autoScalingGroupName/awseb-e-hehnrqjjrt-stack-*
|
|
- Sid: LegacyBeanstalkObjects
|
|
Effect: Allow
|
|
Action:
|
|
- s3:Delete*
|
|
- s3:Get*
|
|
- s3:Put*
|
|
Resource: arn:aws:s3:::elasticbeanstalk-*/*
|
|
- Sid: LegacyBeanstalkBuckets
|
|
Effect: Allow
|
|
Action:
|
|
- s3:GetBucket*
|
|
- s3:ListBucket
|
|
- s3:PutBucketOwnershipControls
|
|
- s3:PutBucketPolicy
|
|
- s3:PutBucketPublicAccessBlock
|
|
Resource: arn:aws:s3:::elasticbeanstalk-*
|
|
- Sid: ReadDeployParameters
|
|
Effect: Allow
|
|
Action:
|
|
- ssm:GetParameter
|
|
- ssm:GetParameters
|
|
Resource: arn:aws:ssm:us-east-1:396287094661:parameter/shoc-backend/dev/deploy/*
|
|
|
|
ShocBackendStagingDeployBoundary:
|
|
Type: AWS::IAM::ManagedPolicy
|
|
Condition: IsExternalDevAccount
|
|
DeletionPolicy: Retain
|
|
UpdateReplacePolicy: Retain
|
|
Properties:
|
|
ManagedPolicyName: shoc-backend-staging-deploy-boundary
|
|
Description: Maximum deployment permissions for githubdeploy-shoc-backend-staging.
|
|
PolicyDocument:
|
|
Version: "2012-10-17"
|
|
Statement:
|
|
- Sid: DescribeDeploymentResources
|
|
Effect: Allow
|
|
Action:
|
|
- autoscaling:Describe*
|
|
- ec2:Describe*
|
|
- elasticbeanstalk:DescribeApplicationVersions
|
|
- elasticbeanstalk:DescribeEnvironments
|
|
- elasticbeanstalk:DescribeEvents
|
|
- elasticloadbalancing:Describe*
|
|
Resource: "*"
|
|
- Sid: CreateApplicationVersion
|
|
Effect: Allow
|
|
Action: elasticbeanstalk:CreateApplicationVersion
|
|
Resource:
|
|
- arn:aws:elasticbeanstalk:us-east-1:396287094661:application/shoc-backend
|
|
- arn:aws:elasticbeanstalk:us-east-1:396287094661:applicationversion/shoc-backend/*
|
|
- Sid: UpdateStagingEnvironment
|
|
Effect: Allow
|
|
Action: elasticbeanstalk:UpdateEnvironment
|
|
Resource: arn:aws:elasticbeanstalk:us-east-1:396287094661:environment/shoc-backend/shoc-backend-staging
|
|
- Sid: ManageStagingEnvironmentStack
|
|
Effect: Allow
|
|
Action:
|
|
- cloudformation:CancelUpdateStack
|
|
- cloudformation:DescribeStackEvents
|
|
- cloudformation:DescribeStackResource
|
|
- cloudformation:DescribeStackResources
|
|
- cloudformation:DescribeStacks
|
|
- cloudformation:GetTemplate
|
|
- cloudformation:ListStackResources
|
|
- cloudformation:UpdateStack
|
|
Resource: arn:aws:cloudformation:us-east-1:396287094661:stack/awseb-e-6c9m4vb62z-stack/*
|
|
- Sid: ManageStagingEnvironmentAsg
|
|
Effect: Allow
|
|
Action:
|
|
- autoscaling:PutNotificationConfiguration
|
|
- autoscaling:ResumeProcesses
|
|
- autoscaling:SuspendProcesses
|
|
Resource: arn:aws:autoscaling:us-east-1:396287094661:autoScalingGroup:*:autoScalingGroupName/awseb-e-6c9m4vb62z-stack-*
|
|
- Sid: UploadApplicationVersion
|
|
Effect: Allow
|
|
Action:
|
|
- s3:PutObject
|
|
- s3:PutObjectAcl
|
|
- s3:PutObjectVersionAcl
|
|
- s3:GetObject
|
|
- s3:GetObjectAcl
|
|
- s3:GetObjectVersion
|
|
- s3:GetObjectVersionAcl
|
|
- s3:DeleteObject
|
|
Resource:
|
|
- arn:aws:s3:::elasticbeanstalk-us-east-1-396287094661/shoc-backend/*
|
|
- arn:aws:s3:::elasticbeanstalk-us-east-1-396287094661/resources/_runtime/_embedded_extensions/shoc-backend/*
|
|
- arn:aws:s3:::elasticbeanstalk-us-east-1-396287094661/resources/environments/e-6c9m4vb62z/*
|
|
- Sid: UseBeanstalkBucket
|
|
Effect: Allow
|
|
Action:
|
|
- s3:GetBucketLocation
|
|
- s3:ListBucket
|
|
- s3:GetBucketPolicy
|
|
- s3:GetBucketAcl
|
|
- s3:GetBucketVersioning
|
|
- s3:GetBucketOwnershipControls
|
|
Resource: arn:aws:s3:::elasticbeanstalk-us-east-1-396287094661
|
|
- Sid: ReadDeployParameters
|
|
Effect: Allow
|
|
Action:
|
|
- ssm:GetParameter
|
|
- ssm:GetParameters
|
|
Resource: arn:aws:ssm:us-east-1:396287094661:parameter/shoc-backend/staging/deploy/*
|
|
|
|
# Dedicated runtime ceilings preserve the non-AI portions of
|
|
# AWSElasticBeanstalkWebTier while removing its 2026 Bedrock/Marketplace
|
|
# additions. All S3/log/health resources are pinned to this account and the
|
|
# exact SHOC environment; X-Ray APIs do not support resource scoping.
|
|
ShocBackendDevRuntimeBoundary:
|
|
Type: AWS::IAM::ManagedPolicy
|
|
Condition: IsExternalDevAccount
|
|
DeletionPolicy: Retain
|
|
UpdateReplacePolicy: Retain
|
|
Properties:
|
|
ManagedPolicyName: shoc-backend-dev-runtime-boundary
|
|
Description: Maximum runtime permissions for the SHOC backend dev instance role.
|
|
PolicyDocument:
|
|
Version: "2012-10-17"
|
|
Statement:
|
|
- Sid: ReadAppConfig
|
|
Effect: Allow
|
|
Action: secretsmanager:GetSecretValue
|
|
Resource: arn:aws:secretsmanager:us-east-1:396287094661:secret:shoc/dev/app-config-*
|
|
- Sid: ReadWebhookSecret
|
|
Effect: Allow
|
|
Action:
|
|
- secretsmanager:DescribeSecret
|
|
- secretsmanager:GetSecretValue
|
|
Resource: arn:aws:secretsmanager:us-east-1:011934824531:secret:workorder-ingest/shoc-webhook-hmac-puYTcB
|
|
- Sid: DecryptWebhookSecret
|
|
Effect: Allow
|
|
Action: kms:Decrypt
|
|
Resource: arn:aws:kms:us-east-1:011934824531:key/d10fd1f0-a61a-4405-8568-85e9fd11ba18
|
|
Condition:
|
|
StringEquals:
|
|
"kms:ViaService": secretsmanager.us-east-1.amazonaws.com
|
|
- Sid: AssumeDynamoReader
|
|
Effect: Allow
|
|
Action: sts:AssumeRole
|
|
Resource: arn:aws:iam::328440206208:role/shoc-dynamo-reader
|
|
- Sid: ElasticBeanstalkBucket
|
|
Effect: Allow
|
|
Action:
|
|
- s3:Get*
|
|
- s3:List*
|
|
- s3:PutObject
|
|
Resource:
|
|
- arn:aws:s3:::elasticbeanstalk-us-east-1-396287094661
|
|
- arn:aws:s3:::elasticbeanstalk-us-east-1-396287094661/*
|
|
- Sid: ElasticBeanstalkHealth
|
|
Effect: Allow
|
|
Action: elasticbeanstalk:PutInstanceStatistics
|
|
Resource:
|
|
- arn:aws:elasticbeanstalk:us-east-1:396287094661:application/shoc-backend
|
|
- arn:aws:elasticbeanstalk:us-east-1:396287094661:environment/shoc-backend/shoc-backend-dev
|
|
- Sid: ElasticBeanstalkLogs
|
|
Effect: Allow
|
|
Action:
|
|
- logs:PutLogEvents
|
|
- logs:CreateLogStream
|
|
- logs:DescribeLogStreams
|
|
- logs:DescribeLogGroups
|
|
Resource: arn:aws:logs:us-east-1:396287094661:log-group:/aws/elasticbeanstalk/shoc-backend-dev*
|
|
- Sid: XRayTelemetry
|
|
Effect: Allow
|
|
Action:
|
|
- xray:PutTraceSegments
|
|
- xray:PutTelemetryRecords
|
|
- xray:GetSamplingRules
|
|
- xray:GetSamplingTargets
|
|
- xray:GetSamplingStatisticSummaries
|
|
Resource: "*"
|
|
|
|
ShocBackendStagingRuntimeBoundary:
|
|
Type: AWS::IAM::ManagedPolicy
|
|
Condition: IsExternalDevAccount
|
|
DeletionPolicy: Retain
|
|
UpdateReplacePolicy: Retain
|
|
Properties:
|
|
ManagedPolicyName: shoc-backend-staging-runtime-boundary
|
|
Description: Maximum runtime permissions for the SHOC backend staging instance role.
|
|
PolicyDocument:
|
|
Version: "2012-10-17"
|
|
Statement:
|
|
- Sid: ReadAppConfig
|
|
Effect: Allow
|
|
Action: secretsmanager:GetSecretValue
|
|
Resource: arn:aws:secretsmanager:us-east-1:396287094661:secret:shoc/staging/app-config-*
|
|
- Sid: ReadWebhookSecret
|
|
Effect: Allow
|
|
Action:
|
|
- secretsmanager:DescribeSecret
|
|
- secretsmanager:GetSecretValue
|
|
Resource: arn:aws:secretsmanager:us-east-1:011934824531:secret:workorder-ingest/shoc-webhook-hmac-puYTcB
|
|
- Sid: DecryptWebhookSecret
|
|
Effect: Allow
|
|
Action: kms:Decrypt
|
|
Resource: arn:aws:kms:us-east-1:011934824531:key/d10fd1f0-a61a-4405-8568-85e9fd11ba18
|
|
Condition:
|
|
StringEquals:
|
|
"kms:ViaService": secretsmanager.us-east-1.amazonaws.com
|
|
- Sid: ElasticBeanstalkBucket
|
|
Effect: Allow
|
|
Action:
|
|
- s3:Get*
|
|
- s3:List*
|
|
- s3:PutObject
|
|
Resource:
|
|
- arn:aws:s3:::elasticbeanstalk-us-east-1-396287094661
|
|
- arn:aws:s3:::elasticbeanstalk-us-east-1-396287094661/*
|
|
- Sid: ElasticBeanstalkHealth
|
|
Effect: Allow
|
|
Action: elasticbeanstalk:PutInstanceStatistics
|
|
Resource:
|
|
- arn:aws:elasticbeanstalk:us-east-1:396287094661:application/shoc-backend
|
|
- arn:aws:elasticbeanstalk:us-east-1:396287094661:environment/shoc-backend/shoc-backend-staging
|
|
- Sid: ElasticBeanstalkLogs
|
|
Effect: Allow
|
|
Action:
|
|
- logs:PutLogEvents
|
|
- logs:CreateLogStream
|
|
- logs:DescribeLogStreams
|
|
- logs:DescribeLogGroups
|
|
Resource: arn:aws:logs:us-east-1:396287094661:log-group:/aws/elasticbeanstalk/shoc-backend-staging*
|
|
- Sid: XRayTelemetry
|
|
Effect: Allow
|
|
Action:
|
|
- xray:PutTraceSegments
|
|
- xray:PutTelemetryRecords
|
|
- xray:GetSamplingRules
|
|
- xray:GetSamplingTargets
|
|
- xray:GetSamplingStatisticSummaries
|
|
Resource: "*"
|
|
|
|
# ---------------------------------------------------------------------------
|
|
# shoc-backend import/adoption rehearsal (external-dev only)
|
|
#
|
|
# These roles intentionally do not attach HcptfIamManagementPolicy. Its
|
|
# DenySelfMutation protects every githubdeploy-* role, while this rehearsal
|
|
# must adopt three exact githubdeploy roles. Each apply role instead carries
|
|
# an environment-scoped inline policy. No apply role can create/delete roles,
|
|
# change managed-policy attachments or boundaries, read/write secret
|
|
# values, or pass a role. Live apply roles may UpdateAssumeRolePolicy only
|
|
# on the matching githubdeploy-shoc-backend-{dev,staging} role so the
|
|
# GitHub OIDC job_workflow_ref seam can land. The POC gate controls its new
|
|
# pair independently; the live gate stays false until the four existing
|
|
# dev/staging roles enter through a CloudFormation IMPORT change set.
|
|
#
|
|
# The existing app.terraform.io provider is referenced by literal ARN. The
|
|
# stack instance sets CreateOIDCProvider=false, so external-dev never attempts
|
|
# to create the account-global provider.
|
|
# ---------------------------------------------------------------------------
|
|
HcptfShocBackendPocPlanRole:
|
|
Type: AWS::IAM::Role
|
|
Condition: ShouldManageShocBackendPocRoles
|
|
DeletionPolicy: Retain
|
|
UpdateReplacePolicy: Retain
|
|
Properties:
|
|
RoleName: hcptf-shoc-backend-tf-poc-plan
|
|
Description: Read-only HCP Terraform plan role for the SHOC backend import rehearsal.
|
|
PermissionsBoundary: arn:aws:iam::396287094661:policy/external-dev-execution-boundary
|
|
MaxSessionDuration: 3600
|
|
AssumeRolePolicyDocument:
|
|
Version: "2012-10-17"
|
|
Statement:
|
|
- Effect: Allow
|
|
Principal:
|
|
Federated: arn:aws:iam::396287094661:oidc-provider/app.terraform.io
|
|
Action: sts:AssumeRoleWithWebIdentity
|
|
Condition:
|
|
StringEquals:
|
|
"app.terraform.io:aud": aws.workload.identity
|
|
"app.terraform.io:sub": organization:seahaven:project:seahaven-external-dev:workspace:shoc-backend-tf-poc:run_phase:plan
|
|
Policies:
|
|
- &shocPocReadPolicy
|
|
PolicyName: shoc-backend-tf-poc-import-read
|
|
PolicyDocument:
|
|
Version: "2012-10-17"
|
|
Statement:
|
|
- Sid: CallerIdentity
|
|
Effect: Allow
|
|
Action: sts:GetCallerIdentity
|
|
Resource: "*"
|
|
- Sid: ReadExactIam
|
|
Effect: Allow
|
|
Action:
|
|
- iam:GetInstanceProfile
|
|
- iam:GetRole
|
|
- iam:GetRolePolicy
|
|
- iam:ListAttachedRolePolicies
|
|
- iam:ListInstanceProfileTags
|
|
- iam:ListInstanceProfilesForRole
|
|
- iam:ListRolePolicies
|
|
- iam:ListRoleTags
|
|
Resource:
|
|
- arn:aws:iam::396287094661:role/githubdeploy-shoc-backend-tf-poc
|
|
- arn:aws:iam::396287094661:role/shoc-backend-tf-poc
|
|
- arn:aws:iam::396287094661:instance-profile/shoc-backend-tf-poc
|
|
- arn:aws:iam::396287094661:role/shoc-eb-service-role
|
|
- Sid: ReadOidcProviders
|
|
Effect: Allow
|
|
Action: iam:GetOpenIDConnectProvider
|
|
Resource:
|
|
- arn:aws:iam::396287094661:oidc-provider/app.terraform.io
|
|
- arn:aws:iam::396287094661:oidc-provider/token.actions.githubusercontent.com
|
|
- Sid: ListOidcProviders
|
|
Effect: Allow
|
|
Action: iam:ListOpenIDConnectProviders
|
|
Resource: "*"
|
|
- Sid: ReadSharedInventory
|
|
Effect: Allow
|
|
Action:
|
|
- acm:ListCertificates
|
|
- autoscaling:DescribeAutoScalingGroups
|
|
- ec2:DescribeSecurityGroups
|
|
- ec2:DescribeSubnets
|
|
- ec2:DescribeVpcAttribute
|
|
- ec2:DescribeVpcs
|
|
- elasticbeanstalk:DescribeApplications
|
|
- elasticbeanstalk:DescribeConfigurationOptions
|
|
- elasticbeanstalk:DescribeConfigurationSettings
|
|
- elasticbeanstalk:DescribeEnvironmentResources
|
|
- elasticbeanstalk:DescribeEnvironments
|
|
- elasticbeanstalk:ListTagsForResource
|
|
- rds:DescribeDBInstances
|
|
- route53:ListHostedZonesByName
|
|
Resource: "*"
|
|
- Sid: ReadSharedCertificate
|
|
Effect: Allow
|
|
Action:
|
|
- acm:DescribeCertificate
|
|
- acm:ListTagsForCertificate
|
|
Resource: arn:aws:acm:us-east-1:396287094661:certificate/2b78e74f-7b65-4b82-a413-7a498b102f00
|
|
- Sid: ReadPocCertificate
|
|
Effect: Allow
|
|
Action:
|
|
- acm:DescribeCertificate
|
|
- acm:GetCertificate
|
|
- acm:ListTagsForCertificate
|
|
Resource: arn:aws:acm:us-east-1:396287094661:certificate/*
|
|
Condition:
|
|
StringEquals:
|
|
"aws:ResourceTag/project": shoc
|
|
"aws:ResourceTag/env": tf-poc
|
|
- Sid: ReadSharedRdsTags
|
|
Effect: Allow
|
|
Action: rds:ListTagsForResource
|
|
Resource: arn:aws:rds:us-east-1:396287094661:db:shoc-sqlserver-shared
|
|
- Sid: AccessExistingElasticBeanstalkStorage
|
|
Effect: Allow
|
|
Action:
|
|
- s3:CreateBucket
|
|
- s3:PutBucketOwnershipControls
|
|
Resource: arn:aws:s3:::elasticbeanstalk-us-east-1-396287094661
|
|
- Sid: ReadPocDns
|
|
Effect: Allow
|
|
Action:
|
|
- route53:GetHostedZone
|
|
- route53:ListResourceRecordSets
|
|
- route53:ListTagsForResource
|
|
Resource: arn:aws:route53:::hostedzone/Z02451891BSZD93CMMGDU
|
|
- Sid: ReadRoute53Changes
|
|
Effect: Allow
|
|
Action: route53:GetChange
|
|
Resource: arn:aws:route53:::change/*
|
|
- Sid: ReadPocAppConfigMetadata
|
|
Effect: Allow
|
|
Action:
|
|
- secretsmanager:DescribeSecret
|
|
- secretsmanager:GetResourcePolicy
|
|
- secretsmanager:ListSecretVersionIds
|
|
Resource: arn:aws:secretsmanager:us-east-1:396287094661:secret:shoc/tf-poc/app-config-*
|
|
|
|
HcptfShocBackendPocApplyRole:
|
|
Type: AWS::IAM::Role
|
|
Condition: ShouldManageShocBackendPocRoles
|
|
DeletionPolicy: Retain
|
|
UpdateReplacePolicy: Retain
|
|
Properties:
|
|
RoleName: hcptf-shoc-backend-tf-poc
|
|
Description: Import/adoption HCP Terraform apply role for SHOC backend tf-poc.
|
|
Tags:
|
|
- Key: HcpTerraformWorkspace
|
|
Value: shoc-backend-tf-poc
|
|
PermissionsBoundary: arn:aws:iam::396287094661:policy/external-dev-execution-boundary
|
|
MaxSessionDuration: 3600
|
|
AssumeRolePolicyDocument:
|
|
Version: "2012-10-17"
|
|
Statement:
|
|
- Effect: Allow
|
|
Principal:
|
|
Federated: arn:aws:iam::396287094661:oidc-provider/app.terraform.io
|
|
Action: sts:AssumeRoleWithWebIdentity
|
|
Condition:
|
|
StringEquals:
|
|
"app.terraform.io:aud": aws.workload.identity
|
|
"app.terraform.io:sub": organization:seahaven:project:seahaven-external-dev:workspace:shoc-backend-tf-poc:run_phase:apply
|
|
Policies:
|
|
- *shocPocReadPolicy
|
|
- PolicyName: shoc-backend-tf-poc-import-apply
|
|
PolicyDocument:
|
|
Version: "2012-10-17"
|
|
Statement:
|
|
- Sid: UpdatePocEnvironment
|
|
Effect: Allow
|
|
Action: elasticbeanstalk:UpdateEnvironment
|
|
Resource: arn:aws:elasticbeanstalk:us-east-1:396287094661:environment/shoc-backend/shoc-backend-tf-poc
|
|
- Sid: PutPocRuntimePolicy
|
|
Effect: Allow
|
|
Action: iam:PutRolePolicy
|
|
Resource: arn:aws:iam::396287094661:role/shoc-backend-tf-poc
|
|
Condition:
|
|
StringEquals:
|
|
"iam:PermissionsBoundary": arn:aws:iam::396287094661:policy/shoc-backend-tf-poc-runtime-boundary
|
|
- Sid: TagPocRuntimeRole
|
|
Effect: Allow
|
|
Action:
|
|
- iam:TagRole
|
|
- iam:UntagRole
|
|
Resource: arn:aws:iam::396287094661:role/shoc-backend-tf-poc
|
|
- Sid: ManagePocInstanceProfile
|
|
Effect: Allow
|
|
Action:
|
|
- iam:TagInstanceProfile
|
|
- iam:UntagInstanceProfile
|
|
Resource: arn:aws:iam::396287094661:instance-profile/shoc-backend-tf-poc
|
|
- Sid: PutPocGithubDeployPolicy
|
|
Effect: Allow
|
|
Action: iam:PutRolePolicy
|
|
Resource: arn:aws:iam::396287094661:role/githubdeploy-shoc-backend-tf-poc
|
|
Condition:
|
|
StringEquals:
|
|
"iam:PermissionsBoundary": arn:aws:iam::396287094661:policy/shoc-backend-tf-poc-deploy-boundary
|
|
- Sid: TagPocGithubDeployRole
|
|
Effect: Allow
|
|
Action:
|
|
- iam:TagRole
|
|
- iam:UntagRole
|
|
Resource: arn:aws:iam::396287094661:role/githubdeploy-shoc-backend-tf-poc
|
|
- Sid: TagPocAppConfig
|
|
Effect: Allow
|
|
Action:
|
|
- secretsmanager:TagResource
|
|
- secretsmanager:UntagResource
|
|
Resource: arn:aws:secretsmanager:us-east-1:396287094661:secret:shoc/tf-poc/app-config-*
|
|
- Sid: ChangePocApiAndValidationRecords
|
|
Effect: Allow
|
|
Action: route53:ChangeResourceRecordSets
|
|
Resource: arn:aws:route53:::hostedzone/Z02451891BSZD93CMMGDU
|
|
Condition:
|
|
ForAllValues:StringLike:
|
|
"route53:ChangeResourceRecordSetsNormalizedRecordNames":
|
|
- api.tf-poc.seahaven.com
|
|
- "*.tf-poc.seahaven.com"
|
|
ForAllValues:StringEquals:
|
|
"route53:ChangeResourceRecordSetsRecordTypes":
|
|
- CNAME
|
|
- Sid: TagPocHostedZone
|
|
Effect: Allow
|
|
Action: route53:ChangeTagsForResource
|
|
Resource: arn:aws:route53:::hostedzone/Z02451891BSZD93CMMGDU
|
|
- Sid: TagPocCertificate
|
|
Effect: Allow
|
|
Action:
|
|
- acm:AddTagsToCertificate
|
|
- acm:RemoveTagsFromCertificate
|
|
Resource: arn:aws:acm:us-east-1:396287094661:certificate/*
|
|
Condition:
|
|
StringEquals:
|
|
"aws:ResourceTag/project": shoc
|
|
"aws:ResourceTag/env": tf-poc
|
|
- Sid: TerminatePocEnvironment
|
|
Effect: Allow
|
|
Action: elasticbeanstalk:TerminateEnvironment
|
|
Resource: arn:aws:elasticbeanstalk:us-east-1:396287094661:environment/shoc-backend/shoc-backend-tf-poc
|
|
- Sid: DeletePocRuntimeIam
|
|
Effect: Allow
|
|
Action:
|
|
- iam:DeleteRole
|
|
- iam:DeleteRolePolicy
|
|
- iam:DetachRolePolicy
|
|
Resource: arn:aws:iam::396287094661:role/shoc-backend-tf-poc
|
|
- Sid: DeletePocInstanceProfile
|
|
Effect: Allow
|
|
Action:
|
|
- iam:DeleteInstanceProfile
|
|
- iam:RemoveRoleFromInstanceProfile
|
|
Resource: arn:aws:iam::396287094661:instance-profile/shoc-backend-tf-poc
|
|
- Sid: DeletePocAppConfig
|
|
Effect: Allow
|
|
Action: secretsmanager:DeleteSecret
|
|
Resource: arn:aws:secretsmanager:us-east-1:396287094661:secret:shoc/tf-poc/app-config-*
|
|
- Sid: DeletePocHostedZone
|
|
Effect: Allow
|
|
Action: route53:DeleteHostedZone
|
|
Resource: arn:aws:route53:::hostedzone/Z02451891BSZD93CMMGDU
|
|
- Sid: DeletePocCertificate
|
|
Effect: Allow
|
|
Action: acm:DeleteCertificate
|
|
Resource: arn:aws:acm:us-east-1:396287094661:certificate/*
|
|
Condition:
|
|
StringEquals:
|
|
"aws:ResourceTag/project": shoc
|
|
"aws:ResourceTag/env": tf-poc
|
|
|
|
HcptfShocBackendDevPlanRole:
|
|
Type: AWS::IAM::Role
|
|
Condition: ShouldManageShocBackendLiveRoles
|
|
DeletionPolicy: Retain
|
|
UpdateReplacePolicy: Retain
|
|
Properties:
|
|
RoleName: hcptf-shoc-backend-dev-plan
|
|
Description: Read-only HCP Terraform plan role for SHOC backend dev import.
|
|
PermissionsBoundary: arn:aws:iam::396287094661:policy/external-dev-execution-boundary
|
|
MaxSessionDuration: 3600
|
|
AssumeRolePolicyDocument:
|
|
Version: "2012-10-17"
|
|
Statement:
|
|
- Effect: Allow
|
|
Principal:
|
|
Federated: arn:aws:iam::396287094661:oidc-provider/app.terraform.io
|
|
Action: sts:AssumeRoleWithWebIdentity
|
|
Condition:
|
|
StringEquals:
|
|
"app.terraform.io:aud": aws.workload.identity
|
|
"app.terraform.io:sub": organization:seahaven:project:seahaven-external-dev:workspace:shoc-backend-dev:run_phase:plan
|
|
Policies:
|
|
- &shocDevReadPolicy
|
|
PolicyName: shoc-backend-dev-import-read
|
|
PolicyDocument:
|
|
Version: "2012-10-17"
|
|
Statement:
|
|
- Sid: CallerIdentity
|
|
Effect: Allow
|
|
Action: sts:GetCallerIdentity
|
|
Resource: "*"
|
|
- Sid: ReadExactIam
|
|
Effect: Allow
|
|
Action:
|
|
- iam:GetInstanceProfile
|
|
- iam:GetRole
|
|
- iam:GetRolePolicy
|
|
- iam:ListAttachedRolePolicies
|
|
- iam:ListInstanceProfileTags
|
|
- iam:ListInstanceProfilesForRole
|
|
- iam:ListRolePolicies
|
|
- iam:ListRoleTags
|
|
Resource:
|
|
- arn:aws:iam::396287094661:role/githubdeploy-shoc-backend-dev
|
|
- arn:aws:iam::396287094661:role/shoc-backend-dev
|
|
- arn:aws:iam::396287094661:instance-profile/shoc-backend-dev
|
|
- arn:aws:iam::396287094661:role/shoc-eb-service-role
|
|
- Sid: ReadGithubOidc
|
|
Effect: Allow
|
|
Action: iam:GetOpenIDConnectProvider
|
|
Resource: arn:aws:iam::396287094661:oidc-provider/token.actions.githubusercontent.com
|
|
- Sid: ListOidcProviders
|
|
Effect: Allow
|
|
Action: iam:ListOpenIDConnectProviders
|
|
Resource: "*"
|
|
- Sid: ReadSharedInventory
|
|
Effect: Allow
|
|
Action:
|
|
- acm:ListCertificates
|
|
- autoscaling:DescribeAutoScalingGroups
|
|
- ec2:DescribeSecurityGroups
|
|
- ec2:DescribeSubnets
|
|
- ec2:DescribeVpcs
|
|
- elasticbeanstalk:DescribeApplications
|
|
- elasticbeanstalk:DescribeConfigurationOptions
|
|
- elasticbeanstalk:DescribeConfigurationSettings
|
|
- elasticbeanstalk:DescribeEnvironmentResources
|
|
- elasticbeanstalk:DescribeEnvironments
|
|
- elasticbeanstalk:ListTagsForResource
|
|
- rds:DescribeDBInstances
|
|
- route53:ListHostedZones
|
|
- route53:ListHostedZonesByName
|
|
Resource: "*"
|
|
# Elastic Beanstalk DescribeConfigurationSettings calls
|
|
# CreateBucket against its existing regional service bucket
|
|
# during both plan and apply refresh.
|
|
- Sid: AuthorizeExistingEbBucketDiscovery
|
|
Effect: Allow
|
|
Action:
|
|
- s3:CreateBucket
|
|
- s3:PutBucketOwnershipControls
|
|
Resource: arn:aws:s3:::elasticbeanstalk-us-east-1-396287094661
|
|
Condition:
|
|
StringEquals:
|
|
s3:x-amz-object-ownership: ObjectWriter
|
|
- Sid: ReadSharedCertificate
|
|
Effect: Allow
|
|
Action:
|
|
- acm:DescribeCertificate
|
|
- acm:GetCertificate
|
|
- acm:ListTagsForCertificate
|
|
Resource: arn:aws:acm:us-east-1:396287094661:certificate/2b78e74f-7b65-4b82-a413-7a498b102f00
|
|
- Sid: ReadSharedRdsTags
|
|
Effect: Allow
|
|
Action: rds:ListTagsForResource
|
|
Resource: arn:aws:rds:us-east-1:396287094661:db:shoc-sqlserver-shared
|
|
- Sid: ReadDevDns
|
|
Effect: Allow
|
|
Action:
|
|
- route53:GetHostedZone
|
|
- route53:GetChange
|
|
- route53:ListResourceRecordSets
|
|
- route53:ListTagsForResource
|
|
Resource:
|
|
- arn:aws:route53:::hostedzone/Z07671212N75U4YLPWZR8
|
|
- arn:aws:route53:::change/*
|
|
- Sid: ReadDevAppConfigMetadata
|
|
Effect: Allow
|
|
Action:
|
|
- secretsmanager:DescribeSecret
|
|
- secretsmanager:GetResourcePolicy
|
|
- secretsmanager:ListSecretVersionIds
|
|
Resource: arn:aws:secretsmanager:us-east-1:396287094661:secret:shoc/dev/app-config-*
|
|
- Sid: ReadDevDeploySsm
|
|
Effect: Allow
|
|
Action:
|
|
- ssm:GetParameter
|
|
- ssm:GetParameters
|
|
- ssm:ListTagsForResource
|
|
Resource: arn:aws:ssm:us-east-1:396287094661:parameter/shoc-backend/dev/deploy/*
|
|
- Sid: DescribeDevDeploySsm
|
|
Effect: Allow
|
|
Action: ssm:DescribeParameters
|
|
Resource: "*"
|
|
|
|
HcptfShocBackendDevApplyRole:
|
|
Type: AWS::IAM::Role
|
|
Condition: ShouldManageShocBackendLiveRoles
|
|
DeletionPolicy: Retain
|
|
UpdateReplacePolicy: Retain
|
|
Properties:
|
|
RoleName: hcptf-shoc-backend-dev
|
|
Description: Import/adoption HCP Terraform apply role for SHOC backend dev.
|
|
Tags:
|
|
- Key: HcpTerraformWorkspace
|
|
Value: shoc-backend-dev
|
|
PermissionsBoundary: arn:aws:iam::396287094661:policy/external-dev-execution-boundary
|
|
MaxSessionDuration: 3600
|
|
AssumeRolePolicyDocument:
|
|
Version: "2012-10-17"
|
|
Statement:
|
|
- Effect: Allow
|
|
Principal:
|
|
Federated: arn:aws:iam::396287094661:oidc-provider/app.terraform.io
|
|
Action: sts:AssumeRoleWithWebIdentity
|
|
Condition:
|
|
StringEquals:
|
|
"app.terraform.io:aud": aws.workload.identity
|
|
"app.terraform.io:sub": organization:seahaven:project:seahaven-external-dev:workspace:shoc-backend-dev:run_phase:apply
|
|
Policies:
|
|
- *shocDevReadPolicy
|
|
- PolicyName: shoc-backend-dev-import-apply
|
|
PolicyDocument:
|
|
Version: "2012-10-17"
|
|
Statement:
|
|
- Sid: UpdateDevEnvironment
|
|
Effect: Allow
|
|
Action:
|
|
- elasticbeanstalk:UpdateEnvironment
|
|
- elasticbeanstalk:UpdateTagsForResource
|
|
Resource: arn:aws:elasticbeanstalk:us-east-1:396287094661:environment/shoc-backend/shoc-backend-dev
|
|
- Sid: ManageDevEnvironmentStack
|
|
Effect: Allow
|
|
Action:
|
|
- cloudformation:CancelUpdateStack
|
|
- cloudformation:DescribeStackEvents
|
|
- cloudformation:DescribeStackResource
|
|
- cloudformation:DescribeStackResources
|
|
- cloudformation:DescribeStacks
|
|
- cloudformation:GetTemplate
|
|
- cloudformation:ListStackResources
|
|
- cloudformation:UpdateStack
|
|
Resource: arn:aws:cloudformation:us-east-1:396287094661:stack/awseb-e-hehnrqjjrt-stack/*
|
|
- Sid: DescribeDeploymentResources
|
|
Effect: Allow
|
|
Action:
|
|
- autoscaling:Describe*
|
|
- ec2:Describe*
|
|
- elasticloadbalancing:Describe*
|
|
Resource: "*"
|
|
- Sid: ManageDevEnvironmentAsg
|
|
Effect: Allow
|
|
Action:
|
|
- autoscaling:PutNotificationConfiguration
|
|
- autoscaling:ResumeProcesses
|
|
- autoscaling:SuspendProcesses
|
|
Resource: arn:aws:autoscaling:us-east-1:396287094661:autoScalingGroup:*:autoScalingGroupName/awseb-e-hehnrqjjrt-stack-*
|
|
- Sid: LegacyBeanstalkObjects
|
|
Effect: Allow
|
|
Action:
|
|
- s3:Delete*
|
|
- s3:Get*
|
|
- s3:Put*
|
|
Resource: arn:aws:s3:::elasticbeanstalk-*/*
|
|
- Sid: LegacyBeanstalkBuckets
|
|
Effect: Allow
|
|
Action:
|
|
- s3:GetBucket*
|
|
- s3:ListBucket
|
|
- s3:PutBucketOwnershipControls
|
|
- s3:PutBucketPolicy
|
|
- s3:PutBucketPublicAccessBlock
|
|
Resource: arn:aws:s3:::elasticbeanstalk-*
|
|
- Sid: PutDevRuntimePolicy
|
|
Effect: Allow
|
|
Action: iam:PutRolePolicy
|
|
Resource: arn:aws:iam::396287094661:role/shoc-backend-dev
|
|
Condition:
|
|
StringEquals:
|
|
"iam:PermissionsBoundary": arn:aws:iam::396287094661:policy/shoc-backend-dev-runtime-boundary
|
|
- Sid: TagDevRuntimeRole
|
|
Effect: Allow
|
|
Action:
|
|
- iam:TagRole
|
|
- iam:UntagRole
|
|
Resource: arn:aws:iam::396287094661:role/shoc-backend-dev
|
|
- Sid: ManageDevInstanceProfile
|
|
Effect: Allow
|
|
Action:
|
|
- iam:TagInstanceProfile
|
|
- iam:UntagInstanceProfile
|
|
Resource: arn:aws:iam::396287094661:instance-profile/shoc-backend-dev
|
|
- Sid: PutDevGithubDeployPolicy
|
|
Effect: Allow
|
|
Action: iam:PutRolePolicy
|
|
Resource: arn:aws:iam::396287094661:role/githubdeploy-shoc-backend-dev
|
|
Condition:
|
|
StringEquals:
|
|
"iam:PermissionsBoundary": arn:aws:iam::396287094661:policy/shoc-backend-dev-deploy-boundary
|
|
- Sid: TagDevGithubDeployRole
|
|
Effect: Allow
|
|
Action:
|
|
- iam:TagRole
|
|
- iam:UntagRole
|
|
Resource: arn:aws:iam::396287094661:role/githubdeploy-shoc-backend-dev
|
|
- Sid: UpdateDevGithubDeployTrust
|
|
Effect: Allow
|
|
Action: iam:UpdateAssumeRolePolicy
|
|
Resource: arn:aws:iam::396287094661:role/githubdeploy-shoc-backend-dev
|
|
- Sid: ManageDevDeploySsm
|
|
Effect: Allow
|
|
Action:
|
|
- ssm:PutParameter
|
|
- ssm:AddTagsToResource
|
|
- ssm:RemoveTagsFromResource
|
|
Resource: arn:aws:ssm:us-east-1:396287094661:parameter/shoc-backend/dev/deploy/*
|
|
- Sid: TagDevAppConfig
|
|
Effect: Allow
|
|
Action:
|
|
- secretsmanager:TagResource
|
|
- secretsmanager:UntagResource
|
|
Resource: arn:aws:secretsmanager:us-east-1:396287094661:secret:shoc/dev/app-config-*
|
|
- Sid: ChangeDevApiRecord
|
|
Effect: Allow
|
|
Action: route53:ChangeResourceRecordSets
|
|
Resource: arn:aws:route53:::hostedzone/Z07671212N75U4YLPWZR8
|
|
Condition:
|
|
ForAllValues:StringEquals:
|
|
"route53:ChangeResourceRecordSetsNormalizedRecordNames":
|
|
- api.dev.seahaven.com
|
|
"route53:ChangeResourceRecordSetsRecordTypes":
|
|
- A
|
|
|
|
HcptfShocBackendStagingPlanRole:
|
|
Type: AWS::IAM::Role
|
|
Condition: ShouldManageShocBackendLiveRoles
|
|
DeletionPolicy: Retain
|
|
UpdateReplacePolicy: Retain
|
|
Properties:
|
|
RoleName: hcptf-shoc-backend-staging-plan
|
|
Description: Read-only HCP Terraform plan role for SHOC backend staging import.
|
|
PermissionsBoundary: arn:aws:iam::396287094661:policy/external-dev-execution-boundary
|
|
MaxSessionDuration: 3600
|
|
AssumeRolePolicyDocument:
|
|
Version: "2012-10-17"
|
|
Statement:
|
|
- Effect: Allow
|
|
Principal:
|
|
Federated: arn:aws:iam::396287094661:oidc-provider/app.terraform.io
|
|
Action: sts:AssumeRoleWithWebIdentity
|
|
Condition:
|
|
StringEquals:
|
|
"app.terraform.io:aud": aws.workload.identity
|
|
"app.terraform.io:sub": organization:seahaven:project:seahaven-external-dev:workspace:shoc-backend-staging:run_phase:plan
|
|
Policies:
|
|
- &shocStagingReadPolicy
|
|
PolicyName: shoc-backend-staging-import-read
|
|
PolicyDocument:
|
|
Version: "2012-10-17"
|
|
Statement:
|
|
- Sid: CallerIdentity
|
|
Effect: Allow
|
|
Action: sts:GetCallerIdentity
|
|
Resource: "*"
|
|
- Sid: ReadExactIam
|
|
Effect: Allow
|
|
Action:
|
|
- iam:GetInstanceProfile
|
|
- iam:GetRole
|
|
- iam:GetRolePolicy
|
|
- iam:ListAttachedRolePolicies
|
|
- iam:ListInstanceProfileTags
|
|
- iam:ListInstanceProfilesForRole
|
|
- iam:ListRolePolicies
|
|
- iam:ListRoleTags
|
|
Resource:
|
|
- arn:aws:iam::396287094661:role/githubdeploy-shoc-backend-staging
|
|
- arn:aws:iam::396287094661:role/shoc-backend-staging
|
|
- arn:aws:iam::396287094661:instance-profile/shoc-backend-staging
|
|
- arn:aws:iam::396287094661:role/shoc-eb-service-role
|
|
- Sid: ReadGithubOidc
|
|
Effect: Allow
|
|
Action: iam:GetOpenIDConnectProvider
|
|
Resource: arn:aws:iam::396287094661:oidc-provider/token.actions.githubusercontent.com
|
|
- Sid: ListOidcProviders
|
|
Effect: Allow
|
|
Action: iam:ListOpenIDConnectProviders
|
|
Resource: "*"
|
|
- Sid: ReadSharedInventory
|
|
Effect: Allow
|
|
Action:
|
|
- acm:ListCertificates
|
|
- autoscaling:DescribeAutoScalingGroups
|
|
- ec2:DescribeSecurityGroups
|
|
- ec2:DescribeSubnets
|
|
- ec2:DescribeVpcs
|
|
- elasticbeanstalk:DescribeApplications
|
|
- elasticbeanstalk:DescribeConfigurationOptions
|
|
- elasticbeanstalk:DescribeConfigurationSettings
|
|
- elasticbeanstalk:DescribeEnvironmentResources
|
|
- elasticbeanstalk:DescribeEnvironments
|
|
- elasticbeanstalk:ListTagsForResource
|
|
- rds:DescribeDBInstances
|
|
- route53:ListHostedZones
|
|
- route53:ListHostedZonesByName
|
|
Resource: "*"
|
|
# Elastic Beanstalk DescribeConfigurationSettings calls
|
|
# CreateBucket against its existing regional service bucket
|
|
# during both plan and apply refresh.
|
|
- Sid: AuthorizeExistingEbBucketDiscovery
|
|
Effect: Allow
|
|
Action:
|
|
- s3:CreateBucket
|
|
- s3:PutBucketOwnershipControls
|
|
Resource: arn:aws:s3:::elasticbeanstalk-us-east-1-396287094661
|
|
Condition:
|
|
StringEquals:
|
|
s3:x-amz-object-ownership: ObjectWriter
|
|
- Sid: ReadSharedCertificate
|
|
Effect: Allow
|
|
Action:
|
|
- acm:DescribeCertificate
|
|
- acm:GetCertificate
|
|
- acm:ListTagsForCertificate
|
|
Resource: arn:aws:acm:us-east-1:396287094661:certificate/2b78e74f-7b65-4b82-a413-7a498b102f00
|
|
- Sid: ReadSharedRdsTags
|
|
Effect: Allow
|
|
Action: rds:ListTagsForResource
|
|
Resource: arn:aws:rds:us-east-1:396287094661:db:shoc-sqlserver-shared
|
|
- Sid: ReadStagingDns
|
|
Effect: Allow
|
|
Action:
|
|
- route53:GetHostedZone
|
|
- route53:GetChange
|
|
- route53:ListResourceRecordSets
|
|
- route53:ListTagsForResource
|
|
Resource:
|
|
- arn:aws:route53:::hostedzone/Z02602739VQWBWCAGXP4
|
|
- arn:aws:route53:::change/*
|
|
- Sid: ReadStagingAppConfigMetadata
|
|
Effect: Allow
|
|
Action:
|
|
- secretsmanager:DescribeSecret
|
|
- secretsmanager:GetResourcePolicy
|
|
- secretsmanager:ListSecretVersionIds
|
|
Resource: arn:aws:secretsmanager:us-east-1:396287094661:secret:shoc/staging/app-config-*
|
|
- Sid: ReadStagingDeploySsm
|
|
Effect: Allow
|
|
Action:
|
|
- ssm:GetParameter
|
|
- ssm:GetParameters
|
|
- ssm:ListTagsForResource
|
|
Resource: arn:aws:ssm:us-east-1:396287094661:parameter/shoc-backend/staging/deploy/*
|
|
- Sid: DescribeStagingDeploySsm
|
|
Effect: Allow
|
|
Action: ssm:DescribeParameters
|
|
Resource: "*"
|
|
|
|
HcptfShocBackendStagingApplyRole:
|
|
Type: AWS::IAM::Role
|
|
Condition: ShouldManageShocBackendLiveRoles
|
|
DeletionPolicy: Retain
|
|
UpdateReplacePolicy: Retain
|
|
Properties:
|
|
RoleName: hcptf-shoc-backend-staging
|
|
Description: Import/adoption HCP Terraform apply role for SHOC backend staging.
|
|
Tags:
|
|
- Key: HcpTerraformWorkspace
|
|
Value: shoc-backend-staging
|
|
PermissionsBoundary: arn:aws:iam::396287094661:policy/external-dev-execution-boundary
|
|
MaxSessionDuration: 3600
|
|
AssumeRolePolicyDocument:
|
|
Version: "2012-10-17"
|
|
Statement:
|
|
- Effect: Allow
|
|
Principal:
|
|
Federated: arn:aws:iam::396287094661:oidc-provider/app.terraform.io
|
|
Action: sts:AssumeRoleWithWebIdentity
|
|
Condition:
|
|
StringEquals:
|
|
"app.terraform.io:aud": aws.workload.identity
|
|
"app.terraform.io:sub": organization:seahaven:project:seahaven-external-dev:workspace:shoc-backend-staging:run_phase:apply
|
|
Policies:
|
|
- *shocStagingReadPolicy
|
|
- PolicyName: shoc-backend-staging-import-apply
|
|
PolicyDocument:
|
|
Version: "2012-10-17"
|
|
Statement:
|
|
- Sid: UpdateStagingEnvironment
|
|
Effect: Allow
|
|
Action:
|
|
- elasticbeanstalk:UpdateEnvironment
|
|
- elasticbeanstalk:UpdateTagsForResource
|
|
Resource: arn:aws:elasticbeanstalk:us-east-1:396287094661:environment/shoc-backend/shoc-backend-staging
|
|
- Sid: ManageStagingEnvironmentStack
|
|
Effect: Allow
|
|
Action:
|
|
- cloudformation:CancelUpdateStack
|
|
- cloudformation:DescribeStackEvents
|
|
- cloudformation:DescribeStackResource
|
|
- cloudformation:DescribeStackResources
|
|
- cloudformation:DescribeStacks
|
|
- cloudformation:GetTemplate
|
|
- cloudformation:ListStackResources
|
|
- cloudformation:UpdateStack
|
|
Resource: arn:aws:cloudformation:us-east-1:396287094661:stack/awseb-e-6c9m4vb62z-stack/*
|
|
- Sid: DescribeDeploymentResources
|
|
Effect: Allow
|
|
Action:
|
|
- autoscaling:Describe*
|
|
- ec2:Describe*
|
|
- elasticloadbalancing:Describe*
|
|
Resource: "*"
|
|
- Sid: ManageStagingEnvironmentAsg
|
|
Effect: Allow
|
|
Action:
|
|
- autoscaling:PutNotificationConfiguration
|
|
- autoscaling:ResumeProcesses
|
|
- autoscaling:SuspendProcesses
|
|
Resource: arn:aws:autoscaling:us-east-1:396287094661:autoScalingGroup:*:autoScalingGroupName/awseb-e-6c9m4vb62z-stack-*
|
|
- Sid: StagingBeanstalkObjects
|
|
Effect: Allow
|
|
Action:
|
|
- s3:Delete*
|
|
- s3:Get*
|
|
- s3:Put*
|
|
Resource: arn:aws:s3:::elasticbeanstalk-us-east-1-396287094661/*
|
|
- Sid: StagingBeanstalkBuckets
|
|
Effect: Allow
|
|
Action:
|
|
- s3:GetBucket*
|
|
- s3:ListBucket
|
|
- s3:PutBucketOwnershipControls
|
|
- s3:PutBucketPolicy
|
|
- s3:PutBucketPublicAccessBlock
|
|
Resource: arn:aws:s3:::elasticbeanstalk-us-east-1-396287094661
|
|
# Elastic Beanstalk stages the CloudFormation template for
|
|
# configuration UpdateStack calls in its AWS-owned regional
|
|
# bucket and CloudFormation fetches it with the caller's
|
|
# credentials. Zip deploys never touch this path.
|
|
- Sid: ReadBeanstalkServiceTemplates
|
|
Effect: Allow
|
|
Action:
|
|
- s3:GetObject
|
|
- s3:GetObjectVersion
|
|
Resource: arn:aws:s3:::elasticbeanstalk-us-east-1/*
|
|
- Sid: ManageCloudFormationTemplates
|
|
Effect: Allow
|
|
Action:
|
|
- s3:CreateBucket
|
|
- s3:GetBucket*
|
|
- s3:ListBucket
|
|
- s3:PutBucketPolicy
|
|
- s3:PutBucketOwnershipControls
|
|
- s3:PutBucketPublicAccessBlock
|
|
- s3:PutEncryptionConfiguration
|
|
Resource: arn:aws:s3:::cf-templates-*
|
|
- Sid: ManageCloudFormationTemplateObjects
|
|
Effect: Allow
|
|
Action:
|
|
- s3:Get*
|
|
- s3:Put*
|
|
- s3:Delete*
|
|
Resource: arn:aws:s3:::cf-templates-*/*
|
|
- Sid: PutStagingRuntimePolicy
|
|
Effect: Allow
|
|
Action: iam:PutRolePolicy
|
|
Resource: arn:aws:iam::396287094661:role/shoc-backend-staging
|
|
Condition:
|
|
StringEquals:
|
|
"iam:PermissionsBoundary": arn:aws:iam::396287094661:policy/shoc-backend-staging-runtime-boundary
|
|
- Sid: UpdateStagingRuntimeTrust
|
|
Effect: Allow
|
|
Action:
|
|
- iam:UpdateAssumeRolePolicy
|
|
- iam:UpdateRole
|
|
- iam:UpdateRoleDescription
|
|
Resource: arn:aws:iam::396287094661:role/shoc-backend-staging
|
|
- Sid: TagStagingRuntimeRole
|
|
Effect: Allow
|
|
Action:
|
|
- iam:TagRole
|
|
- iam:UntagRole
|
|
Resource: arn:aws:iam::396287094661:role/shoc-backend-staging
|
|
- Sid: ManageStagingInstanceProfile
|
|
Effect: Allow
|
|
Action:
|
|
- iam:TagInstanceProfile
|
|
- iam:UntagInstanceProfile
|
|
Resource: arn:aws:iam::396287094661:instance-profile/shoc-backend-staging
|
|
- Sid: PutStagingGithubDeployPolicy
|
|
Effect: Allow
|
|
Action: iam:PutRolePolicy
|
|
Resource: arn:aws:iam::396287094661:role/githubdeploy-shoc-backend-staging
|
|
Condition:
|
|
StringEquals:
|
|
"iam:PermissionsBoundary": arn:aws:iam::396287094661:policy/shoc-backend-staging-deploy-boundary
|
|
- Sid: TagStagingGithubDeployRole
|
|
Effect: Allow
|
|
Action:
|
|
- iam:TagRole
|
|
- iam:UntagRole
|
|
Resource: arn:aws:iam::396287094661:role/githubdeploy-shoc-backend-staging
|
|
- Sid: UpdateStagingGithubDeployTrust
|
|
Effect: Allow
|
|
Action: iam:UpdateAssumeRolePolicy
|
|
Resource: arn:aws:iam::396287094661:role/githubdeploy-shoc-backend-staging
|
|
- Sid: ManageStagingDeploySsm
|
|
Effect: Allow
|
|
Action:
|
|
- ssm:PutParameter
|
|
- ssm:AddTagsToResource
|
|
- ssm:RemoveTagsFromResource
|
|
Resource: arn:aws:ssm:us-east-1:396287094661:parameter/shoc-backend/staging/deploy/*
|
|
- Sid: TagStagingAppConfig
|
|
Effect: Allow
|
|
Action:
|
|
- secretsmanager:TagResource
|
|
- secretsmanager:UntagResource
|
|
Resource: arn:aws:secretsmanager:us-east-1:396287094661:secret:shoc/staging/app-config-*
|
|
- Sid: ChangeStagingApiRecord
|
|
Effect: Allow
|
|
Action: route53:ChangeResourceRecordSets
|
|
Resource: arn:aws:route53:::hostedzone/Z02602739VQWBWCAGXP4
|
|
Condition:
|
|
ForAllValues:StringEquals:
|
|
"route53:ChangeResourceRecordSetsNormalizedRecordNames":
|
|
- api.staging.seahaven.com
|
|
"route53:ChangeResourceRecordSetsRecordTypes":
|
|
- CNAME
|