seahaven-org-baseline/.github/workflows/ci.yaml
Adam Moussa 8ff8ba1a87
ci(iam): check synthesized policies with Access Analyzer (PLAT-234) (#160)
* ci(iam): check synthesized policies with Access Analyzer (PLAT-234)

Adds a CI job that checks bootstrap trust for StringEquals, rejects
lambda writes on the plan refresh template, and runs ValidatePolicy
plus CheckNoNewAccess when the policy-check role can be assumed.

Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com>

* ci(iam): fail closed on widened policies (PLAT-234)

Compare new and removed SCPs, and fail when a Deny shrinks or a Condition
changes. Run CheckNoNewAccess on bootstrap templates from the base repo.
Install the base worktree's own dependencies and warn when analyzer
credentials are skipped.

Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com>

---------

Co-authored-by: Cursor Agent <cursoragent@cursor.com>
Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com>
2026-09-28 16:27:08 +00:00

58 lines
2 KiB
YAML

name: CI
on:
pull_request:
branches: [main]
merge_group:
permissions:
contents: read
jobs:
ci:
uses: Sea-Haven-Industries/.github/.github/workflows/ci-typescript-cdk.yaml@e5691d8a7f96ac4d5a841a82975ff0a4354d53ac # v1.0.7
with:
node-version: "24"
iam-policy-check:
runs-on: ubuntu-latest
timeout-minutes: 30
permissions:
id-token: write
contents: read
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
fetch-depth: 0
- uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0
with:
node-version: "24"
cache: npm
- name: Install dependencies
run: npm ci
- name: Synthesize organization policies
run: npx cdk synth org-governance -o cdk.out --quiet
- name: Synthesize base-branch organization policies
run: |
git fetch origin main
git worktree add --detach /tmp/iam-base origin/main
npm ci --prefix /tmp/iam-base
(cd /tmp/iam-base && npx cdk synth org-governance -o /tmp/iam-base-out --quiet)
- name: Configure AWS credentials
id: aws-creds
continue-on-error: true
uses: aws-actions/configure-aws-credentials@e1253824e5c10ff9df46874f81ed3ec929e19cfd # v6.3.0
with:
role-to-assume: arn:aws:iam::328440206208:role/githubdeploy-seahaven-org-baseline-policy-check
aws-region: us-east-1 # pragma: allowlist secret
- name: Note skipped analyzer credentials
if: steps.aws-creds.outcome != 'success'
run: echo "::warning title=Access Analyzer skipped::OIDC assume-role did not succeed, so ValidatePolicy and CheckNoNewAccess did not run. The skip stays until githubdeploy-seahaven-org-baseline-policy-check is deployed."
- name: Check IAM policies
run: python3 scripts/check_iam_policies.py --cdk-out cdk.out --base-cdk-out /tmp/iam-base-out --base-repo /tmp/iam-base --self-test