mirror of
https://github.com/Sea-Haven-Industries/seahaven-org-baseline.git
synced 2026-10-01 09:43:16 +00:00
* ci(iam): check synthesized policies with Access Analyzer (PLAT-234) Adds a CI job that checks bootstrap trust for StringEquals, rejects lambda writes on the plan refresh template, and runs ValidatePolicy plus CheckNoNewAccess when the policy-check role can be assumed. Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com> * ci(iam): fail closed on widened policies (PLAT-234) Compare new and removed SCPs, and fail when a Deny shrinks or a Condition changes. Run CheckNoNewAccess on bootstrap templates from the base repo. Install the base worktree's own dependencies and warn when analyzer credentials are skipped. Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com> --------- Co-authored-by: Cursor Agent <cursoragent@cursor.com> Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com>
58 lines
2 KiB
YAML
58 lines
2 KiB
YAML
name: CI
|
|
on:
|
|
pull_request:
|
|
branches: [main]
|
|
merge_group:
|
|
|
|
permissions:
|
|
contents: read
|
|
|
|
jobs:
|
|
ci:
|
|
uses: Sea-Haven-Industries/.github/.github/workflows/ci-typescript-cdk.yaml@e5691d8a7f96ac4d5a841a82975ff0a4354d53ac # v1.0.7
|
|
with:
|
|
node-version: "24"
|
|
|
|
iam-policy-check:
|
|
runs-on: ubuntu-latest
|
|
timeout-minutes: 30
|
|
permissions:
|
|
id-token: write
|
|
contents: read
|
|
steps:
|
|
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
|
with:
|
|
fetch-depth: 0
|
|
|
|
- uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0
|
|
with:
|
|
node-version: "24"
|
|
cache: npm
|
|
|
|
- name: Install dependencies
|
|
run: npm ci
|
|
|
|
- name: Synthesize organization policies
|
|
run: npx cdk synth org-governance -o cdk.out --quiet
|
|
|
|
- name: Synthesize base-branch organization policies
|
|
run: |
|
|
git fetch origin main
|
|
git worktree add --detach /tmp/iam-base origin/main
|
|
npm ci --prefix /tmp/iam-base
|
|
(cd /tmp/iam-base && npx cdk synth org-governance -o /tmp/iam-base-out --quiet)
|
|
|
|
- name: Configure AWS credentials
|
|
id: aws-creds
|
|
continue-on-error: true
|
|
uses: aws-actions/configure-aws-credentials@e1253824e5c10ff9df46874f81ed3ec929e19cfd # v6.3.0
|
|
with:
|
|
role-to-assume: arn:aws:iam::328440206208:role/githubdeploy-seahaven-org-baseline-policy-check
|
|
aws-region: us-east-1 # pragma: allowlist secret
|
|
|
|
- name: Note skipped analyzer credentials
|
|
if: steps.aws-creds.outcome != 'success'
|
|
run: echo "::warning title=Access Analyzer skipped::OIDC assume-role did not succeed, so ValidatePolicy and CheckNoNewAccess did not run. The skip stays until githubdeploy-seahaven-org-baseline-policy-check is deployed."
|
|
|
|
- name: Check IAM policies
|
|
run: python3 scripts/check_iam_policies.py --cdk-out cdk.out --base-cdk-out /tmp/iam-base-out --base-repo /tmp/iam-base --self-test
|