mirror of
https://github.com/Sea-Haven-Industries/seahaven-org-baseline.git
synced 2026-10-06 12:11:58 +00:00
* feat(hcptf): add hcptf-mta-sts apply and plan roles to seahaven-hcptf New MtaStsRoles construct nested in the prod seahaven-hcptf stack for the mta-sts-prod HCP workspace. Fresh roles, plain create, Retain on every resource. Trust is StringEquals on the exact workspace sub per run phase. Managed policies at /tf-managed/: - mta-sts-hcptf-iam: manage only githubdeploy-mta-sts and its boundary; CreateRole requires that boundary; DenySelfMutation on hcptf-*, githubdeploy-*, cdk, OrganizationAccountAccessRole, seahaven-* - mta-sts-hcptf-services: S3 on mta-sts-prod-*, CloudFront, ACM scoped to Project=mta-sts, SSM /mta-sts/deploy/* and the WAF ACL parameter, GitHub OIDC provider read - mta-sts-hcptf-plan: enumerated refresh reads beside ViewOnlyAccess Outputs MtaStsApplyRoleArn and MtaStsPlanRoleArn. README lists mta-sts with the other prod exec roles that live in this stack. * fix(hcptf): scope mta-sts CreatePolicy and plan policy reads to the boundary ARN CreateDeployBoundary now names the boundary ARN as its Resource instead of "*", keeping the BoundaryFor request-tag condition as a second gate. The plan sidecar's GetPolicy, GetPolicyVersion, ListPolicyVersions, and ListPolicyTags are merged into one RefreshDeployBoundary statement on the boundary ARN. The boundary is the only managed policy in Terraform state, and ViewOnlyAccess does not carry GetPolicy or GetPolicyVersion. * fix(hcptf): replace cloudfront:* in mta-sts services policy with tag-gated grants CloudFrontManage granted cloudfront:* on every CloudFront resource in the account. Split into: - CloudFrontRead: the Get and ListTagsForResource calls Terraform makes - CloudFrontCreateTagged: CreateDistribution and TagResource on the distribution ARN type, gated on request tag Project=mta-sts - CloudFrontManageTagged: Update, Delete, Tag, Untag, and CreateInvalidation gated on resource tag Project=mta-sts - CloudFrontOac: Create, Update, Delete on the origin-access-control ARN type; OACs do not support tags A distribution another workspace owns cannot be mutated by this role. The workspace provider must set Project=mta-sts in default_tags. * fix(hcptf): close mta-sts TagResource bypass and trim ACM and plan reads CloudFrontCreateTagged keeps cloudfront:TagResource, which CreateDistributionWithTags requires before the distribution has tags, but adds Null aws:ResourceTag/Project so it applies only to a distribution with no Project tag yet. An existing distribution owned by another workspace can no longer be re-tagged into CloudFrontManageTagged's scope. ACM is trimmed to what aws_acm_certificate calls: RequestCertificate, DescribeCertificate, ListTagsForCertificate, AddTagsToCertificate, RemoveTagsFromCertificate, DeleteCertificate. GetCertificate, RenewCertificate, and ListCertificates are dropped from both roles. RefreshDeployRole reads only githubdeploy-mta-sts; the two CFN-owned exec roles are not in Terraform state. * fix(hcptf): give CloudFront create actions Resource "*" in mta-sts services policy cloudfront:CreateDistribution and cloudfront:CreateOriginAccessControl have no resource type in the service authorization reference and only match Resource "*". Scoping them to the distribution and OAC ARN types would have implicitly denied the first apply. TagResource at create time stays on the distribution ARN type with the RequestTag and Null ResourceTag conditions, and OAC update and delete stay on the OAC ARN type. Verified with iam simulate-custom-policy: CreateDistribution with request tag Project=mta-sts allowed; TagResource, UpdateDistribution, and DeleteDistribution on a distribution tagged Project=seahaven-site denied. |
||
|---|---|---|
| .. | ||
| deploy-substrate | ||
| hcptf-bootstrap | ||
| scp | ||
| terraform-substrate | ||
| account-baseline-stack.ts | ||
| alarm-topic-stack.ts | ||
| app-web-acl-stack.ts | ||
| backup-offsite-stack.ts | ||
| backup-stack.ts | ||
| bedrock-logging-regional.ts | ||
| bedrock-logging.ts | ||
| cis-monitoring.ts | ||
| deploy-substrate-stack.ts | ||
| detective-controls.ts | ||
| dynamodb-cmk-stack.ts | ||
| engineering-access-stack.ts | ||
| flow-logs.ts | ||
| governance-toggles.ts | ||
| hcptf-policy-aspect.ts | ||
| logs-key.ts | ||
| member-baseline-stack.ts | ||
| mta-sts-hcptf-stack.ts | ||
| org-governance-stack.ts | ||
| platform-access-stack.ts | ||
| regional-baseline-stack.ts | ||
| seahaven-hcptf-stack.ts | ||
| seahaven-site-hcptf-stack.ts | ||
| ses-monitoring.ts | ||
| terraform-substrate-stack.ts | ||
| view-access-stack.ts | ||
| web-acl.ts | ||