mirror of
https://github.com/Sea-Haven-Industries/seahaven-org-baseline.git
synced 2026-09-30 06:53:17 +00:00
The six pairs are already in HCP state and DeletionPolicy is Retain, so CloudFormation drops the logical IDs without deleting the roles.
1520 lines
71 KiB
YAML
1520 lines
71 KiB
YAML
AWSTemplateFormatVersion: "2010-09-09"
|
|
Description: >-
|
|
Per-account HCP Terraform deploy substrate for Sea Haven Industries:
|
|
the app.terraform.io OIDC identity provider and the shared boundary-gated
|
|
IAM guardrail policy used by prod/dev apply roles, plus exact per-workspace
|
|
role pairs appended at each stack's migration time. External-dev SHOC roles
|
|
use environment-scoped inline policies instead of the shared IAM manager.
|
|
|
|
# PROVENANCE / DESIGN SOURCE
|
|
# Authored fresh 2026-07-30 (the mgmt Terraform POC's CLI-created provider and
|
|
# hcptf-* roles were rolled back the same day, so there is no deployed source
|
|
# to vendor). HcptfIamManagementPolicy DERIVES FROM the reviewed
|
|
# seahaven-cfn-exec-iam-management pattern in
|
|
# lib/deploy-substrate/deploy-substrate.template.yaml (boundary-gated
|
|
# CreateRole/AttachRolePolicy/PutRolePolicy/PutRolePermissionsBoundary +
|
|
# DenyBoundaryTampering / DenyBoundaryPolicyEdit / DenySelfMutation) but is
|
|
# DELIBERATELY STRICTER — it is NOT a byte-identical mirror. Do not "reconcile"
|
|
# the two by copying this file's statements back, or vice versa; the divergences
|
|
# below are load-bearing and were required by the 2026-07-30 security review
|
|
# (findings C1-C5, one confirmed critical + one high):
|
|
#
|
|
# 1. ROLE PATH SCOPING (review finding C2). The SAM copy's Resource
|
|
# `role/*` on the boundary-gated statements is justified there by SAM
|
|
# auto-generating execution roles at path / with no settable RolePath —
|
|
# a path condition would break every SAM deploy. THAT RATIONALE DOES NOT
|
|
# TRANSFER: Terraform's aws_iam_role supports `path` and `name_prefix`.
|
|
# So every role-WRITE statement here is scoped to the Terraform-owned path
|
|
# `role/tf-managed/*`. Terraform configs MUST set path = "/tf-managed/" on
|
|
# every role they create; a role created anywhere else is denied. The path
|
|
# is deliberately NOT `hcptf-*`, which would collide with the substrate's
|
|
# own hcptf-* apply/plan roles under DenySelfMutation's wildcard.
|
|
# 2. READ AND WRITE SPLIT (review findings C1, C3, C4). The SAM copy's
|
|
# IAMRoleReadAndDelete grants iam:UpdateAssumeRolePolicy / DeleteRole /
|
|
# DetachRolePolicy / DeleteRolePolicy / UpdateRole on Resource "*"
|
|
# unconditioned — a confirmed privilege-escalation primitive (repoint the
|
|
# AdministratorAccess CDK bootstrap role's trust policy, then assume it
|
|
# cross-account) that DenySelfMutation's three name patterns do not cover.
|
|
# Here those actions are split: reads stay on "*" (Terraform data sources
|
|
# need them), every destructive/mutating action is confined to
|
|
# `role/tf-managed/*`. This closes the escalation at the root instead of
|
|
# chasing it with a denylist.
|
|
# 3. PASSROLE SCOPING (review finding C5). The SAM copy passes any role to
|
|
# Lambda (its comment claims SAM-role scoping the Resource does not
|
|
# express). Here PassRole is confined to `role/tf-managed/*`, so one
|
|
# workspace cannot attach another workspace's execution role to a function
|
|
# it controls — that path performs no IAM write and would otherwise evade
|
|
# every boundary gate and Deny in this document.
|
|
# 4. DENYSELFMUTATION SCOPE. Extended beyond the substrate's own principals to
|
|
# cdk-hnb659fds-* (AdministratorAccess bootstrap roles),
|
|
# OrganizationAccountAccessRole, and seahaven-* (detective-control roles
|
|
# such as the Config recorder role, which no SCP on prod/nonprod protects
|
|
# from iam:DeleteRole). Defense in depth behind the path scoping above.
|
|
#
|
|
# The SAM copy retains its adjudicated accepted risks because SAM's constraints
|
|
# are real; this file has no such excuse. KNOWN OPEN ITEM (pre-existing, not
|
|
# introduced here): the org's ProtectPrivilegedRoles SCP encodes exactly the
|
|
# protection in (4) but is attached ONLY to the security OU — extending it to
|
|
# prod/nonprod is the durable org-level fix and is tracked separately.
|
|
#
|
|
# COUPLING (frozen, PLAT-143/PLAT-149): the enumerated StringEquals list below
|
|
# is the last prod/dev HCP allow-list this document will carry. Do not append
|
|
# another seahaven-lambda-execution-boundary-<workload> ARN here. New HCP
|
|
# Lambda ceilings are policy/tf-managed/<stack> created by hcptf-bootstrap
|
|
# (CLI, PLAT-145). CreatePolicy lives only on that bootstrap role. Do not
|
|
# put ArnLike on this list, and do not add ArnLike to the SAM copy in
|
|
# deploy-substrate (PLAT-52 AC1: githubdeploy-seahaven-org-baseline can
|
|
# CreatePolicy via CFN). Existing eight workloads keep these ARNs until their
|
|
# consumer Terraform imports detach seahaven-hcptf-iam-management and this
|
|
# stack is deleted in prod/dev (PLAT-147). External-dev SHOC roles below do
|
|
# not attach this policy.
|
|
#
|
|
# SIZE BUDGET: this document is at the 6,144-character wall (4693 compact /
|
|
# 10 statements after eight workload ARNs). That accumulator is why prod/dev
|
|
# per-workspace IAM is leaving this file. Do not grow it.
|
|
#
|
|
# PER-WORKSPACE ROLE ACCUMULATOR — CLOSED FOR PROD/DEV
|
|
# Do not append new hcptf-<stack> pairs for prod or dev. App Terraform owns
|
|
# those roles (PLAT-144/PLAT-146). The six imported prod pairs are removed
|
|
# here. Their previous DeletionPolicy is Retain, so CloudFormation forgets
|
|
# them (PLAT-147). hcptf-sh-openswe-traces was already forgotten.
|
|
# seahaven-site lives in seahaven-site-hcptf. External-dev
|
|
# SHOC roles below remain in this template (PLAT-148). All remaining subs are
|
|
# exact StringEquals (never StringLike, never a wildcarded run_phase).
|
|
#
|
|
# This template is deployed via lib/terraform-substrate-stack.ts
|
|
# (cloudformation-include) as stack seahaven-terraform-substrate, once per
|
|
# member account that hosts Terraform-managed workloads (currently
|
|
# seahaven-prod 011934824531, seahaven-dev 710827005802, and external-dev
|
|
# 396287094661; NEVER mgmt — mgmt stays SAM until its stacks migrate out).
|
|
|
|
Parameters:
|
|
CreateOIDCProvider:
|
|
Type: String
|
|
Default: "true"
|
|
AllowedValues: ["true", "false"]
|
|
Description: >-
|
|
Set to false if the app.terraform.io OIDC provider already exists in this
|
|
account. An account holds exactly ONE provider per URL, so an unconditional
|
|
create collides. Because the provider is Retain, a FIRST-create rollback
|
|
(caused by any other resource in this stack failing) leaves the provider
|
|
behind as an orphan and the stack in ROLLBACK_COMPLETE — which cannot be
|
|
updated. Recovery: delete the stack, then either
|
|
`aws iam delete-open-id-connect-provider --open-id-connect-provider-arn
|
|
arn:aws:iam::<acct>:oidc-provider/app.terraform.io` before retrying, or
|
|
redeploy with this parameter false. Same idempotency affordance the sibling
|
|
deploy-substrate template carries for the GitHub provider.
|
|
EnableShocBackendPocRoles:
|
|
Type: String
|
|
Default: "false"
|
|
AllowedValues: ["true", "false"]
|
|
Description: >-
|
|
External-dev tf-poc gate. Keep false for the base-stack create, then set
|
|
true on the reviewed normal update that creates the new tf-poc role pair.
|
|
EnableShocBackendLiveRoles:
|
|
Type: String
|
|
Default: "false"
|
|
AllowedValues: ["true", "false"]
|
|
Description: >-
|
|
External-dev live-role collision guard. Keep false until the four existing
|
|
dev/staging roles have been removed from Terraform state with destroy=false.
|
|
Set true only in the CloudFormation IMPORT change set that adopts them.
|
|
|
|
Conditions:
|
|
ShouldCreateOIDCProvider: !Equals [!Ref CreateOIDCProvider, "true"]
|
|
# Per-workspace hcptf-* roles for afi-backup-monitor-prod (PLAT-56) must only
|
|
# exist in seahaven-prod. The same template deploys to seahaven-dev; creating
|
|
# prod-workspace trust there would leave dead credentials in the wrong account.
|
|
IsProdAccount: !Equals [!Ref "AWS::AccountId", "011934824531"]
|
|
IsExternalDevAccount: !Equals [!Ref "AWS::AccountId", "396287094661"]
|
|
IsSharedIamManagementAccount: !Or
|
|
- !Equals [!Ref "AWS::AccountId", "011934824531"]
|
|
- !Equals [!Ref "AWS::AccountId", "710827005802"]
|
|
ShouldManageShocBackendPocRoles: !And
|
|
- !Condition IsExternalDevAccount
|
|
- !Equals [!Ref EnableShocBackendPocRoles, "true"]
|
|
ShouldManageShocBackendLiveRoles: !And
|
|
- !Condition IsExternalDevAccount
|
|
- !Equals [!Ref EnableShocBackendLiveRoles, "true"]
|
|
|
|
Resources:
|
|
|
|
# ---------------------------------------------------------------------------
|
|
# HCP Terraform OIDC provider
|
|
#
|
|
# Created by default: Phase-0 checks (2026-07-30) confirmed neither prod nor
|
|
# dev has an app.terraform.io provider (the mgmt POC's copy was deleted in the
|
|
# same-day rollback and never existed in the member accounts). An account
|
|
# holds exactly ONE provider per URL — see the parameter above for the
|
|
# first-create rollback trap this condition exists to make recoverable.
|
|
# ---------------------------------------------------------------------------
|
|
TerraformCloudOIDCProvider:
|
|
Type: AWS::IAM::OIDCProvider
|
|
Condition: ShouldCreateOIDCProvider
|
|
Properties:
|
|
Url: https://app.terraform.io
|
|
ClientIdList:
|
|
# Default audience of HCP Terraform dynamic provider credentials
|
|
# (TFC_AWS_WORKLOAD_IDENTITY_AUDIENCE). Trust policies pin this via
|
|
# StringEquals on app.terraform.io:aud.
|
|
- aws.workload.identity
|
|
ThumbprintList:
|
|
# AWS ignores thumbprints for issuers signed by a trusted root CA
|
|
# (app.terraform.io qualifies) and secures trust via the CA bundle;
|
|
# the property is populated because CloudFormation requires a value.
|
|
# This is the thumbprint HashiCorp's own AWS setup documentation uses.
|
|
- 9e99a48a9960b14926bb7f3b02e22da2b0ab7280
|
|
# Every future hcptf-* role trusts this provider. Retain so deleting the
|
|
# stack can never delete the account's Terraform federation anchor out
|
|
# from under live workspaces.
|
|
DeletionPolicy: Retain
|
|
UpdateReplacePolicy: Retain
|
|
|
|
# ---------------------------------------------------------------------------
|
|
# Shared boundary-gated IAM guardrail policy (attached managed policy)
|
|
#
|
|
# Attached by every per-workspace Terraform APPLY role (hcptf-<stack>);
|
|
# NEVER by plan roles (hcptf-<stack>-plan are read-only and hold no IAM
|
|
# writes at all). Defined once here so all apply roles carry the identical
|
|
# reviewed escalation control instead of per-role copies that can drift.
|
|
#
|
|
# PRIMARY ESCALATION CONTROL (same design as INFRA-97 on the SAM side):
|
|
# every iam:CreateRole / AttachRolePolicy / PutRolePolicy is conditioned on
|
|
# the target role carrying seahaven-lambda-execution-boundary, so a role
|
|
# created by a Terraform apply can never exceed the boundary ceiling. The
|
|
# POC security review confirmed the unconditioned alternative is critical:
|
|
# iam:PutRolePolicy on Lambda exec roles + lambda:UpdateFunctionCode reads
|
|
# every secret in the account.
|
|
# ---------------------------------------------------------------------------
|
|
HcptfIamManagementPolicy:
|
|
Type: AWS::IAM::ManagedPolicy
|
|
Condition: IsSharedIamManagementAccount
|
|
Properties:
|
|
# Fixed name: future hcptf-* roles reference it by ARN, and a rename
|
|
# would detach-and-replace mid-update. Treat a rename as a coordinated
|
|
# migration, not an edit.
|
|
ManagedPolicyName: seahaven-hcptf-iam-management
|
|
Description: >-
|
|
Boundary-gated IAM role lifecycle for per-workspace Terraform apply
|
|
roles (hcptf-*), plus the explicit Deny backstops that keep the
|
|
permissions boundary from being detached or rewritten and the deploy
|
|
substrates' own principals from being mutated. Mirrors
|
|
seahaven-cfn-exec-iam-management; reconcile changes across both.
|
|
PolicyDocument:
|
|
Version: "2012-10-17"
|
|
Statement:
|
|
# Create role — MUST attach boundary AND land on the Terraform-owned
|
|
# path. Two independent gates: the boundary caps what the role can do,
|
|
# the path caps which roles this policy can touch at all. Terraform
|
|
# configs set path = "/tf-managed/" on every aws_iam_role.
|
|
- Sid: IAMCreateRoleWithBoundary
|
|
Effect: Allow
|
|
Action:
|
|
- iam:CreateRole
|
|
Resource:
|
|
- !Sub "arn:aws:iam::${AWS::AccountId}:role/tf-managed/*"
|
|
Condition:
|
|
StringEquals:
|
|
"iam:PermissionsBoundary": &acceptableLambdaBoundaries
|
|
- !Sub "arn:aws:iam::${AWS::AccountId}:policy/seahaven-lambda-execution-boundary"
|
|
- !Sub "arn:aws:iam::${AWS::AccountId}:policy/seahaven-lambda-execution-boundary-afi-backup-monitor"
|
|
- !Sub "arn:aws:iam::${AWS::AccountId}:policy/seahaven-lambda-execution-boundary-front-integrations"
|
|
- !Sub "arn:aws:iam::${AWS::AccountId}:policy/seahaven-lambda-execution-boundary-procurement-ingest"
|
|
- !Sub "arn:aws:iam::${AWS::AccountId}:policy/seahaven-lambda-execution-boundary-meal-order-manager"
|
|
- !Sub "arn:aws:iam::${AWS::AccountId}:policy/seahaven-lambda-execution-boundary-seahaven-site"
|
|
- !Sub "arn:aws:iam::${AWS::AccountId}:policy/seahaven-lambda-execution-boundary-seahaven-door-unlock-api"
|
|
- !Sub "arn:aws:iam::${AWS::AccountId}:policy/seahaven-lambda-execution-boundary-paychex-integrations"
|
|
|
|
# Attach managed policies — MUST have boundary already on role
|
|
- Sid: IAMAttachPolicyWithBoundary
|
|
Effect: Allow
|
|
Action:
|
|
- iam:AttachRolePolicy
|
|
Resource:
|
|
- !Sub "arn:aws:iam::${AWS::AccountId}:role/tf-managed/*"
|
|
Condition:
|
|
StringEquals:
|
|
"iam:PermissionsBoundary": *acceptableLambdaBoundaries
|
|
|
|
# Put inline policy — MUST have boundary already on role
|
|
- Sid: IAMPutRolePolicyWithBoundary
|
|
Effect: Allow
|
|
Action:
|
|
- iam:PutRolePolicy
|
|
Resource:
|
|
- !Sub "arn:aws:iam::${AWS::AccountId}:role/tf-managed/*"
|
|
Condition:
|
|
StringEquals:
|
|
"iam:PermissionsBoundary": *acceptableLambdaBoundaries
|
|
|
|
# Boundary management — SET only, never DELETE. For a delete, the
|
|
# iam:PermissionsBoundary condition key resolves to the boundary
|
|
# CURRENTLY on the target role, so a StringEquals grant would match
|
|
# exactly the roles the gate protects and self-defeat it (verified
|
|
# live against the mgmt SAM copy 2026-07-27). Terraform never needs
|
|
# the delete: it SETS the boundary on roles it creates, and destroy
|
|
# calls DeleteRole.
|
|
# Path-scoped as well as boundary-pinned: the condition constrains WHICH
|
|
# boundary may be set, not WHICH role receives it. Unscoped (as in the
|
|
# SAM copy) this is a one-way denial-of-service — applying the Lambda
|
|
# runtime boundary to the CDK bootstrap execution role collapses its
|
|
# permissions, and DenyBoundaryTampering below then blocks removal by
|
|
# this same principal (2026-07-30 review finding C3).
|
|
- Sid: IAMPutPermissionsBoundary
|
|
Effect: Allow
|
|
Action:
|
|
- iam:PutRolePermissionsBoundary
|
|
Resource:
|
|
- !Sub "arn:aws:iam::${AWS::AccountId}:role/tf-managed/*"
|
|
Condition:
|
|
StringEquals:
|
|
"iam:PermissionsBoundary": *acceptableLambdaBoundaries
|
|
|
|
# Explicit Deny backstop (AWS's NoBoundaryPolicyEdit/NoBoundaryDelete
|
|
# delegation pattern). A Deny is required, not merely omitting the
|
|
# Allow — any future Allow added to an apply role silently reopens
|
|
# the escalation otherwise.
|
|
- Sid: DenyBoundaryTampering
|
|
Effect: Deny
|
|
Action:
|
|
- iam:DeleteRolePermissionsBoundary
|
|
- iam:DeleteUserPermissionsBoundary
|
|
Resource:
|
|
- !Sub "arn:aws:iam::${AWS::AccountId}:role/*"
|
|
- !Sub "arn:aws:iam::${AWS::AccountId}:user/*"
|
|
|
|
# Whole seahaven-* policy family: this policy carries the Denies, so
|
|
# it is a higher-value target than the boundary it protects. Safe to
|
|
# scope broadly — no Terraform stack manages a seahaven-* managed
|
|
# policy, and apply roles hold no iam:CreatePolicy.
|
|
- Sid: DenyBoundaryPolicyEdit
|
|
Effect: Deny
|
|
Action:
|
|
- iam:CreatePolicyVersion
|
|
- iam:SetDefaultPolicyVersion
|
|
- iam:DeletePolicyVersion
|
|
- iam:DeletePolicy
|
|
Resource:
|
|
- !Sub "arn:aws:iam::${AWS::AccountId}:policy/seahaven-*"
|
|
|
|
# Self-protection for BOTH deploy substrates' principals. Without
|
|
# this the control is one API call from being undone —
|
|
# IAMRoleReadAndDelete below grants iam:DetachRolePolicy on
|
|
# Resource "*" unconditioned, so an apply role could detach this
|
|
# very policy from itself. Scope covers the Terraform substrate's
|
|
# own roles (hcptf-*) AND the GitHub Actions substrate's
|
|
# (github-cfn-execution-role, githubdeploy-*): a Terraform apply
|
|
# never legitimately manages any of them — hcptf-* roles are
|
|
# managed by THIS stack via the CDK bootstrap execution role, the
|
|
# GitHub-side roles by their own substrate/onboarding — so the Deny
|
|
# costs nothing operationally and closes the same
|
|
# UpdateAssumeRolePolicy-on-* repoint risk the SAM-side review
|
|
# flagged, for every substrate principal reachable from this path.
|
|
- Sid: DenySelfMutation
|
|
Effect: Deny
|
|
Action:
|
|
- iam:AttachRolePolicy
|
|
- iam:DeleteRole
|
|
- iam:DeleteRolePolicy
|
|
- iam:DeleteRolePermissionsBoundary
|
|
- iam:DetachRolePolicy
|
|
- iam:PutRolePolicy
|
|
- iam:PutRolePermissionsBoundary
|
|
- iam:UpdateAssumeRolePolicy
|
|
- iam:UpdateRole
|
|
- iam:UpdateRoleDescription
|
|
Resource:
|
|
- !Sub "arn:aws:iam::${AWS::AccountId}:role/hcptf-*"
|
|
- !Sub "arn:aws:iam::${AWS::AccountId}:role/github-cfn-execution-role"
|
|
- !Sub "arn:aws:iam::${AWS::AccountId}:role/githubdeploy-*"
|
|
# Extended beyond the SAM copy's three patterns (2026-07-30 review
|
|
# findings C1/C3/C4). cdk-hnb659fds-* carries AdministratorAccess
|
|
# and deploys this very stack; OrganizationAccountAccessRole is the
|
|
# org break-glass path; seahaven-* covers detective-control roles
|
|
# (e.g. the Config recorder role) that the protect-security-baseline
|
|
# SCP does NOT shield from iam:DeleteRole. Defense in depth — the
|
|
# path scoping on the write statements is the primary control.
|
|
- !Sub "arn:aws:iam::${AWS::AccountId}:role/cdk-hnb659fds-*"
|
|
- !Sub "arn:aws:iam::${AWS::AccountId}:role/OrganizationAccountAccessRole"
|
|
- !Sub "arn:aws:iam::${AWS::AccountId}:role/seahaven-*"
|
|
|
|
# READ-ONLY on every role/policy in the account. Terraform data sources
|
|
# and refresh legitimately need to read arbitrary roles; none of these
|
|
# actions can modify anything, so Resource "*" is safe here.
|
|
- Sid: IAMReadOnly
|
|
Effect: Allow
|
|
Action:
|
|
- iam:GetRole
|
|
- iam:GetRolePolicy
|
|
- iam:ListAttachedRolePolicies
|
|
- iam:ListRolePolicies
|
|
- iam:ListRoles
|
|
- iam:GetPolicy
|
|
- iam:GetPolicyVersion
|
|
- iam:ListPolicies
|
|
- iam:ListPolicyVersions
|
|
Resource: "*"
|
|
|
|
# DESTRUCTIVE / MUTATING role actions — confined to the Terraform-owned
|
|
# path. The SAM copy grants these on Resource "*" unconditioned, which
|
|
# the 2026-07-30 review confirmed as a critical escalation primitive
|
|
# (finding C1): iam:UpdateAssumeRolePolicy on "*" lets the principal
|
|
# repoint the AdministratorAccess CDK bootstrap role's trust policy to
|
|
# an external account and assume it. Path scoping closes that at the
|
|
# root rather than enumerating protected names.
|
|
- Sid: IAMRoleWriteScoped
|
|
Effect: Allow
|
|
Action:
|
|
- iam:DeleteRole
|
|
- iam:DeleteRolePolicy
|
|
- iam:DetachRolePolicy
|
|
- iam:TagRole
|
|
- iam:UntagRole
|
|
- iam:UpdateRole
|
|
- iam:UpdateRoleDescription
|
|
- iam:UpdateAssumeRolePolicy
|
|
Resource:
|
|
- !Sub "arn:aws:iam::${AWS::AccountId}:role/tf-managed/*"
|
|
|
|
# PassRole — Terraform passes the execution roles it created (which are
|
|
# on the tf-managed path, boundary-gated above) to the Lambda service.
|
|
# Path-scoped, not role/*: unscoped, one workspace's apply role could
|
|
# attach ANOTHER workspace's or a SAM stack's execution role to a
|
|
# function it controls and run arbitrary code as that identity — a path
|
|
# that performs no IAM write and so evades every boundary gate and Deny
|
|
# in this document (2026-07-30 review finding C5). Other target services
|
|
# (scheduler, apigateway, ...) are NOT granted: a stack that needs one
|
|
# adds a scoped PassRole statement to its own apply role at migration.
|
|
- Sid: IAMPassRole
|
|
Effect: Allow
|
|
Action:
|
|
- iam:PassRole
|
|
Resource:
|
|
- !Sub "arn:aws:iam::${AWS::AccountId}:role/tf-managed/*"
|
|
Condition:
|
|
StringEquals:
|
|
"iam:PassedToService": "lambda.amazonaws.com"
|
|
|
|
# ---------------------------------------------------------------------------
|
|
# SHOC backend GitHub deployment permissions boundaries (external-dev only)
|
|
#
|
|
# These are ceilings for the dev and staging githubdeploy roles, not grants.
|
|
# Existing dev/staging roles receive them through a separately approved
|
|
# administrator/CDK action before HCP import.
|
|
# ---------------------------------------------------------------------------
|
|
ShocBackendDevDeployBoundary:
|
|
Type: AWS::IAM::ManagedPolicy
|
|
Condition: IsExternalDevAccount
|
|
DeletionPolicy: Retain
|
|
UpdateReplacePolicy: Retain
|
|
Properties:
|
|
ManagedPolicyName: shoc-backend-dev-deploy-boundary
|
|
Description: Maximum deployment permissions for githubdeploy-shoc-backend-dev.
|
|
PolicyDocument:
|
|
Version: "2012-10-17"
|
|
Statement:
|
|
- Sid: DescribeDeploymentResources
|
|
Effect: Allow
|
|
Action:
|
|
- autoscaling:Describe*
|
|
- ec2:Describe*
|
|
- elasticbeanstalk:DescribeApplicationVersions
|
|
- elasticbeanstalk:DescribeEnvironments
|
|
- elasticbeanstalk:DescribeEvents
|
|
- elasticloadbalancing:Describe*
|
|
Resource: "*"
|
|
- Sid: CreateApplicationVersion
|
|
Effect: Allow
|
|
Action: elasticbeanstalk:CreateApplicationVersion
|
|
Resource:
|
|
- arn:aws:elasticbeanstalk:us-east-1:396287094661:application/shoc-backend
|
|
- arn:aws:elasticbeanstalk:us-east-1:396287094661:applicationversion/shoc-backend/*
|
|
- Sid: UpdateDevEnvironment
|
|
Effect: Allow
|
|
Action: elasticbeanstalk:UpdateEnvironment
|
|
Resource: arn:aws:elasticbeanstalk:us-east-1:396287094661:environment/shoc-backend/shoc-backend-dev
|
|
- Sid: ManageDevEnvironmentStack
|
|
Effect: Allow
|
|
Action:
|
|
- cloudformation:CancelUpdateStack
|
|
- cloudformation:DescribeStackEvents
|
|
- cloudformation:DescribeStackResource
|
|
- cloudformation:DescribeStackResources
|
|
- cloudformation:DescribeStacks
|
|
- cloudformation:GetTemplate
|
|
- cloudformation:ListStackResources
|
|
- cloudformation:UpdateStack
|
|
Resource: arn:aws:cloudformation:us-east-1:396287094661:stack/awseb-e-hehnrqjjrt-stack/*
|
|
- Sid: ManageDevEnvironmentAsg
|
|
Effect: Allow
|
|
Action:
|
|
- autoscaling:PutNotificationConfiguration
|
|
- autoscaling:ResumeProcesses
|
|
- autoscaling:SuspendProcesses
|
|
Resource: arn:aws:autoscaling:us-east-1:396287094661:autoScalingGroup:*:autoScalingGroupName/awseb-e-hehnrqjjrt-stack-*
|
|
- Sid: LegacyBeanstalkObjects
|
|
Effect: Allow
|
|
Action:
|
|
- s3:Delete*
|
|
- s3:Get*
|
|
- s3:Put*
|
|
Resource: arn:aws:s3:::elasticbeanstalk-*/*
|
|
- Sid: LegacyBeanstalkBuckets
|
|
Effect: Allow
|
|
Action:
|
|
- s3:GetBucket*
|
|
- s3:ListBucket
|
|
- s3:PutBucketOwnershipControls
|
|
- s3:PutBucketPolicy
|
|
- s3:PutBucketPublicAccessBlock
|
|
Resource: arn:aws:s3:::elasticbeanstalk-*
|
|
- Sid: ReadDeployParameters
|
|
Effect: Allow
|
|
Action:
|
|
- ssm:GetParameter
|
|
- ssm:GetParameters
|
|
Resource: arn:aws:ssm:us-east-1:396287094661:parameter/shoc-backend/dev/deploy/*
|
|
|
|
ShocBackendStagingDeployBoundary:
|
|
Type: AWS::IAM::ManagedPolicy
|
|
Condition: IsExternalDevAccount
|
|
DeletionPolicy: Retain
|
|
UpdateReplacePolicy: Retain
|
|
Properties:
|
|
ManagedPolicyName: shoc-backend-staging-deploy-boundary
|
|
Description: Maximum deployment permissions for githubdeploy-shoc-backend-staging.
|
|
PolicyDocument:
|
|
Version: "2012-10-17"
|
|
Statement:
|
|
- Sid: DescribeDeploymentResources
|
|
Effect: Allow
|
|
Action:
|
|
- autoscaling:Describe*
|
|
- ec2:Describe*
|
|
- elasticbeanstalk:DescribeApplicationVersions
|
|
- elasticbeanstalk:DescribeEnvironments
|
|
- elasticbeanstalk:DescribeEvents
|
|
- elasticloadbalancing:Describe*
|
|
Resource: "*"
|
|
- Sid: CreateApplicationVersion
|
|
Effect: Allow
|
|
Action: elasticbeanstalk:CreateApplicationVersion
|
|
Resource:
|
|
- arn:aws:elasticbeanstalk:us-east-1:396287094661:application/shoc-backend
|
|
- arn:aws:elasticbeanstalk:us-east-1:396287094661:applicationversion/shoc-backend/*
|
|
- Sid: UpdateStagingEnvironment
|
|
Effect: Allow
|
|
Action: elasticbeanstalk:UpdateEnvironment
|
|
Resource: arn:aws:elasticbeanstalk:us-east-1:396287094661:environment/shoc-backend/shoc-backend-staging
|
|
- Sid: ManageStagingEnvironmentStack
|
|
Effect: Allow
|
|
Action:
|
|
- cloudformation:CancelUpdateStack
|
|
- cloudformation:DescribeStackEvents
|
|
- cloudformation:DescribeStackResource
|
|
- cloudformation:DescribeStackResources
|
|
- cloudformation:DescribeStacks
|
|
- cloudformation:GetTemplate
|
|
- cloudformation:ListStackResources
|
|
- cloudformation:UpdateStack
|
|
Resource: arn:aws:cloudformation:us-east-1:396287094661:stack/awseb-e-6c9m4vb62z-stack/*
|
|
- Sid: ManageStagingEnvironmentAsg
|
|
Effect: Allow
|
|
Action:
|
|
- autoscaling:PutNotificationConfiguration
|
|
- autoscaling:ResumeProcesses
|
|
- autoscaling:SuspendProcesses
|
|
Resource: arn:aws:autoscaling:us-east-1:396287094661:autoScalingGroup:*:autoScalingGroupName/awseb-e-6c9m4vb62z-stack-*
|
|
- Sid: UploadApplicationVersion
|
|
Effect: Allow
|
|
Action:
|
|
- s3:PutObject
|
|
- s3:PutObjectAcl
|
|
- s3:PutObjectVersionAcl
|
|
- s3:GetObject
|
|
- s3:GetObjectAcl
|
|
- s3:GetObjectVersion
|
|
- s3:GetObjectVersionAcl
|
|
- s3:DeleteObject
|
|
Resource:
|
|
- arn:aws:s3:::elasticbeanstalk-us-east-1-396287094661/shoc-backend/*
|
|
- arn:aws:s3:::elasticbeanstalk-us-east-1-396287094661/resources/_runtime/_embedded_extensions/shoc-backend/*
|
|
- arn:aws:s3:::elasticbeanstalk-us-east-1-396287094661/resources/environments/e-6c9m4vb62z/*
|
|
- Sid: UseBeanstalkBucket
|
|
Effect: Allow
|
|
Action:
|
|
- s3:GetBucketLocation
|
|
- s3:ListBucket
|
|
- s3:GetBucketPolicy
|
|
- s3:GetBucketAcl
|
|
- s3:GetBucketVersioning
|
|
- s3:GetBucketOwnershipControls
|
|
Resource: arn:aws:s3:::elasticbeanstalk-us-east-1-396287094661
|
|
- Sid: ReadDeployParameters
|
|
Effect: Allow
|
|
Action:
|
|
- ssm:GetParameter
|
|
- ssm:GetParameters
|
|
Resource: arn:aws:ssm:us-east-1:396287094661:parameter/shoc-backend/staging/deploy/*
|
|
|
|
# Dedicated runtime ceilings preserve the non-AI portions of
|
|
# AWSElasticBeanstalkWebTier while removing its 2026 Bedrock/Marketplace
|
|
# additions. All S3/log/health resources are pinned to this account and the
|
|
# exact SHOC environment; X-Ray APIs do not support resource scoping.
|
|
ShocBackendDevRuntimeBoundary:
|
|
Type: AWS::IAM::ManagedPolicy
|
|
Condition: IsExternalDevAccount
|
|
DeletionPolicy: Retain
|
|
UpdateReplacePolicy: Retain
|
|
Properties:
|
|
ManagedPolicyName: shoc-backend-dev-runtime-boundary
|
|
Description: Maximum runtime permissions for the SHOC backend dev instance role.
|
|
PolicyDocument:
|
|
Version: "2012-10-17"
|
|
Statement:
|
|
- Sid: ReadAppConfig
|
|
Effect: Allow
|
|
Action: secretsmanager:GetSecretValue
|
|
Resource: arn:aws:secretsmanager:us-east-1:396287094661:secret:shoc/dev/app-config-*
|
|
- Sid: ReadWebhookSecret
|
|
Effect: Allow
|
|
Action:
|
|
- secretsmanager:DescribeSecret
|
|
- secretsmanager:GetSecretValue
|
|
Resource: arn:aws:secretsmanager:us-east-1:011934824531:secret:workorder-ingest/shoc-webhook-hmac-puYTcB
|
|
- Sid: DecryptWebhookSecret
|
|
Effect: Allow
|
|
Action: kms:Decrypt
|
|
Resource: arn:aws:kms:us-east-1:011934824531:key/d10fd1f0-a61a-4405-8568-85e9fd11ba18
|
|
Condition:
|
|
StringEquals:
|
|
"kms:ViaService": secretsmanager.us-east-1.amazonaws.com
|
|
- Sid: AssumeDynamoReader
|
|
Effect: Allow
|
|
Action: sts:AssumeRole
|
|
Resource: arn:aws:iam::328440206208:role/shoc-dynamo-reader
|
|
- Sid: ElasticBeanstalkBucket
|
|
Effect: Allow
|
|
Action:
|
|
- s3:Get*
|
|
- s3:List*
|
|
- s3:PutObject
|
|
Resource:
|
|
- arn:aws:s3:::elasticbeanstalk-us-east-1-396287094661
|
|
- arn:aws:s3:::elasticbeanstalk-us-east-1-396287094661/*
|
|
- Sid: ElasticBeanstalkHealth
|
|
Effect: Allow
|
|
Action: elasticbeanstalk:PutInstanceStatistics
|
|
Resource:
|
|
- arn:aws:elasticbeanstalk:us-east-1:396287094661:application/shoc-backend
|
|
- arn:aws:elasticbeanstalk:us-east-1:396287094661:environment/shoc-backend/shoc-backend-dev
|
|
- Sid: ElasticBeanstalkLogs
|
|
Effect: Allow
|
|
Action:
|
|
- logs:PutLogEvents
|
|
- logs:CreateLogStream
|
|
- logs:DescribeLogStreams
|
|
- logs:DescribeLogGroups
|
|
Resource: arn:aws:logs:us-east-1:396287094661:log-group:/aws/elasticbeanstalk/shoc-backend-dev*
|
|
- Sid: XRayTelemetry
|
|
Effect: Allow
|
|
Action:
|
|
- xray:PutTraceSegments
|
|
- xray:PutTelemetryRecords
|
|
- xray:GetSamplingRules
|
|
- xray:GetSamplingTargets
|
|
- xray:GetSamplingStatisticSummaries
|
|
Resource: "*"
|
|
|
|
ShocBackendStagingRuntimeBoundary:
|
|
Type: AWS::IAM::ManagedPolicy
|
|
Condition: IsExternalDevAccount
|
|
DeletionPolicy: Retain
|
|
UpdateReplacePolicy: Retain
|
|
Properties:
|
|
ManagedPolicyName: shoc-backend-staging-runtime-boundary
|
|
Description: Maximum runtime permissions for the SHOC backend staging instance role.
|
|
PolicyDocument:
|
|
Version: "2012-10-17"
|
|
Statement:
|
|
- Sid: ReadAppConfig
|
|
Effect: Allow
|
|
Action: secretsmanager:GetSecretValue
|
|
Resource: arn:aws:secretsmanager:us-east-1:396287094661:secret:shoc/staging/app-config-*
|
|
- Sid: ReadWebhookSecret
|
|
Effect: Allow
|
|
Action:
|
|
- secretsmanager:DescribeSecret
|
|
- secretsmanager:GetSecretValue
|
|
Resource: arn:aws:secretsmanager:us-east-1:011934824531:secret:workorder-ingest/shoc-webhook-hmac-puYTcB
|
|
- Sid: DecryptWebhookSecret
|
|
Effect: Allow
|
|
Action: kms:Decrypt
|
|
Resource: arn:aws:kms:us-east-1:011934824531:key/d10fd1f0-a61a-4405-8568-85e9fd11ba18
|
|
Condition:
|
|
StringEquals:
|
|
"kms:ViaService": secretsmanager.us-east-1.amazonaws.com
|
|
- Sid: ElasticBeanstalkBucket
|
|
Effect: Allow
|
|
Action:
|
|
- s3:Get*
|
|
- s3:List*
|
|
- s3:PutObject
|
|
Resource:
|
|
- arn:aws:s3:::elasticbeanstalk-us-east-1-396287094661
|
|
- arn:aws:s3:::elasticbeanstalk-us-east-1-396287094661/*
|
|
- Sid: ElasticBeanstalkHealth
|
|
Effect: Allow
|
|
Action: elasticbeanstalk:PutInstanceStatistics
|
|
Resource:
|
|
- arn:aws:elasticbeanstalk:us-east-1:396287094661:application/shoc-backend
|
|
- arn:aws:elasticbeanstalk:us-east-1:396287094661:environment/shoc-backend/shoc-backend-staging
|
|
- Sid: ElasticBeanstalkLogs
|
|
Effect: Allow
|
|
Action:
|
|
- logs:PutLogEvents
|
|
- logs:CreateLogStream
|
|
- logs:DescribeLogStreams
|
|
- logs:DescribeLogGroups
|
|
Resource: arn:aws:logs:us-east-1:396287094661:log-group:/aws/elasticbeanstalk/shoc-backend-staging*
|
|
- Sid: XRayTelemetry
|
|
Effect: Allow
|
|
Action:
|
|
- xray:PutTraceSegments
|
|
- xray:PutTelemetryRecords
|
|
- xray:GetSamplingRules
|
|
- xray:GetSamplingTargets
|
|
- xray:GetSamplingStatisticSummaries
|
|
Resource: "*"
|
|
|
|
# ---------------------------------------------------------------------------
|
|
# shoc-backend import/adoption rehearsal (external-dev only)
|
|
#
|
|
# These roles intentionally do not attach HcptfIamManagementPolicy. Its
|
|
# DenySelfMutation protects every githubdeploy-* role, while this rehearsal
|
|
# must adopt three exact githubdeploy roles. Each apply role instead carries
|
|
# an environment-scoped inline policy. No apply role can create/delete roles,
|
|
# change managed-policy attachments or boundaries, read/write secret
|
|
# values, or pass a role. Live apply roles may UpdateAssumeRolePolicy only
|
|
# on the matching githubdeploy-shoc-backend-{dev,staging} role so the
|
|
# GitHub OIDC job_workflow_ref seam can land. The POC gate controls its new
|
|
# pair independently; the live gate stays false until the four existing
|
|
# dev/staging roles enter through a CloudFormation IMPORT change set.
|
|
#
|
|
# The existing app.terraform.io provider is referenced by literal ARN. The
|
|
# stack instance sets CreateOIDCProvider=false, so external-dev never attempts
|
|
# to create the account-global provider.
|
|
# ---------------------------------------------------------------------------
|
|
HcptfShocBackendPocPlanRole:
|
|
Type: AWS::IAM::Role
|
|
Condition: ShouldManageShocBackendPocRoles
|
|
DeletionPolicy: Retain
|
|
UpdateReplacePolicy: Retain
|
|
Properties:
|
|
RoleName: hcptf-shoc-backend-tf-poc-plan
|
|
Description: Read-only HCP Terraform plan role for the SHOC backend import rehearsal.
|
|
PermissionsBoundary: arn:aws:iam::396287094661:policy/external-dev-execution-boundary
|
|
MaxSessionDuration: 3600
|
|
AssumeRolePolicyDocument:
|
|
Version: "2012-10-17"
|
|
Statement:
|
|
- Effect: Allow
|
|
Principal:
|
|
Federated: arn:aws:iam::396287094661:oidc-provider/app.terraform.io
|
|
Action: sts:AssumeRoleWithWebIdentity
|
|
Condition:
|
|
StringEquals:
|
|
"app.terraform.io:aud": aws.workload.identity
|
|
"app.terraform.io:sub": organization:seahaven:project:seahaven-external-dev:workspace:shoc-backend-tf-poc:run_phase:plan
|
|
Policies:
|
|
- &shocPocReadPolicy
|
|
PolicyName: shoc-backend-tf-poc-import-read
|
|
PolicyDocument:
|
|
Version: "2012-10-17"
|
|
Statement:
|
|
- Sid: CallerIdentity
|
|
Effect: Allow
|
|
Action: sts:GetCallerIdentity
|
|
Resource: "*"
|
|
- Sid: ReadExactIam
|
|
Effect: Allow
|
|
Action:
|
|
- iam:GetInstanceProfile
|
|
- iam:GetRole
|
|
- iam:GetRolePolicy
|
|
- iam:ListAttachedRolePolicies
|
|
- iam:ListInstanceProfileTags
|
|
- iam:ListInstanceProfilesForRole
|
|
- iam:ListRolePolicies
|
|
- iam:ListRoleTags
|
|
Resource:
|
|
- arn:aws:iam::396287094661:role/githubdeploy-shoc-backend-tf-poc
|
|
- arn:aws:iam::396287094661:role/shoc-backend-tf-poc
|
|
- arn:aws:iam::396287094661:instance-profile/shoc-backend-tf-poc
|
|
- arn:aws:iam::396287094661:role/shoc-eb-service-role
|
|
- Sid: ReadOidcProviders
|
|
Effect: Allow
|
|
Action: iam:GetOpenIDConnectProvider
|
|
Resource:
|
|
- arn:aws:iam::396287094661:oidc-provider/app.terraform.io
|
|
- arn:aws:iam::396287094661:oidc-provider/token.actions.githubusercontent.com
|
|
- Sid: ListOidcProviders
|
|
Effect: Allow
|
|
Action: iam:ListOpenIDConnectProviders
|
|
Resource: "*"
|
|
- Sid: ReadSharedInventory
|
|
Effect: Allow
|
|
Action:
|
|
- acm:ListCertificates
|
|
- autoscaling:DescribeAutoScalingGroups
|
|
- ec2:DescribeSecurityGroups
|
|
- ec2:DescribeSubnets
|
|
- ec2:DescribeVpcAttribute
|
|
- ec2:DescribeVpcs
|
|
- elasticbeanstalk:DescribeApplications
|
|
- elasticbeanstalk:DescribeConfigurationOptions
|
|
- elasticbeanstalk:DescribeConfigurationSettings
|
|
- elasticbeanstalk:DescribeEnvironmentResources
|
|
- elasticbeanstalk:DescribeEnvironments
|
|
- elasticbeanstalk:ListTagsForResource
|
|
- rds:DescribeDBInstances
|
|
- route53:ListHostedZonesByName
|
|
Resource: "*"
|
|
- Sid: ReadSharedCertificate
|
|
Effect: Allow
|
|
Action:
|
|
- acm:DescribeCertificate
|
|
- acm:ListTagsForCertificate
|
|
Resource: arn:aws:acm:us-east-1:396287094661:certificate/2b78e74f-7b65-4b82-a413-7a498b102f00
|
|
- Sid: ReadPocCertificate
|
|
Effect: Allow
|
|
Action:
|
|
- acm:DescribeCertificate
|
|
- acm:GetCertificate
|
|
- acm:ListTagsForCertificate
|
|
Resource: arn:aws:acm:us-east-1:396287094661:certificate/*
|
|
Condition:
|
|
StringEquals:
|
|
"aws:ResourceTag/project": shoc
|
|
"aws:ResourceTag/env": tf-poc
|
|
- Sid: ReadSharedRdsTags
|
|
Effect: Allow
|
|
Action: rds:ListTagsForResource
|
|
Resource: arn:aws:rds:us-east-1:396287094661:db:shoc-sqlserver-shared
|
|
- Sid: AccessExistingElasticBeanstalkStorage
|
|
Effect: Allow
|
|
Action:
|
|
- s3:CreateBucket
|
|
- s3:PutBucketOwnershipControls
|
|
Resource: arn:aws:s3:::elasticbeanstalk-us-east-1-396287094661
|
|
- Sid: ReadPocDns
|
|
Effect: Allow
|
|
Action:
|
|
- route53:GetHostedZone
|
|
- route53:ListResourceRecordSets
|
|
- route53:ListTagsForResource
|
|
Resource: arn:aws:route53:::hostedzone/Z02451891BSZD93CMMGDU
|
|
- Sid: ReadRoute53Changes
|
|
Effect: Allow
|
|
Action: route53:GetChange
|
|
Resource: arn:aws:route53:::change/*
|
|
- Sid: ReadPocAppConfigMetadata
|
|
Effect: Allow
|
|
Action:
|
|
- secretsmanager:DescribeSecret
|
|
- secretsmanager:GetResourcePolicy
|
|
- secretsmanager:ListSecretVersionIds
|
|
Resource: arn:aws:secretsmanager:us-east-1:396287094661:secret:shoc/tf-poc/app-config-*
|
|
|
|
HcptfShocBackendPocApplyRole:
|
|
Type: AWS::IAM::Role
|
|
Condition: ShouldManageShocBackendPocRoles
|
|
DeletionPolicy: Retain
|
|
UpdateReplacePolicy: Retain
|
|
Properties:
|
|
RoleName: hcptf-shoc-backend-tf-poc
|
|
Description: Import/adoption HCP Terraform apply role for SHOC backend tf-poc.
|
|
Tags:
|
|
- Key: HcpTerraformWorkspace
|
|
Value: shoc-backend-tf-poc
|
|
PermissionsBoundary: arn:aws:iam::396287094661:policy/external-dev-execution-boundary
|
|
MaxSessionDuration: 3600
|
|
AssumeRolePolicyDocument:
|
|
Version: "2012-10-17"
|
|
Statement:
|
|
- Effect: Allow
|
|
Principal:
|
|
Federated: arn:aws:iam::396287094661:oidc-provider/app.terraform.io
|
|
Action: sts:AssumeRoleWithWebIdentity
|
|
Condition:
|
|
StringEquals:
|
|
"app.terraform.io:aud": aws.workload.identity
|
|
"app.terraform.io:sub": organization:seahaven:project:seahaven-external-dev:workspace:shoc-backend-tf-poc:run_phase:apply
|
|
Policies:
|
|
- *shocPocReadPolicy
|
|
- PolicyName: shoc-backend-tf-poc-import-apply
|
|
PolicyDocument:
|
|
Version: "2012-10-17"
|
|
Statement:
|
|
- Sid: UpdatePocEnvironment
|
|
Effect: Allow
|
|
Action: elasticbeanstalk:UpdateEnvironment
|
|
Resource: arn:aws:elasticbeanstalk:us-east-1:396287094661:environment/shoc-backend/shoc-backend-tf-poc
|
|
- Sid: PutPocRuntimePolicy
|
|
Effect: Allow
|
|
Action: iam:PutRolePolicy
|
|
Resource: arn:aws:iam::396287094661:role/shoc-backend-tf-poc
|
|
Condition:
|
|
StringEquals:
|
|
"iam:PermissionsBoundary": arn:aws:iam::396287094661:policy/shoc-backend-tf-poc-runtime-boundary
|
|
- Sid: TagPocRuntimeRole
|
|
Effect: Allow
|
|
Action:
|
|
- iam:TagRole
|
|
- iam:UntagRole
|
|
Resource: arn:aws:iam::396287094661:role/shoc-backend-tf-poc
|
|
- Sid: ManagePocInstanceProfile
|
|
Effect: Allow
|
|
Action:
|
|
- iam:TagInstanceProfile
|
|
- iam:UntagInstanceProfile
|
|
Resource: arn:aws:iam::396287094661:instance-profile/shoc-backend-tf-poc
|
|
- Sid: PutPocGithubDeployPolicy
|
|
Effect: Allow
|
|
Action: iam:PutRolePolicy
|
|
Resource: arn:aws:iam::396287094661:role/githubdeploy-shoc-backend-tf-poc
|
|
Condition:
|
|
StringEquals:
|
|
"iam:PermissionsBoundary": arn:aws:iam::396287094661:policy/shoc-backend-tf-poc-deploy-boundary
|
|
- Sid: TagPocGithubDeployRole
|
|
Effect: Allow
|
|
Action:
|
|
- iam:TagRole
|
|
- iam:UntagRole
|
|
Resource: arn:aws:iam::396287094661:role/githubdeploy-shoc-backend-tf-poc
|
|
- Sid: TagPocAppConfig
|
|
Effect: Allow
|
|
Action:
|
|
- secretsmanager:TagResource
|
|
- secretsmanager:UntagResource
|
|
Resource: arn:aws:secretsmanager:us-east-1:396287094661:secret:shoc/tf-poc/app-config-*
|
|
- Sid: ChangePocApiAndValidationRecords
|
|
Effect: Allow
|
|
Action: route53:ChangeResourceRecordSets
|
|
Resource: arn:aws:route53:::hostedzone/Z02451891BSZD93CMMGDU
|
|
Condition:
|
|
ForAllValues:StringLike:
|
|
"route53:ChangeResourceRecordSetsNormalizedRecordNames":
|
|
- api.tf-poc.seahaven.com
|
|
- "*.tf-poc.seahaven.com"
|
|
ForAllValues:StringEquals:
|
|
"route53:ChangeResourceRecordSetsRecordTypes":
|
|
- CNAME
|
|
- Sid: TagPocHostedZone
|
|
Effect: Allow
|
|
Action: route53:ChangeTagsForResource
|
|
Resource: arn:aws:route53:::hostedzone/Z02451891BSZD93CMMGDU
|
|
- Sid: TagPocCertificate
|
|
Effect: Allow
|
|
Action:
|
|
- acm:AddTagsToCertificate
|
|
- acm:RemoveTagsFromCertificate
|
|
Resource: arn:aws:acm:us-east-1:396287094661:certificate/*
|
|
Condition:
|
|
StringEquals:
|
|
"aws:ResourceTag/project": shoc
|
|
"aws:ResourceTag/env": tf-poc
|
|
- Sid: TerminatePocEnvironment
|
|
Effect: Allow
|
|
Action: elasticbeanstalk:TerminateEnvironment
|
|
Resource: arn:aws:elasticbeanstalk:us-east-1:396287094661:environment/shoc-backend/shoc-backend-tf-poc
|
|
- Sid: DeletePocRuntimeIam
|
|
Effect: Allow
|
|
Action:
|
|
- iam:DeleteRole
|
|
- iam:DeleteRolePolicy
|
|
- iam:DetachRolePolicy
|
|
Resource: arn:aws:iam::396287094661:role/shoc-backend-tf-poc
|
|
- Sid: DeletePocInstanceProfile
|
|
Effect: Allow
|
|
Action:
|
|
- iam:DeleteInstanceProfile
|
|
- iam:RemoveRoleFromInstanceProfile
|
|
Resource: arn:aws:iam::396287094661:instance-profile/shoc-backend-tf-poc
|
|
- Sid: DeletePocAppConfig
|
|
Effect: Allow
|
|
Action: secretsmanager:DeleteSecret
|
|
Resource: arn:aws:secretsmanager:us-east-1:396287094661:secret:shoc/tf-poc/app-config-*
|
|
- Sid: DeletePocHostedZone
|
|
Effect: Allow
|
|
Action: route53:DeleteHostedZone
|
|
Resource: arn:aws:route53:::hostedzone/Z02451891BSZD93CMMGDU
|
|
- Sid: DeletePocCertificate
|
|
Effect: Allow
|
|
Action: acm:DeleteCertificate
|
|
Resource: arn:aws:acm:us-east-1:396287094661:certificate/*
|
|
Condition:
|
|
StringEquals:
|
|
"aws:ResourceTag/project": shoc
|
|
"aws:ResourceTag/env": tf-poc
|
|
|
|
HcptfShocBackendDevPlanRole:
|
|
Type: AWS::IAM::Role
|
|
Condition: ShouldManageShocBackendLiveRoles
|
|
DeletionPolicy: Retain
|
|
UpdateReplacePolicy: Retain
|
|
Properties:
|
|
RoleName: hcptf-shoc-backend-dev-plan
|
|
Description: Read-only HCP Terraform plan role for SHOC backend dev import.
|
|
PermissionsBoundary: arn:aws:iam::396287094661:policy/external-dev-execution-boundary
|
|
MaxSessionDuration: 3600
|
|
AssumeRolePolicyDocument:
|
|
Version: "2012-10-17"
|
|
Statement:
|
|
- Effect: Allow
|
|
Principal:
|
|
Federated: arn:aws:iam::396287094661:oidc-provider/app.terraform.io
|
|
Action: sts:AssumeRoleWithWebIdentity
|
|
Condition:
|
|
StringEquals:
|
|
"app.terraform.io:aud": aws.workload.identity
|
|
"app.terraform.io:sub": organization:seahaven:project:seahaven-external-dev:workspace:shoc-backend-dev:run_phase:plan
|
|
Policies:
|
|
- &shocDevReadPolicy
|
|
PolicyName: shoc-backend-dev-import-read
|
|
PolicyDocument:
|
|
Version: "2012-10-17"
|
|
Statement:
|
|
- Sid: CallerIdentity
|
|
Effect: Allow
|
|
Action: sts:GetCallerIdentity
|
|
Resource: "*"
|
|
- Sid: ReadExactIam
|
|
Effect: Allow
|
|
Action:
|
|
- iam:GetInstanceProfile
|
|
- iam:GetRole
|
|
- iam:GetRolePolicy
|
|
- iam:ListAttachedRolePolicies
|
|
- iam:ListInstanceProfileTags
|
|
- iam:ListInstanceProfilesForRole
|
|
- iam:ListRolePolicies
|
|
- iam:ListRoleTags
|
|
Resource:
|
|
- arn:aws:iam::396287094661:role/githubdeploy-shoc-backend-dev
|
|
- arn:aws:iam::396287094661:role/shoc-backend-dev
|
|
- arn:aws:iam::396287094661:instance-profile/shoc-backend-dev
|
|
- arn:aws:iam::396287094661:role/shoc-eb-service-role
|
|
- Sid: ReadGithubOidc
|
|
Effect: Allow
|
|
Action: iam:GetOpenIDConnectProvider
|
|
Resource: arn:aws:iam::396287094661:oidc-provider/token.actions.githubusercontent.com
|
|
- Sid: ListOidcProviders
|
|
Effect: Allow
|
|
Action: iam:ListOpenIDConnectProviders
|
|
Resource: "*"
|
|
- Sid: ReadSharedInventory
|
|
Effect: Allow
|
|
Action:
|
|
- acm:ListCertificates
|
|
- autoscaling:DescribeAutoScalingGroups
|
|
- ec2:DescribeSecurityGroups
|
|
- ec2:DescribeSubnets
|
|
- ec2:DescribeVpcs
|
|
- elasticbeanstalk:DescribeApplications
|
|
- elasticbeanstalk:DescribeConfigurationOptions
|
|
- elasticbeanstalk:DescribeConfigurationSettings
|
|
- elasticbeanstalk:DescribeEnvironmentResources
|
|
- elasticbeanstalk:DescribeEnvironments
|
|
- elasticbeanstalk:ListTagsForResource
|
|
- rds:DescribeDBInstances
|
|
- route53:ListHostedZones
|
|
- route53:ListHostedZonesByName
|
|
Resource: "*"
|
|
# Elastic Beanstalk DescribeConfigurationSettings calls
|
|
# CreateBucket against its existing regional service bucket
|
|
# during both plan and apply refresh.
|
|
- Sid: AuthorizeExistingEbBucketDiscovery
|
|
Effect: Allow
|
|
Action:
|
|
- s3:CreateBucket
|
|
- s3:PutBucketOwnershipControls
|
|
Resource: arn:aws:s3:::elasticbeanstalk-us-east-1-396287094661
|
|
Condition:
|
|
StringEquals:
|
|
s3:x-amz-object-ownership: ObjectWriter
|
|
- Sid: ReadSharedCertificate
|
|
Effect: Allow
|
|
Action:
|
|
- acm:DescribeCertificate
|
|
- acm:GetCertificate
|
|
- acm:ListTagsForCertificate
|
|
Resource: arn:aws:acm:us-east-1:396287094661:certificate/2b78e74f-7b65-4b82-a413-7a498b102f00
|
|
- Sid: ReadSharedRdsTags
|
|
Effect: Allow
|
|
Action: rds:ListTagsForResource
|
|
Resource: arn:aws:rds:us-east-1:396287094661:db:shoc-sqlserver-shared
|
|
- Sid: ReadDevDns
|
|
Effect: Allow
|
|
Action:
|
|
- route53:GetHostedZone
|
|
- route53:GetChange
|
|
- route53:ListResourceRecordSets
|
|
- route53:ListTagsForResource
|
|
Resource:
|
|
- arn:aws:route53:::hostedzone/Z07671212N75U4YLPWZR8
|
|
- arn:aws:route53:::change/*
|
|
- Sid: ReadDevAppConfigMetadata
|
|
Effect: Allow
|
|
Action:
|
|
- secretsmanager:DescribeSecret
|
|
- secretsmanager:GetResourcePolicy
|
|
- secretsmanager:ListSecretVersionIds
|
|
Resource: arn:aws:secretsmanager:us-east-1:396287094661:secret:shoc/dev/app-config-*
|
|
- Sid: ReadDevDeploySsm
|
|
Effect: Allow
|
|
Action:
|
|
- ssm:GetParameter
|
|
- ssm:GetParameters
|
|
- ssm:ListTagsForResource
|
|
Resource: arn:aws:ssm:us-east-1:396287094661:parameter/shoc-backend/dev/deploy/*
|
|
- Sid: DescribeDevDeploySsm
|
|
Effect: Allow
|
|
Action: ssm:DescribeParameters
|
|
Resource: "*"
|
|
|
|
HcptfShocBackendDevApplyRole:
|
|
Type: AWS::IAM::Role
|
|
Condition: ShouldManageShocBackendLiveRoles
|
|
DeletionPolicy: Retain
|
|
UpdateReplacePolicy: Retain
|
|
Properties:
|
|
RoleName: hcptf-shoc-backend-dev
|
|
Description: Import/adoption HCP Terraform apply role for SHOC backend dev.
|
|
Tags:
|
|
- Key: HcpTerraformWorkspace
|
|
Value: shoc-backend-dev
|
|
PermissionsBoundary: arn:aws:iam::396287094661:policy/external-dev-execution-boundary
|
|
MaxSessionDuration: 3600
|
|
AssumeRolePolicyDocument:
|
|
Version: "2012-10-17"
|
|
Statement:
|
|
- Effect: Allow
|
|
Principal:
|
|
Federated: arn:aws:iam::396287094661:oidc-provider/app.terraform.io
|
|
Action: sts:AssumeRoleWithWebIdentity
|
|
Condition:
|
|
StringEquals:
|
|
"app.terraform.io:aud": aws.workload.identity
|
|
"app.terraform.io:sub": organization:seahaven:project:seahaven-external-dev:workspace:shoc-backend-dev:run_phase:apply
|
|
Policies:
|
|
- *shocDevReadPolicy
|
|
- PolicyName: shoc-backend-dev-import-apply
|
|
PolicyDocument:
|
|
Version: "2012-10-17"
|
|
Statement:
|
|
- Sid: UpdateDevEnvironment
|
|
Effect: Allow
|
|
Action:
|
|
- elasticbeanstalk:UpdateEnvironment
|
|
- elasticbeanstalk:UpdateTagsForResource
|
|
Resource: arn:aws:elasticbeanstalk:us-east-1:396287094661:environment/shoc-backend/shoc-backend-dev
|
|
- Sid: ManageDevEnvironmentStack
|
|
Effect: Allow
|
|
Action:
|
|
- cloudformation:CancelUpdateStack
|
|
- cloudformation:DescribeStackEvents
|
|
- cloudformation:DescribeStackResource
|
|
- cloudformation:DescribeStackResources
|
|
- cloudformation:DescribeStacks
|
|
- cloudformation:GetTemplate
|
|
- cloudformation:ListStackResources
|
|
- cloudformation:UpdateStack
|
|
Resource: arn:aws:cloudformation:us-east-1:396287094661:stack/awseb-e-hehnrqjjrt-stack/*
|
|
- Sid: DescribeDeploymentResources
|
|
Effect: Allow
|
|
Action:
|
|
- autoscaling:Describe*
|
|
- ec2:Describe*
|
|
- elasticloadbalancing:Describe*
|
|
Resource: "*"
|
|
- Sid: ManageDevEnvironmentAsg
|
|
Effect: Allow
|
|
Action:
|
|
- autoscaling:PutNotificationConfiguration
|
|
- autoscaling:ResumeProcesses
|
|
- autoscaling:SuspendProcesses
|
|
Resource: arn:aws:autoscaling:us-east-1:396287094661:autoScalingGroup:*:autoScalingGroupName/awseb-e-hehnrqjjrt-stack-*
|
|
- Sid: LegacyBeanstalkObjects
|
|
Effect: Allow
|
|
Action:
|
|
- s3:Delete*
|
|
- s3:Get*
|
|
- s3:Put*
|
|
Resource: arn:aws:s3:::elasticbeanstalk-*/*
|
|
- Sid: LegacyBeanstalkBuckets
|
|
Effect: Allow
|
|
Action:
|
|
- s3:GetBucket*
|
|
- s3:ListBucket
|
|
- s3:PutBucketOwnershipControls
|
|
- s3:PutBucketPolicy
|
|
- s3:PutBucketPublicAccessBlock
|
|
Resource: arn:aws:s3:::elasticbeanstalk-*
|
|
- Sid: PutDevRuntimePolicy
|
|
Effect: Allow
|
|
Action: iam:PutRolePolicy
|
|
Resource: arn:aws:iam::396287094661:role/shoc-backend-dev
|
|
Condition:
|
|
StringEquals:
|
|
"iam:PermissionsBoundary": arn:aws:iam::396287094661:policy/shoc-backend-dev-runtime-boundary
|
|
- Sid: TagDevRuntimeRole
|
|
Effect: Allow
|
|
Action:
|
|
- iam:TagRole
|
|
- iam:UntagRole
|
|
Resource: arn:aws:iam::396287094661:role/shoc-backend-dev
|
|
- Sid: ManageDevInstanceProfile
|
|
Effect: Allow
|
|
Action:
|
|
- iam:TagInstanceProfile
|
|
- iam:UntagInstanceProfile
|
|
Resource: arn:aws:iam::396287094661:instance-profile/shoc-backend-dev
|
|
- Sid: PutDevGithubDeployPolicy
|
|
Effect: Allow
|
|
Action: iam:PutRolePolicy
|
|
Resource: arn:aws:iam::396287094661:role/githubdeploy-shoc-backend-dev
|
|
Condition:
|
|
StringEquals:
|
|
"iam:PermissionsBoundary": arn:aws:iam::396287094661:policy/shoc-backend-dev-deploy-boundary
|
|
- Sid: TagDevGithubDeployRole
|
|
Effect: Allow
|
|
Action:
|
|
- iam:TagRole
|
|
- iam:UntagRole
|
|
Resource: arn:aws:iam::396287094661:role/githubdeploy-shoc-backend-dev
|
|
- Sid: UpdateDevGithubDeployTrust
|
|
Effect: Allow
|
|
Action: iam:UpdateAssumeRolePolicy
|
|
Resource: arn:aws:iam::396287094661:role/githubdeploy-shoc-backend-dev
|
|
- Sid: ManageDevDeploySsm
|
|
Effect: Allow
|
|
Action:
|
|
- ssm:PutParameter
|
|
- ssm:AddTagsToResource
|
|
- ssm:RemoveTagsFromResource
|
|
Resource: arn:aws:ssm:us-east-1:396287094661:parameter/shoc-backend/dev/deploy/*
|
|
- Sid: TagDevAppConfig
|
|
Effect: Allow
|
|
Action:
|
|
- secretsmanager:TagResource
|
|
- secretsmanager:UntagResource
|
|
Resource: arn:aws:secretsmanager:us-east-1:396287094661:secret:shoc/dev/app-config-*
|
|
- Sid: ChangeDevApiRecord
|
|
Effect: Allow
|
|
Action: route53:ChangeResourceRecordSets
|
|
Resource: arn:aws:route53:::hostedzone/Z07671212N75U4YLPWZR8
|
|
Condition:
|
|
ForAllValues:StringEquals:
|
|
"route53:ChangeResourceRecordSetsNormalizedRecordNames":
|
|
- api.dev.seahaven.com
|
|
"route53:ChangeResourceRecordSetsRecordTypes":
|
|
- A
|
|
|
|
HcptfShocBackendStagingPlanRole:
|
|
Type: AWS::IAM::Role
|
|
Condition: ShouldManageShocBackendLiveRoles
|
|
DeletionPolicy: Retain
|
|
UpdateReplacePolicy: Retain
|
|
Properties:
|
|
RoleName: hcptf-shoc-backend-staging-plan
|
|
Description: Read-only HCP Terraform plan role for SHOC backend staging import.
|
|
PermissionsBoundary: arn:aws:iam::396287094661:policy/external-dev-execution-boundary
|
|
MaxSessionDuration: 3600
|
|
AssumeRolePolicyDocument:
|
|
Version: "2012-10-17"
|
|
Statement:
|
|
- Effect: Allow
|
|
Principal:
|
|
Federated: arn:aws:iam::396287094661:oidc-provider/app.terraform.io
|
|
Action: sts:AssumeRoleWithWebIdentity
|
|
Condition:
|
|
StringEquals:
|
|
"app.terraform.io:aud": aws.workload.identity
|
|
"app.terraform.io:sub": organization:seahaven:project:seahaven-external-dev:workspace:shoc-backend-staging:run_phase:plan
|
|
Policies:
|
|
- &shocStagingReadPolicy
|
|
PolicyName: shoc-backend-staging-import-read
|
|
PolicyDocument:
|
|
Version: "2012-10-17"
|
|
Statement:
|
|
- Sid: CallerIdentity
|
|
Effect: Allow
|
|
Action: sts:GetCallerIdentity
|
|
Resource: "*"
|
|
- Sid: ReadExactIam
|
|
Effect: Allow
|
|
Action:
|
|
- iam:GetInstanceProfile
|
|
- iam:GetRole
|
|
- iam:GetRolePolicy
|
|
- iam:ListAttachedRolePolicies
|
|
- iam:ListInstanceProfileTags
|
|
- iam:ListInstanceProfilesForRole
|
|
- iam:ListRolePolicies
|
|
- iam:ListRoleTags
|
|
Resource:
|
|
- arn:aws:iam::396287094661:role/githubdeploy-shoc-backend-staging
|
|
- arn:aws:iam::396287094661:role/shoc-backend-staging
|
|
- arn:aws:iam::396287094661:instance-profile/shoc-backend-staging
|
|
- arn:aws:iam::396287094661:role/shoc-eb-service-role
|
|
- Sid: ReadGithubOidc
|
|
Effect: Allow
|
|
Action: iam:GetOpenIDConnectProvider
|
|
Resource: arn:aws:iam::396287094661:oidc-provider/token.actions.githubusercontent.com
|
|
- Sid: ListOidcProviders
|
|
Effect: Allow
|
|
Action: iam:ListOpenIDConnectProviders
|
|
Resource: "*"
|
|
- Sid: ReadSharedInventory
|
|
Effect: Allow
|
|
Action:
|
|
- acm:ListCertificates
|
|
- autoscaling:DescribeAutoScalingGroups
|
|
- ec2:DescribeSecurityGroups
|
|
- ec2:DescribeSubnets
|
|
- ec2:DescribeVpcs
|
|
- elasticbeanstalk:DescribeApplications
|
|
- elasticbeanstalk:DescribeConfigurationOptions
|
|
- elasticbeanstalk:DescribeConfigurationSettings
|
|
- elasticbeanstalk:DescribeEnvironmentResources
|
|
- elasticbeanstalk:DescribeEnvironments
|
|
- elasticbeanstalk:ListTagsForResource
|
|
- rds:DescribeDBInstances
|
|
- route53:ListHostedZones
|
|
- route53:ListHostedZonesByName
|
|
Resource: "*"
|
|
# Elastic Beanstalk DescribeConfigurationSettings calls
|
|
# CreateBucket against its existing regional service bucket
|
|
# during both plan and apply refresh.
|
|
- Sid: AuthorizeExistingEbBucketDiscovery
|
|
Effect: Allow
|
|
Action:
|
|
- s3:CreateBucket
|
|
- s3:PutBucketOwnershipControls
|
|
Resource: arn:aws:s3:::elasticbeanstalk-us-east-1-396287094661
|
|
Condition:
|
|
StringEquals:
|
|
s3:x-amz-object-ownership: ObjectWriter
|
|
- Sid: ReadSharedCertificate
|
|
Effect: Allow
|
|
Action:
|
|
- acm:DescribeCertificate
|
|
- acm:GetCertificate
|
|
- acm:ListTagsForCertificate
|
|
Resource: arn:aws:acm:us-east-1:396287094661:certificate/2b78e74f-7b65-4b82-a413-7a498b102f00
|
|
- Sid: ReadSharedRdsTags
|
|
Effect: Allow
|
|
Action: rds:ListTagsForResource
|
|
Resource: arn:aws:rds:us-east-1:396287094661:db:shoc-sqlserver-shared
|
|
- Sid: ReadStagingDns
|
|
Effect: Allow
|
|
Action:
|
|
- route53:GetHostedZone
|
|
- route53:GetChange
|
|
- route53:ListResourceRecordSets
|
|
- route53:ListTagsForResource
|
|
Resource:
|
|
- arn:aws:route53:::hostedzone/Z02602739VQWBWCAGXP4
|
|
- arn:aws:route53:::change/*
|
|
- Sid: ReadStagingAppConfigMetadata
|
|
Effect: Allow
|
|
Action:
|
|
- secretsmanager:DescribeSecret
|
|
- secretsmanager:GetResourcePolicy
|
|
- secretsmanager:ListSecretVersionIds
|
|
Resource: arn:aws:secretsmanager:us-east-1:396287094661:secret:shoc/staging/app-config-*
|
|
- Sid: ReadStagingDeploySsm
|
|
Effect: Allow
|
|
Action:
|
|
- ssm:GetParameter
|
|
- ssm:GetParameters
|
|
- ssm:ListTagsForResource
|
|
Resource: arn:aws:ssm:us-east-1:396287094661:parameter/shoc-backend/staging/deploy/*
|
|
- Sid: DescribeStagingDeploySsm
|
|
Effect: Allow
|
|
Action: ssm:DescribeParameters
|
|
Resource: "*"
|
|
|
|
HcptfShocBackendStagingApplyRole:
|
|
Type: AWS::IAM::Role
|
|
Condition: ShouldManageShocBackendLiveRoles
|
|
DeletionPolicy: Retain
|
|
UpdateReplacePolicy: Retain
|
|
Properties:
|
|
RoleName: hcptf-shoc-backend-staging
|
|
Description: Import/adoption HCP Terraform apply role for SHOC backend staging.
|
|
Tags:
|
|
- Key: HcpTerraformWorkspace
|
|
Value: shoc-backend-staging
|
|
PermissionsBoundary: arn:aws:iam::396287094661:policy/external-dev-execution-boundary
|
|
MaxSessionDuration: 3600
|
|
AssumeRolePolicyDocument:
|
|
Version: "2012-10-17"
|
|
Statement:
|
|
- Effect: Allow
|
|
Principal:
|
|
Federated: arn:aws:iam::396287094661:oidc-provider/app.terraform.io
|
|
Action: sts:AssumeRoleWithWebIdentity
|
|
Condition:
|
|
StringEquals:
|
|
"app.terraform.io:aud": aws.workload.identity
|
|
"app.terraform.io:sub": organization:seahaven:project:seahaven-external-dev:workspace:shoc-backend-staging:run_phase:apply
|
|
Policies:
|
|
- *shocStagingReadPolicy
|
|
- PolicyName: shoc-backend-staging-import-apply
|
|
PolicyDocument:
|
|
Version: "2012-10-17"
|
|
Statement:
|
|
- Sid: UpdateStagingEnvironment
|
|
Effect: Allow
|
|
Action:
|
|
- elasticbeanstalk:UpdateEnvironment
|
|
- elasticbeanstalk:UpdateTagsForResource
|
|
Resource: arn:aws:elasticbeanstalk:us-east-1:396287094661:environment/shoc-backend/shoc-backend-staging
|
|
- Sid: ManageStagingEnvironmentStack
|
|
Effect: Allow
|
|
Action:
|
|
- cloudformation:CancelUpdateStack
|
|
- cloudformation:DescribeStackEvents
|
|
- cloudformation:DescribeStackResource
|
|
- cloudformation:DescribeStackResources
|
|
- cloudformation:DescribeStacks
|
|
- cloudformation:GetTemplate
|
|
- cloudformation:ListStackResources
|
|
- cloudformation:UpdateStack
|
|
Resource: arn:aws:cloudformation:us-east-1:396287094661:stack/awseb-e-6c9m4vb62z-stack/*
|
|
- Sid: DescribeDeploymentResources
|
|
Effect: Allow
|
|
Action:
|
|
- autoscaling:Describe*
|
|
- ec2:Describe*
|
|
- elasticloadbalancing:Describe*
|
|
Resource: "*"
|
|
- Sid: ManageStagingEnvironmentAsg
|
|
Effect: Allow
|
|
Action:
|
|
- autoscaling:PutNotificationConfiguration
|
|
- autoscaling:ResumeProcesses
|
|
- autoscaling:SuspendProcesses
|
|
Resource: arn:aws:autoscaling:us-east-1:396287094661:autoScalingGroup:*:autoScalingGroupName/awseb-e-6c9m4vb62z-stack-*
|
|
- Sid: StagingBeanstalkObjects
|
|
Effect: Allow
|
|
Action:
|
|
- s3:Delete*
|
|
- s3:Get*
|
|
- s3:Put*
|
|
Resource: arn:aws:s3:::elasticbeanstalk-us-east-1-396287094661/*
|
|
- Sid: StagingBeanstalkBuckets
|
|
Effect: Allow
|
|
Action:
|
|
- s3:GetBucket*
|
|
- s3:ListBucket
|
|
- s3:PutBucketOwnershipControls
|
|
- s3:PutBucketPolicy
|
|
- s3:PutBucketPublicAccessBlock
|
|
Resource: arn:aws:s3:::elasticbeanstalk-us-east-1-396287094661
|
|
# Elastic Beanstalk stages the CloudFormation template for
|
|
# configuration UpdateStack calls in its AWS-owned regional
|
|
# bucket and CloudFormation fetches it with the caller's
|
|
# credentials. Zip deploys never touch this path.
|
|
- Sid: ReadBeanstalkServiceTemplates
|
|
Effect: Allow
|
|
Action:
|
|
- s3:GetObject
|
|
- s3:GetObjectVersion
|
|
Resource: arn:aws:s3:::elasticbeanstalk-us-east-1/*
|
|
- Sid: ManageCloudFormationTemplates
|
|
Effect: Allow
|
|
Action:
|
|
- s3:CreateBucket
|
|
- s3:GetBucket*
|
|
- s3:ListBucket
|
|
- s3:PutBucketPolicy
|
|
- s3:PutBucketOwnershipControls
|
|
- s3:PutBucketPublicAccessBlock
|
|
- s3:PutEncryptionConfiguration
|
|
Resource: arn:aws:s3:::cf-templates-*
|
|
- Sid: ManageCloudFormationTemplateObjects
|
|
Effect: Allow
|
|
Action:
|
|
- s3:Get*
|
|
- s3:Put*
|
|
- s3:Delete*
|
|
Resource: arn:aws:s3:::cf-templates-*/*
|
|
- Sid: PutStagingRuntimePolicy
|
|
Effect: Allow
|
|
Action: iam:PutRolePolicy
|
|
Resource: arn:aws:iam::396287094661:role/shoc-backend-staging
|
|
Condition:
|
|
StringEquals:
|
|
"iam:PermissionsBoundary": arn:aws:iam::396287094661:policy/shoc-backend-staging-runtime-boundary
|
|
- Sid: UpdateStagingRuntimeTrust
|
|
Effect: Allow
|
|
Action:
|
|
- iam:UpdateAssumeRolePolicy
|
|
- iam:UpdateRole
|
|
- iam:UpdateRoleDescription
|
|
Resource: arn:aws:iam::396287094661:role/shoc-backend-staging
|
|
- Sid: TagStagingRuntimeRole
|
|
Effect: Allow
|
|
Action:
|
|
- iam:TagRole
|
|
- iam:UntagRole
|
|
Resource: arn:aws:iam::396287094661:role/shoc-backend-staging
|
|
- Sid: ManageStagingInstanceProfile
|
|
Effect: Allow
|
|
Action:
|
|
- iam:TagInstanceProfile
|
|
- iam:UntagInstanceProfile
|
|
Resource: arn:aws:iam::396287094661:instance-profile/shoc-backend-staging
|
|
- Sid: PutStagingGithubDeployPolicy
|
|
Effect: Allow
|
|
Action: iam:PutRolePolicy
|
|
Resource: arn:aws:iam::396287094661:role/githubdeploy-shoc-backend-staging
|
|
Condition:
|
|
StringEquals:
|
|
"iam:PermissionsBoundary": arn:aws:iam::396287094661:policy/shoc-backend-staging-deploy-boundary
|
|
- Sid: TagStagingGithubDeployRole
|
|
Effect: Allow
|
|
Action:
|
|
- iam:TagRole
|
|
- iam:UntagRole
|
|
Resource: arn:aws:iam::396287094661:role/githubdeploy-shoc-backend-staging
|
|
- Sid: UpdateStagingGithubDeployTrust
|
|
Effect: Allow
|
|
Action: iam:UpdateAssumeRolePolicy
|
|
Resource: arn:aws:iam::396287094661:role/githubdeploy-shoc-backend-staging
|
|
- Sid: ManageStagingDeploySsm
|
|
Effect: Allow
|
|
Action:
|
|
- ssm:PutParameter
|
|
- ssm:AddTagsToResource
|
|
- ssm:RemoveTagsFromResource
|
|
Resource: arn:aws:ssm:us-east-1:396287094661:parameter/shoc-backend/staging/deploy/*
|
|
- Sid: TagStagingAppConfig
|
|
Effect: Allow
|
|
Action:
|
|
- secretsmanager:TagResource
|
|
- secretsmanager:UntagResource
|
|
Resource: arn:aws:secretsmanager:us-east-1:396287094661:secret:shoc/staging/app-config-*
|
|
- Sid: ChangeStagingApiRecord
|
|
Effect: Allow
|
|
Action: route53:ChangeResourceRecordSets
|
|
Resource: arn:aws:route53:::hostedzone/Z02602739VQWBWCAGXP4
|
|
Condition:
|
|
ForAllValues:StringEquals:
|
|
"route53:ChangeResourceRecordSetsNormalizedRecordNames":
|
|
- api.staging.seahaven.com
|
|
"route53:ChangeResourceRecordSetsRecordTypes":
|
|
- CNAME
|