mirror of
https://github.com/Sea-Haven-Industries/seahaven-org-baseline.git
synced 2026-09-30 04:33:15 +00:00
SAM repos migrating off the frozen management account need the shared deploy plumbing (permissions boundary + github-cfn-execution-role) in their target account; none of it existed outside mgmt, so there was no OIDC SAM deploy path into seahaven-prod or seahaven-dev at all. Adds a templated, per-account substrate stack so onboarding a future account is one bin/app.ts instance plus one CD job, not a hand-rolled copy. Per-repo githubdeploy-* roles stay out by design: they are provisioned per repo at migration time so an account never accumulates trust for repos that do not deploy to it. The template is a verbatim extraction of the reviewed mgmt substrate, with deliberate, documented divergences — notably the removal of iam:DeleteRolePermissionsBoundary plus explicit Deny backstops, which closes a confirmed privilege-escalation path (see PR body). |
||
|---|---|---|
| .. | ||
| workflows | ||
| dependabot.yml | ||