fix(iam): drop lambda boundary from github deploy role (PLAT-52)

This commit is contained in:
Adam Moussa 2026-08-20 14:31:30 -04:00
parent cf7e407386
commit a8b617d782
No known key found for this signature in database
2 changed files with 9 additions and 8 deletions

View file

@ -23,11 +23,13 @@ data "aws_iam_policy_document" "github_deploy_assume" {
}
resource "aws_iam_role" "github_deploy" {
name = local.deploy_role
path = "/tf-managed/"
description = "GitHub Actions content-deploy role for ${var.github_repo}@${var.github_deploy_branch}"
name = local.deploy_role
path = "/tf-managed/"
description = "GitHub Actions content-deploy role for ${var.github_repo}@${var.github_deploy_branch}"
# Not a Lambda execution role. Do not attach seahaven-lambda-execution-boundary
# (PLAT-52). HCP apply cannot DeleteRolePermissionsBoundary (DenyBoundaryTampering);
# stripping the live attachment is an administrator action after this apply.
assume_role_policy = data.aws_iam_policy_document.github_deploy_assume.json
permissions_boundary = local.boundary_arn
max_session_duration = 3600
}

View file

@ -1,8 +1,7 @@
locals {
account_id = data.aws_caller_identity.current.account_id
boundary_arn = "arn:aws:iam::${local.account_id}:policy/seahaven-lambda-execution-boundary"
bucket_name = "seahaven-site-prod"
deploy_role = "githubdeploy-seahaven-site"
account_id = data.aws_caller_identity.current.account_id
bucket_name = "seahaven-site-prod"
deploy_role = "githubdeploy-seahaven-site"
}
data "aws_caller_identity" "current" {}