mirror of
https://github.com/Sea-Haven-Industries/seahaven-site.git
synced 2026-10-03 03:23:14 +00:00
fix(iam): drop lambda boundary from github deploy role (PLAT-52)
This commit is contained in:
parent
cf7e407386
commit
a8b617d782
2 changed files with 9 additions and 8 deletions
|
|
@ -23,11 +23,13 @@ data "aws_iam_policy_document" "github_deploy_assume" {
|
|||
}
|
||||
|
||||
resource "aws_iam_role" "github_deploy" {
|
||||
name = local.deploy_role
|
||||
path = "/tf-managed/"
|
||||
description = "GitHub Actions content-deploy role for ${var.github_repo}@${var.github_deploy_branch}"
|
||||
name = local.deploy_role
|
||||
path = "/tf-managed/"
|
||||
description = "GitHub Actions content-deploy role for ${var.github_repo}@${var.github_deploy_branch}"
|
||||
# Not a Lambda execution role. Do not attach seahaven-lambda-execution-boundary
|
||||
# (PLAT-52). HCP apply cannot DeleteRolePermissionsBoundary (DenyBoundaryTampering);
|
||||
# stripping the live attachment is an administrator action after this apply.
|
||||
assume_role_policy = data.aws_iam_policy_document.github_deploy_assume.json
|
||||
permissions_boundary = local.boundary_arn
|
||||
max_session_duration = 3600
|
||||
}
|
||||
|
||||
|
|
|
|||
|
|
@ -1,8 +1,7 @@
|
|||
locals {
|
||||
account_id = data.aws_caller_identity.current.account_id
|
||||
boundary_arn = "arn:aws:iam::${local.account_id}:policy/seahaven-lambda-execution-boundary"
|
||||
bucket_name = "seahaven-site-prod"
|
||||
deploy_role = "githubdeploy-seahaven-site"
|
||||
account_id = data.aws_caller_identity.current.account_id
|
||||
bucket_name = "seahaven-site-prod"
|
||||
deploy_role = "githubdeploy-seahaven-site"
|
||||
}
|
||||
|
||||
data "aws_caller_identity" "current" {}
|
||||
|
|
|
|||
Loading…
Add table
Reference in a new issue