diff --git a/terraform/iam_github_deploy.tf b/terraform/iam_github_deploy.tf index 6a115ef..343c6c8 100644 --- a/terraform/iam_github_deploy.tf +++ b/terraform/iam_github_deploy.tf @@ -23,11 +23,13 @@ data "aws_iam_policy_document" "github_deploy_assume" { } resource "aws_iam_role" "github_deploy" { - name = local.deploy_role - path = "/tf-managed/" - description = "GitHub Actions content-deploy role for ${var.github_repo}@${var.github_deploy_branch}" + name = local.deploy_role + path = "/tf-managed/" + description = "GitHub Actions content-deploy role for ${var.github_repo}@${var.github_deploy_branch}" + # Not a Lambda execution role. Do not attach seahaven-lambda-execution-boundary + # (PLAT-52). HCP apply cannot DeleteRolePermissionsBoundary (DenyBoundaryTampering); + # stripping the live attachment is an administrator action after this apply. assume_role_policy = data.aws_iam_policy_document.github_deploy_assume.json - permissions_boundary = local.boundary_arn max_session_duration = 3600 } diff --git a/terraform/locals.tf b/terraform/locals.tf index 40f0b7a..dcd72d4 100644 --- a/terraform/locals.tf +++ b/terraform/locals.tf @@ -1,8 +1,7 @@ locals { - account_id = data.aws_caller_identity.current.account_id - boundary_arn = "arn:aws:iam::${local.account_id}:policy/seahaven-lambda-execution-boundary" - bucket_name = "seahaven-site-prod" - deploy_role = "githubdeploy-seahaven-site" + account_id = data.aws_caller_identity.current.account_id + bucket_name = "seahaven-site-prod" + deploy_role = "githubdeploy-seahaven-site" } data "aws_caller_identity" "current" {}