fix(iam): drop the legacy branch deploy trust (#70)

This commit is contained in:
Adam Moussa 2026-09-25 18:00:19 +00:00 • committed by GitHub
parent 3a8de4e88b
commit cc961e4b93
No known key found for this signature in database
GPG key ID: B5690EEEBB952194
3 changed files with 0 additions and 32 deletions

View file

@ -1,29 +1,4 @@
data "aws_iam_policy_document" "github_deploy_assume" {
# Legacy branch trust. Remove after one deploy through cd-hcp-static has
# succeeded. The branch subject stays until EnvironmentProd is applied.
statement {
sid = "LegacyBranch"
effect = "Allow"
actions = ["sts:AssumeRoleWithWebIdentity"]
principals {
type = "Federated"
identifiers = [data.aws_iam_openid_connect_provider.github.arn]
}
condition {
test = "StringEquals"
variable = "token.actions.githubusercontent.com:aud"
values = ["sts.amazonaws.com"]
}
condition {
test = "StringLike"
variable = "token.actions.githubusercontent.com:sub"
values = ["repo:${var.github_repo}:ref:refs/heads/${var.github_deploy_branch}"]
}
}
statement {
sid = "EnvironmentProd"
effect = "Allow"

View file

@ -4,6 +4,5 @@
aws_region = "us-east-1"
domain_name = "seahaven.com"
github_repo = "Sea-Haven-Industries/seahaven-site"
github_deploy_branch = "main"
# Flip to true after scripts/setup_seahaven_site_domain.sh cert issues the ACM cert.
attach_apex_alias = false

View file

@ -16,12 +16,6 @@ variable "github_repo" {
default = "Sea-Haven-Industries/seahaven-site"
}
variable "github_deploy_branch" {
type = string
description = "Git branch allowed to assume the content-deploy role"
default = "main"
}
variable "attach_apex_alias" {
type = bool
description = <<EOT