From cc961e4b93addd9c59e52e401a289f691ac013ea Mon Sep 17 00:00:00 2001 From: Adam Moussa <166072409+amoussa1229@users.noreply.github.com> Date: Fri, 25 Sep 2026 18:00:19 +0000 Subject: [PATCH] fix(iam): drop the legacy branch deploy trust (#70) --- terraform/iam_github_deploy.tf | 25 ------------------------- terraform/terraform.tfvars.example | 1 - terraform/variables.tf | 6 ------ 3 files changed, 32 deletions(-) diff --git a/terraform/iam_github_deploy.tf b/terraform/iam_github_deploy.tf index eea569b..13d34d1 100644 --- a/terraform/iam_github_deploy.tf +++ b/terraform/iam_github_deploy.tf @@ -1,29 +1,4 @@ data "aws_iam_policy_document" "github_deploy_assume" { - # Legacy branch trust. Remove after one deploy through cd-hcp-static has - # succeeded. The branch subject stays until EnvironmentProd is applied. - statement { - sid = "LegacyBranch" - effect = "Allow" - actions = ["sts:AssumeRoleWithWebIdentity"] - - principals { - type = "Federated" - identifiers = [data.aws_iam_openid_connect_provider.github.arn] - } - - condition { - test = "StringEquals" - variable = "token.actions.githubusercontent.com:aud" - values = ["sts.amazonaws.com"] - } - - condition { - test = "StringLike" - variable = "token.actions.githubusercontent.com:sub" - values = ["repo:${var.github_repo}:ref:refs/heads/${var.github_deploy_branch}"] - } - } - statement { sid = "EnvironmentProd" effect = "Allow" diff --git a/terraform/terraform.tfvars.example b/terraform/terraform.tfvars.example index 61021aa..395a550 100644 --- a/terraform/terraform.tfvars.example +++ b/terraform/terraform.tfvars.example @@ -4,6 +4,5 @@ aws_region = "us-east-1" domain_name = "seahaven.com" github_repo = "Sea-Haven-Industries/seahaven-site" -github_deploy_branch = "main" # Flip to true after scripts/setup_seahaven_site_domain.sh cert issues the ACM cert. attach_apex_alias = false diff --git a/terraform/variables.tf b/terraform/variables.tf index 71370d6..bc1d87e 100644 --- a/terraform/variables.tf +++ b/terraform/variables.tf @@ -16,12 +16,6 @@ variable "github_repo" { default = "Sea-Haven-Industries/seahaven-site" } -variable "github_deploy_branch" { - type = string - description = "Git branch allowed to assume the content-deploy role" - default = "main" -} - variable "attach_apex_alias" { type = bool description = <