mirror of
https://github.com/Sea-Haven-Industries/seahaven-site.git
synced 2026-09-30 04:13:15 +00:00
fix(iam): drop lambda boundary from github deploy role (PLAT-52) (#44)
Some checks are pending
Deploy / deploy (push) Waiting to run
Some checks are pending
Deploy / deploy (push) Waiting to run
* fix(iam): drop lambda boundary from github deploy role (PLAT-52) * fix(iam): skip boundary delete on github deploy role (PLAT-52)
This commit is contained in:
parent
cf7e407386
commit
dc28a1bbca
2 changed files with 14 additions and 5 deletions
|
|
@ -27,8 +27,18 @@ resource "aws_iam_role" "github_deploy" {
|
|||
path = "/tf-managed/"
|
||||
description = "GitHub Actions content-deploy role for ${var.github_repo}@${var.github_deploy_branch}"
|
||||
assume_role_policy = data.aws_iam_policy_document.github_deploy_assume.json
|
||||
permissions_boundary = local.boundary_arn
|
||||
max_session_duration = 3600
|
||||
|
||||
# Not a Lambda execution role. Config omits permissions_boundary so a later
|
||||
# apply will not PutRolePermissionsBoundary the Lambda ceiling back. Live still
|
||||
# has seahaven-lambda-execution-boundary; omitting without ignore_changes would
|
||||
# plan DeleteRolePermissionsBoundary, which hcptf-seahaven-site is denied
|
||||
# (DenyBoundaryTampering). Ignore the attribute so this apply does not touch
|
||||
# the ceiling. An administrator deletes the live attachment, then a follow-up
|
||||
# drops this lifecycle after refresh-only updates state to null.
|
||||
lifecycle {
|
||||
ignore_changes = [permissions_boundary]
|
||||
}
|
||||
}
|
||||
|
||||
data "aws_iam_policy_document" "github_deploy" {
|
||||
|
|
|
|||
|
|
@ -1,8 +1,7 @@
|
|||
locals {
|
||||
account_id = data.aws_caller_identity.current.account_id
|
||||
boundary_arn = "arn:aws:iam::${local.account_id}:policy/seahaven-lambda-execution-boundary"
|
||||
bucket_name = "seahaven-site-prod"
|
||||
deploy_role = "githubdeploy-seahaven-site"
|
||||
account_id = data.aws_caller_identity.current.account_id
|
||||
bucket_name = "seahaven-site-prod"
|
||||
deploy_role = "githubdeploy-seahaven-site"
|
||||
}
|
||||
|
||||
data "aws_caller_identity" "current" {}
|
||||
|
|
|
|||
Loading…
Add table
Reference in a new issue