From dc28a1bbca55575d7888a1a785376c4e204411fe Mon Sep 17 00:00:00 2001 From: Adam Moussa <166072409+amoussa1229@users.noreply.github.com> Date: Thu, 20 Aug 2026 16:05:23 -0400 Subject: [PATCH] fix(iam): drop lambda boundary from github deploy role (PLAT-52) (#44) * fix(iam): drop lambda boundary from github deploy role (PLAT-52) * fix(iam): skip boundary delete on github deploy role (PLAT-52) --- terraform/iam_github_deploy.tf | 12 +++++++++++- terraform/locals.tf | 7 +++---- 2 files changed, 14 insertions(+), 5 deletions(-) diff --git a/terraform/iam_github_deploy.tf b/terraform/iam_github_deploy.tf index 6a115ef..bcdf0e5 100644 --- a/terraform/iam_github_deploy.tf +++ b/terraform/iam_github_deploy.tf @@ -27,8 +27,18 @@ resource "aws_iam_role" "github_deploy" { path = "/tf-managed/" description = "GitHub Actions content-deploy role for ${var.github_repo}@${var.github_deploy_branch}" assume_role_policy = data.aws_iam_policy_document.github_deploy_assume.json - permissions_boundary = local.boundary_arn max_session_duration = 3600 + + # Not a Lambda execution role. Config omits permissions_boundary so a later + # apply will not PutRolePermissionsBoundary the Lambda ceiling back. Live still + # has seahaven-lambda-execution-boundary; omitting without ignore_changes would + # plan DeleteRolePermissionsBoundary, which hcptf-seahaven-site is denied + # (DenyBoundaryTampering). Ignore the attribute so this apply does not touch + # the ceiling. An administrator deletes the live attachment, then a follow-up + # drops this lifecycle after refresh-only updates state to null. + lifecycle { + ignore_changes = [permissions_boundary] + } } data "aws_iam_policy_document" "github_deploy" { diff --git a/terraform/locals.tf b/terraform/locals.tf index 40f0b7a..dcd72d4 100644 --- a/terraform/locals.tf +++ b/terraform/locals.tf @@ -1,8 +1,7 @@ locals { - account_id = data.aws_caller_identity.current.account_id - boundary_arn = "arn:aws:iam::${local.account_id}:policy/seahaven-lambda-execution-boundary" - bucket_name = "seahaven-site-prod" - deploy_role = "githubdeploy-seahaven-site" + account_id = data.aws_caller_identity.current.account_id + bucket_name = "seahaven-site-prod" + deploy_role = "githubdeploy-seahaven-site" } data "aws_caller_identity" "current" {}