fix(iam): skip boundary delete on github deploy role (PLAT-52)

This commit is contained in:
Adam Moussa 2026-08-20 15:03:21 -04:00
parent a8b617d782
commit e61ba59820
No known key found for this signature in database

View file

@ -23,14 +23,22 @@ data "aws_iam_policy_document" "github_deploy_assume" {
}
resource "aws_iam_role" "github_deploy" {
name = local.deploy_role
path = "/tf-managed/"
description = "GitHub Actions content-deploy role for ${var.github_repo}@${var.github_deploy_branch}"
# Not a Lambda execution role. Do not attach seahaven-lambda-execution-boundary
# (PLAT-52). HCP apply cannot DeleteRolePermissionsBoundary (DenyBoundaryTampering);
# stripping the live attachment is an administrator action after this apply.
name = local.deploy_role
path = "/tf-managed/"
description = "GitHub Actions content-deploy role for ${var.github_repo}@${var.github_deploy_branch}"
assume_role_policy = data.aws_iam_policy_document.github_deploy_assume.json
max_session_duration = 3600
# Not a Lambda execution role. Config omits permissions_boundary so a later
# apply will not PutRolePermissionsBoundary the Lambda ceiling back. Live still
# has seahaven-lambda-execution-boundary; omitting without ignore_changes would
# plan DeleteRolePermissionsBoundary, which hcptf-seahaven-site is denied
# (DenyBoundaryTampering). Ignore the attribute so this apply does not touch
# the ceiling. An administrator deletes the live attachment, then a follow-up
# drops this lifecycle after refresh-only updates state to null.
lifecycle {
ignore_changes = [permissions_boundary]
}
}
data "aws_iam_policy_document" "github_deploy" {