From e61ba59820652299c686247bff9786c648670d0b Mon Sep 17 00:00:00 2001 From: Adam Moussa Date: Thu, 20 Aug 2026 15:03:21 -0400 Subject: [PATCH] fix(iam): skip boundary delete on github deploy role (PLAT-52) --- terraform/iam_github_deploy.tf | 20 ++++++++++++++------ 1 file changed, 14 insertions(+), 6 deletions(-) diff --git a/terraform/iam_github_deploy.tf b/terraform/iam_github_deploy.tf index 343c6c8..bcdf0e5 100644 --- a/terraform/iam_github_deploy.tf +++ b/terraform/iam_github_deploy.tf @@ -23,14 +23,22 @@ data "aws_iam_policy_document" "github_deploy_assume" { } resource "aws_iam_role" "github_deploy" { - name = local.deploy_role - path = "/tf-managed/" - description = "GitHub Actions content-deploy role for ${var.github_repo}@${var.github_deploy_branch}" - # Not a Lambda execution role. Do not attach seahaven-lambda-execution-boundary - # (PLAT-52). HCP apply cannot DeleteRolePermissionsBoundary (DenyBoundaryTampering); - # stripping the live attachment is an administrator action after this apply. + name = local.deploy_role + path = "/tf-managed/" + description = "GitHub Actions content-deploy role for ${var.github_repo}@${var.github_deploy_branch}" assume_role_policy = data.aws_iam_policy_document.github_deploy_assume.json max_session_duration = 3600 + + # Not a Lambda execution role. Config omits permissions_boundary so a later + # apply will not PutRolePermissionsBoundary the Lambda ceiling back. Live still + # has seahaven-lambda-execution-boundary; omitting without ignore_changes would + # plan DeleteRolePermissionsBoundary, which hcptf-seahaven-site is denied + # (DenyBoundaryTampering). Ignore the attribute so this apply does not touch + # the ceiling. An administrator deletes the live attachment, then a follow-up + # drops this lifecycle after refresh-only updates state to null. + lifecycle { + ignore_changes = [permissions_boundary] + } } data "aws_iam_policy_document" "github_deploy" {