data "aws_iam_policy_document" "github_deploy_assume" { # Legacy branch trust. Remove after one deploy through cd-hcp-static has # succeeded. The branch subject stays until EnvironmentProd is applied. statement { sid = "LegacyBranch" effect = "Allow" actions = ["sts:AssumeRoleWithWebIdentity"] principals { type = "Federated" identifiers = [data.aws_iam_openid_connect_provider.github.arn] } condition { test = "StringEquals" variable = "token.actions.githubusercontent.com:aud" values = ["sts.amazonaws.com"] } condition { test = "StringLike" variable = "token.actions.githubusercontent.com:sub" values = ["repo:${var.github_repo}:ref:refs/heads/${var.github_deploy_branch}"] } } statement { sid = "EnvironmentProd" effect = "Allow" actions = ["sts:AssumeRoleWithWebIdentity"] principals { type = "Federated" identifiers = [data.aws_iam_openid_connect_provider.github.arn] } condition { test = "StringEquals" variable = "token.actions.githubusercontent.com:aud" values = ["sts.amazonaws.com"] } condition { test = "StringEquals" variable = "token.actions.githubusercontent.com:sub" values = ["repo:${var.github_repo}:environment:prod"] } condition { test = "StringLike" variable = "token.actions.githubusercontent.com:job_workflow_ref" values = ["Sea-Haven-Industries/.github/.github/workflows/cd-hcp-static.yaml@*"] } } } resource "aws_iam_policy" "github_deploy_boundary" { name = "seahaven-site-githubdeploy-boundary" path = "/tf-managed/" description = "Permissions boundary for githubdeploy-seahaven-site" policy = data.aws_iam_policy_document.github_deploy.json # Request tag the hcptf apply role requires before it may CreatePolicy. tags = { BoundaryFor = "githubdeploy-seahaven-site" } } resource "aws_iam_role" "github_deploy" { name = local.deploy_role path = "/tf-managed/" description = "GitHub Actions content-deploy role for ${var.github_repo} Environment prod" assume_role_policy = data.aws_iam_policy_document.github_deploy_assume.json permissions_boundary = aws_iam_policy.github_deploy_boundary.arn max_session_duration = 3600 } data "aws_iam_policy_document" "github_deploy" { statement { sid = "OriginBucketObjects" effect = "Allow" actions = [ "s3:GetObject", "s3:PutObject", "s3:DeleteObject", "s3:GetObjectTagging", "s3:PutObjectTagging", ] resources = ["${aws_s3_bucket.origin.arn}/*"] } statement { sid = "OriginBucketList" effect = "Allow" actions = [ "s3:ListBucket", "s3:GetBucketLocation", ] resources = [aws_s3_bucket.origin.arn] } statement { sid = "InvalidateDistribution" effect = "Allow" actions = [ "cloudfront:CreateInvalidation", "cloudfront:GetDistribution", "cloudfront:GetInvalidation", ] resources = [aws_cloudfront_distribution.site.arn] } statement { sid = "ReadDeployContract" effect = "Allow" actions = [ "ssm:GetParameter", "ssm:GetParameters", ] resources = ["arn:aws:ssm:${var.aws_region}:${local.account_id}:parameter/seahaven-site/deploy/*"] } } resource "aws_iam_role_policy" "github_deploy" { name = "seahaven-site-content-deploy" role = aws_iam_role.github_deploy.id policy = data.aws_iam_policy_document.github_deploy.json }