mirror of
https://github.com/Sea-Haven-Industries/seahaven-site.git
synced 2026-10-02 16:33:14 +00:00
Prod still ships on merge to main. Exec roles leave this workspace, and the deploy reads the bucket and distribution from SSM.
128 lines
3.6 KiB
HCL
128 lines
3.6 KiB
HCL
data "aws_iam_policy_document" "github_deploy_assume" {
|
|
# Legacy branch trust. Remove after one deploy through cd-hcp-static has
|
|
# succeeded. The inline workflow still assumes this subject until then.
|
|
statement {
|
|
sid = "LegacyBranch"
|
|
effect = "Allow"
|
|
actions = ["sts:AssumeRoleWithWebIdentity"]
|
|
|
|
principals {
|
|
type = "Federated"
|
|
identifiers = [data.aws_iam_openid_connect_provider.github.arn]
|
|
}
|
|
|
|
condition {
|
|
test = "StringEquals"
|
|
variable = "token.actions.githubusercontent.com:aud"
|
|
values = ["sts.amazonaws.com"]
|
|
}
|
|
|
|
condition {
|
|
test = "StringLike"
|
|
variable = "token.actions.githubusercontent.com:sub"
|
|
values = ["repo:${var.github_repo}:ref:refs/heads/${var.github_deploy_branch}"]
|
|
}
|
|
}
|
|
|
|
statement {
|
|
sid = "EnvironmentProd"
|
|
effect = "Allow"
|
|
actions = ["sts:AssumeRoleWithWebIdentity"]
|
|
|
|
principals {
|
|
type = "Federated"
|
|
identifiers = [data.aws_iam_openid_connect_provider.github.arn]
|
|
}
|
|
|
|
condition {
|
|
test = "StringEquals"
|
|
variable = "token.actions.githubusercontent.com:aud"
|
|
values = ["sts.amazonaws.com"]
|
|
}
|
|
|
|
condition {
|
|
test = "StringEquals"
|
|
variable = "token.actions.githubusercontent.com:sub"
|
|
values = ["repo:${var.github_repo}:environment:prod"]
|
|
}
|
|
|
|
condition {
|
|
test = "StringLike"
|
|
variable = "token.actions.githubusercontent.com:job_workflow_ref"
|
|
values = ["Sea-Haven-Industries/.github/.github/workflows/cd-hcp-static.yaml@*"]
|
|
}
|
|
}
|
|
}
|
|
|
|
resource "aws_iam_policy" "github_deploy_boundary" {
|
|
name = "seahaven-site-githubdeploy-boundary"
|
|
path = "/tf-managed/"
|
|
description = "Permissions boundary for githubdeploy-seahaven-site"
|
|
policy = data.aws_iam_policy_document.github_deploy.json
|
|
|
|
# Request tag the hcptf apply role requires before it may CreatePolicy.
|
|
tags = {
|
|
BoundaryFor = "githubdeploy-seahaven-site"
|
|
}
|
|
}
|
|
|
|
resource "aws_iam_role" "github_deploy" {
|
|
name = local.deploy_role
|
|
path = "/tf-managed/"
|
|
description = "GitHub Actions content-deploy role for ${var.github_repo} Environment prod"
|
|
assume_role_policy = data.aws_iam_policy_document.github_deploy_assume.json
|
|
permissions_boundary = aws_iam_policy.github_deploy_boundary.arn
|
|
max_session_duration = 3600
|
|
}
|
|
|
|
data "aws_iam_policy_document" "github_deploy" {
|
|
statement {
|
|
sid = "OriginBucketObjects"
|
|
effect = "Allow"
|
|
actions = [
|
|
"s3:GetObject",
|
|
"s3:PutObject",
|
|
"s3:DeleteObject",
|
|
"s3:GetObjectTagging",
|
|
"s3:PutObjectTagging",
|
|
]
|
|
resources = ["${aws_s3_bucket.origin.arn}/*"]
|
|
}
|
|
|
|
statement {
|
|
sid = "OriginBucketList"
|
|
effect = "Allow"
|
|
actions = [
|
|
"s3:ListBucket",
|
|
"s3:GetBucketLocation",
|
|
]
|
|
resources = [aws_s3_bucket.origin.arn]
|
|
}
|
|
|
|
statement {
|
|
sid = "InvalidateDistribution"
|
|
effect = "Allow"
|
|
actions = [
|
|
"cloudfront:CreateInvalidation",
|
|
"cloudfront:GetDistribution",
|
|
"cloudfront:GetInvalidation",
|
|
]
|
|
resources = [aws_cloudfront_distribution.site.arn]
|
|
}
|
|
|
|
statement {
|
|
sid = "ReadDeployContract"
|
|
effect = "Allow"
|
|
actions = [
|
|
"ssm:GetParameter",
|
|
"ssm:GetParameters",
|
|
]
|
|
resources = ["arn:aws:ssm:${var.aws_region}:${local.account_id}:parameter/seahaven-site/deploy/*"]
|
|
}
|
|
}
|
|
|
|
resource "aws_iam_role_policy" "github_deploy" {
|
|
name = "seahaven-site-content-deploy"
|
|
role = aws_iam_role.github_deploy.id
|
|
policy = data.aws_iam_policy_document.github_deploy.json
|
|
}
|