Scope the CI/CD policy to each project's own ECR repositories and ECS services - #241
Merged
Merged
Conversation
Contributor
|
Terraform plan in terraform Plan: 8 to add, 0 to change, 4 to destroy.Terraform used the selected providers to generate the following execution
plan. Resource actions are indicated with the following symbols:
+ create
-/+ destroy and then create replacement
Terraform will perform the following actions:
# module.civic-tech-jobs.module.civic_tech_jobs_cicd.aws_iam_policy.builder will be created
+ resource "aws_iam_policy" "builder" {
+ arn = (known after apply)
+ attachment_count = (known after apply)
+ description = "CI/CD for civic-tech-jobs: push images and redeploy services tagged with project civic-tech-jobs"
+ id = (known after apply)
+ name = "incubator-cicd-civic-tech-jobs"
+ name_prefix = (known after apply)
+ path = "/"
+ policy = jsonencode(
{
+ Statement = [
+ {
+ Action = "ecr:GetAuthorizationToken"
+ Effect = "Allow"
+ Resource = "*"
+ Sid = "EcrAuthToken"
},
+ {
+ Action = [
+ "ecr:CompleteLayerUpload",
+ "ecr:UploadLayerPart",
+ "ecr:InitiateLayerUpload",
+ "ecr:GetDownloadUrlForLayer",
+ "ecr:BatchCheckLayerAvailability",
+ "ecr:PutImage",
+ "ecr:BatchGetImage",
]
+ Condition = {
+ StringEquals = {
+ "aws:ResourceTag/project" = "civic-tech-jobs"
}
}
+ Effect = "Allow"
+ Resource = "arn:aws:ecr:us-west-2:035866691871:repository/*"
+ Sid = "EcrPush"
},
+ {
+ Action = [
+ "ecs:UpdateService",
+ "ecs:DescribeServices",
]
+ Condition = {
+ StringEquals = {
+ "aws:ResourceTag/project" = "civic-tech-jobs"
}
}
+ Effect = "Allow"
+ Resource = "arn:aws:ecs:us-west-2:035866691871:service/incubator-prod/*"
+ Sid = "DeployService"
},
]
+ Version = "2012-10-17"
}
)
+ policy_id = (known after apply)
+ tags = {
+ "project" = "civic-tech-jobs"
}
+ tags_all = {
+ "managed-by" = "terraform-incubator"
+ "project" = "civic-tech-jobs"
}
}
# module.civic-tech-jobs.module.civic_tech_jobs_cicd.aws_iam_role_policy_attachment.this must be replaced
-/+ resource "aws_iam_role_policy_attachment" "this" {
!~ id = "*********************************************************" -> (known after apply)
!~ policy_arn = "arn:aws:iam::035866691871:policy/incubator_builder" -> (known after apply) # forces replacement
# (1 unchanged attribute hidden)
}
# module.home-unite-us.module.cicd_integration.aws_iam_policy.builder will be created
+ resource "aws_iam_policy" "builder" {
+ arn = (known after apply)
+ attachment_count = (known after apply)
+ description = "CI/CD for home-unite-us: push images and redeploy services tagged with project home-unite-us"
+ id = (known after apply)
+ name = "incubator-cicd-home-unite-us"
+ name_prefix = (known after apply)
+ path = "/"
+ policy = jsonencode(
{
+ Statement = [
+ {
+ Action = "ecr:GetAuthorizationToken"
+ Effect = "Allow"
+ Resource = "*"
+ Sid = "EcrAuthToken"
},
+ {
+ Action = [
+ "ecr:CompleteLayerUpload",
+ "ecr:UploadLayerPart",
+ "ecr:InitiateLayerUpload",
+ "ecr:GetDownloadUrlForLayer",
+ "ecr:BatchCheckLayerAvailability",
+ "ecr:PutImage",
+ "ecr:BatchGetImage",
]
+ Condition = {
+ StringEquals = {
+ "aws:ResourceTag/project" = "home-unite-us"
}
}
+ Effect = "Allow"
+ Resource = "arn:aws:ecr:us-west-2:035866691871:repository/*"
+ Sid = "EcrPush"
},
+ {
+ Action = [
+ "ecs:UpdateService",
+ "ecs:DescribeServices",
]
+ Condition = {
+ StringEquals = {
+ "aws:ResourceTag/project" = "home-unite-us"
}
}
+ Effect = "Allow"
+ Resource = "arn:aws:ecs:us-west-2:035866691871:service/incubator-prod/*"
+ Sid = "DeployService"
},
]
+ Version = "2012-10-17"
}
)
+ policy_id = (known after apply)
+ tags = {
+ "project" = "home-unite-us"
}
+ tags_all = {
+ "managed-by" = "terraform-incubator"
+ "project" = "home-unite-us"
}
}
# module.home-unite-us.module.cicd_integration.aws_iam_role_policy_attachment.this must be replaced
-/+ resource "aws_iam_role_policy_attachment" "this" {
!~ id = "*******************************************************" -> (known after apply)
!~ policy_arn = "arn:aws:iam::035866691871:policy/incubator_builder" -> (known after apply) # forces replacement
# (1 unchanged attribute hidden)
}
# module.people-depot.module.people_depot_cicd.aws_iam_policy.builder will be created
+ resource "aws_iam_policy" "builder" {
+ arn = (known after apply)
+ attachment_count = (known after apply)
+ description = "CI/CD for people-depot: push images and redeploy services tagged with project people-depot"
+ id = (known after apply)
+ name = "incubator-cicd-people-depot"
+ name_prefix = (known after apply)
+ path = "/"
+ policy = jsonencode(
{
+ Statement = [
+ {
+ Action = "ecr:GetAuthorizationToken"
+ Effect = "Allow"
+ Resource = "*"
+ Sid = "EcrAuthToken"
},
+ {
+ Action = [
+ "ecr:CompleteLayerUpload",
+ "ecr:UploadLayerPart",
+ "ecr:InitiateLayerUpload",
+ "ecr:GetDownloadUrlForLayer",
+ "ecr:BatchCheckLayerAvailability",
+ "ecr:PutImage",
+ "ecr:BatchGetImage",
]
+ Condition = {
+ StringEquals = {
+ "aws:ResourceTag/project" = "people-depot"
}
}
+ Effect = "Allow"
+ Resource = "arn:aws:ecr:us-west-2:035866691871:repository/*"
+ Sid = "EcrPush"
},
+ {
+ Action = [
+ "ecs:UpdateService",
+ "ecs:DescribeServices",
]
+ Condition = {
+ StringEquals = {
+ "aws:ResourceTag/project" = "people-depot"
}
}
+ Effect = "Allow"
+ Resource = "arn:aws:ecs:us-west-2:035866691871:service/incubator-prod/*"
+ Sid = "DeployService"
},
]
+ Version = "2012-10-17"
}
)
+ policy_id = (known after apply)
+ tags = {
+ "project" = "people-depot"
}
+ tags_all = {
+ "managed-by" = "terraform-incubator"
+ "project" = "people-depot"
}
}
# module.people-depot.module.people_depot_cicd.aws_iam_role_policy_attachment.this must be replaced
-/+ resource "aws_iam_role_policy_attachment" "this" {
!~ id = "******************************************************" -> (known after apply)
!~ policy_arn = "arn:aws:iam::035866691871:policy/incubator_builder" -> (known after apply) # forces replacement
# (1 unchanged attribute hidden)
}
# module.vrms.module.cicd.aws_iam_policy.builder will be created
+ resource "aws_iam_policy" "builder" {
+ arn = (known after apply)
+ attachment_count = (known after apply)
+ description = "CI/CD for vrms: push images and redeploy services tagged with project vrms"
+ id = (known after apply)
+ name = "incubator-cicd-vrms"
+ name_prefix = (known after apply)
+ path = "/"
+ policy = jsonencode(
{
+ Statement = [
+ {
+ Action = "ecr:GetAuthorizationToken"
+ Effect = "Allow"
+ Resource = "*"
+ Sid = "EcrAuthToken"
},
+ {
+ Action = [
+ "ecr:CompleteLayerUpload",
+ "ecr:UploadLayerPart",
+ "ecr:InitiateLayerUpload",
+ "ecr:GetDownloadUrlForLayer",
+ "ecr:BatchCheckLayerAvailability",
+ "ecr:PutImage",
+ "ecr:BatchGetImage",
]
+ Condition = {
+ StringEquals = {
+ "aws:ResourceTag/project" = "vrms"
}
}
+ Effect = "Allow"
+ Resource = "arn:aws:ecr:us-west-2:035866691871:repository/*"
+ Sid = "EcrPush"
},
+ {
+ Action = [
+ "ecs:UpdateService",
+ "ecs:DescribeServices",
]
+ Condition = {
+ StringEquals = {
+ "aws:ResourceTag/project" = "vrms"
}
}
+ Effect = "Allow"
+ Resource = "arn:aws:ecs:us-west-2:035866691871:service/incubator-prod/*"
+ Sid = "DeployService"
},
]
+ Version = "2012-10-17"
}
)
+ policy_id = (known after apply)
+ tags = {
+ "project" = "vrms"
}
+ tags_all = {
+ "managed-by" = "terraform-incubator"
+ "project" = "vrms"
}
}
# module.vrms.module.cicd.aws_iam_role_policy_attachment.this must be replaced
-/+ resource "aws_iam_role_policy_attachment" "this" {
!~ id = "**********************************************" -> (known after apply)
!~ policy_arn = "arn:aws:iam::035866691871:policy/incubator_builder" -> (known after apply) # forces replacement
# (1 unchanged attribute hidden)
}
Plan: 8 to add, 0 to change, 4 to destroy.✅ Plan applied in Terraform apply (OIDC) #93 |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Part 1 of 2 for #202.
Each project's CI/CD role gets its own policy,
incubator-cicd-<project>, inmodules/cicd_integration. Its ECR push and ECS deploy statements only allow resources whoseprojecttag matches the project. Before this, all four roles sharedincubator_builder, which allowed push to every repository andUpdateServiceon every service inincubator-prod.The shared
incubator_builderpolicy stays in place, unattached. It is deleted in a follow-up PR. The attachments referenced it by a hardcoded ARN, so Terraform has no dependency to order a detach before the delete within one apply.Expected plan: 4 policies to add, 4
aws_iam_role_policy_attachmentreplaced (policy_arnforces replacement), nothing else changed or destroyed. During the apply each role is briefly without permissions.Checked before opening:
terraform validate. I also ran the IAM policy simulator against every live ECR repository and ECS service with its realprojecttag: each project is allowed only on its own resources, and the other projects' and untagged resources are denied (288 checks, 0 failures).After merge: confirm the attachments, run the people-depot and CivicTechJobs deploys, and test a cross-project denial with a real role (see #202).