Skip to content

Link the task role output to the Container Permissions wiki page - #243

Merged
ale210 merged 2 commits into
mainfrom
205-link-container-permissions-wiki
Sep 18, 2026
Merged

ale210 merged 2 commits into
mainfrom
205-link-container-permissions-wiki

Conversation

@ale210

@ale210 ale210 commented Sep 18, 2026

Copy link
Copy Markdown
Member

Closes #205.

The documentation itself is the wiki page Container Permissions, published in wiki commit 26db1b4. A wiki page is not delivered as a pull request, so this PR is only the last action item: linking it from the container module, whose task_role_arn output description said "Good for setting up permissions like s3 access" without saying how.

The change

One line in terraform/modules/container/outputs.tf. The new description names the task role as the place project-specific permissions go and links the page. The terraform-docs job regenerates the module README from it.

What the wiki page covers

Written for project teams rather than for DevOps:

  • The two roles and which one you want — task role vs execution role, including the trap that incubator-prod-ecs-task-role is an execution role despite the name. No running container uses that role any more; it survives only until use_own_execution_role is removed.
  • What the task role already grants — ecs execute-command, S3 by project tag and Cognito by project tag, all three delivered by Give the ECS task role project-scoped S3 and Cognito access #242. This section exists so nobody files a request for access they already have.
  • A walkthrough for giving a container an S3 bucket, which after Give the ECS task role project-scoped S3 and Cognito access #242 needs no policy change at all — just the bucket, the project tag and aws_s3_bucket_abac. The page is explicit that omitting the ABAC opt-in fails silently.
  • How to ask for a permission that is not covered, with an SQS statement as the worked example, the aws:ResourceTag pattern, and the two exceptions from the tag standard: services that do not support resource-level permissions or tag conditions, and actions like ecr:GetAuthorizationToken that cannot be scoped at all.
  • How to file the request — hackforla/incubator, Blank Issue Form with No Dependency, with a warning that the picker is still cluttered with website-inherited templates (Delete issue templates that don't apply to incubator #146).

Verification

Both HCL snippets on the page terraform validate clean against the pinned Terraform 1.16.0 and AWS provider 6.64.0, and are fmt-clean — aws_s3_bucket_abac in particular takes abac_status as a nested block rather than an attribute, which is easy to get wrong from prose. All external links on the page return 200, and the rendered page was checked live: headings, the role comparison table and both code blocks all render.

The markdown link in the output description was tested against the pinned terraform-docs v0.20.0 before committing. No existing generated description in this repo contains a markdown link, so there was no precedent for whether the brackets would be escaped into a dead string in the README table; they are not, and the link renders clickable.

Note

terraform fmt would also align the four value = lines in this file with their description = lines. That misalignment predates this change and is left alone rather than adding whitespace-only churn to a one-line documentation change.

@github-actions

github-actions Bot commented Sep 18, 2026 •

Copy link
Copy Markdown
Contributor

Terraform plan in terraform
With backend config files: terraform/prod.backend.tfvars

No changes. Your infrastructure matches the configuration.
No changes. Your infrastructure matches the configuration.

Terraform has compared your real infrastructure against your configuration
and found no differences, so no changes are needed.

✅ Plan applied in Terraform apply (OIDC) #95

@ale210
ale210 merged commit 13e27bc into main Sep 18, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Document how a project gets a scoped permission for its container

1 participant