Link the task role output to the Container Permissions wiki page - #243
Merged
Merged
Conversation
Contributor
|
Terraform plan in terraform No changes. Your infrastructure matches the configuration.✅ Plan applied in Terraform apply (OIDC) #95 |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Closes #205.
The documentation itself is the wiki page Container Permissions, published in wiki commit
26db1b4. A wiki page is not delivered as a pull request, so this PR is only the last action item: linking it from thecontainermodule, whosetask_role_arnoutput description said "Good for setting up permissions like s3 access" without saying how.The change
One line in
terraform/modules/container/outputs.tf. The new description names the task role as the place project-specific permissions go and links the page. Theterraform-docsjob regenerates the module README from it.What the wiki page covers
Written for project teams rather than for DevOps:
incubator-prod-ecs-task-roleis an execution role despite the name. No running container uses that role any more; it survives only untiluse_own_execution_roleis removed.ecs execute-command, S3 by project tag and Cognito by project tag, all three delivered by Give the ECS task role project-scoped S3 and Cognito access #242. This section exists so nobody files a request for access they already have.projecttag andaws_s3_bucket_abac. The page is explicit that omitting the ABAC opt-in fails silently.aws:ResourceTagpattern, and the two exceptions from the tag standard: services that do not support resource-level permissions or tag conditions, and actions likeecr:GetAuthorizationTokenthat cannot be scoped at all.hackforla/incubator, Blank Issue Form with No Dependency, with a warning that the picker is still cluttered with website-inherited templates (Delete issue templates that don't apply to incubator #146).Verification
Both HCL snippets on the page
terraform validateclean against the pinned Terraform 1.16.0 and AWS provider 6.64.0, and arefmt-clean —aws_s3_bucket_abacin particular takesabac_statusas a nested block rather than an attribute, which is easy to get wrong from prose. All external links on the page return 200, and the rendered page was checked live: headings, the role comparison table and both code blocks all render.The markdown link in the output description was tested against the pinned terraform-docs v0.20.0 before committing. No existing generated description in this repo contains a markdown link, so there was no precedent for whether the brackets would be escaped into a dead string in the README table; they are not, and the link renders clickable.
Note
terraform fmtwould also align the fourvalue =lines in this file with theirdescription =lines. That misalignment predates this change and is left alone rather than adding whitespace-only churn to a one-line documentation change.