File tree Expand file tree Collapse file tree
Expand file tree Collapse file tree Original file line number Diff line number Diff line change 66 - main # or any other branch you want to trigger the deployment
77 paths :
88 - ' **/*.tf'
9+ # Recovery path for the approval gate below. When a merge-triggered apply fails
10+ # with plan-changed, re-running it from the Actions tab replays the same push
11+ # event and fails identically, so a manual trigger is the only way back.
12+ workflow_dispatch :
913
1014jobs :
1115 terraform-apply :
3438 with :
3539 path : terraform
3640 backend_config_file : terraform/prod.backend.tfvars
37- auto_approve : true
41+ auto_approve : ${{ github.event_name == 'workflow_dispatch' }}
Original file line number Diff line number Diff line change 1212// hackforla/devops-security#182.
1313//
1414// Do not "fix" their absence by adding them below.
15+ //
16+ // The apply role's sub condition is refs/heads/main ONLY, and that narrowness is
17+ // load-bearing beyond the obvious. terraform-apply.yaml has a workflow_dispatch
18+ // trigger whose runs are auto-approved -- the one path that applies without a
19+ // reviewed plan -- and a dispatch on any other branch presents a different sub,
20+ // so AWS refuses the AssumeRole outright. Widening this to refs/heads/* would
21+ // silently turn that recovery trigger into an unreviewed apply from any branch.
22+ // See hackforla/devops-security#187.
1523
1624module "iam_oidc_gha_incubator" {
1725 source = " ./modules/aws-gha-oidc-providers"
You can’t perform that action at this time.
0 commit comments