Skip to content

Commit 599e551

Browse files
committed
Only auto-approve the Terraform apply on workflow_dispatch
1 parent 2e8f430 commit 599e551

2 files changed

Lines changed: 13 additions & 1 deletion

File tree

‎.github/workflows/terraform-apply.yaml‎

Lines changed: 5 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -6,6 +6,10 @@ on:
66
- main # or any other branch you want to trigger the deployment
77
paths:
88
- '**/*.tf'
9+
# Recovery path for the approval gate below. When a merge-triggered apply fails
10+
# with plan-changed, re-running it from the Actions tab replays the same push
11+
# event and fails identically, so a manual trigger is the only way back.
12+
workflow_dispatch:
913

1014
jobs:
1115
terraform-apply:
@@ -34,4 +38,4 @@ jobs:
3438
with:
3539
path: terraform
3640
backend_config_file: terraform/prod.backend.tfvars
37-
auto_approve: true
41+
auto_approve: ${{ github.event_name == 'workflow_dispatch' }}

‎terraform/aws-gha-oidc-providers.tf‎

Lines changed: 8 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -12,6 +12,14 @@
1212
// hackforla/devops-security#182.
1313
//
1414
// Do not "fix" their absence by adding them below.
15+
//
16+
// The apply role's sub condition is refs/heads/main ONLY, and that narrowness is
17+
// load-bearing beyond the obvious. terraform-apply.yaml has a workflow_dispatch
18+
// trigger whose runs are auto-approved -- the one path that applies without a
19+
// reviewed plan -- and a dispatch on any other branch presents a different sub,
20+
// so AWS refuses the AssumeRole outright. Widening this to refs/heads/* would
21+
// silently turn that recovery trigger into an unreviewed apply from any branch.
22+
// See hackforla/devops-security#187.
1523

1624
module "iam_oidc_gha_incubator" {
1725
source = "./modules/aws-gha-oidc-providers"

0 commit comments

Comments
 (0)