Part of OvertureMaps/ops-team#520.
#747 points reusable-check-python-package-versions.yaml's PR-time version-existence check at MCD (763944545891), reusing codeartifact-pypi-publish-oidc-overturemaps since there's no MCD read-only role yet. Copilot flagged that as a real risk: that role also has publish/write access, and its OIDC trust policy allows assumption from any workflow context in the repo, including pull_request. A PR that gains control of the workflow's post-assumption steps could use those credentials to publish or overwrite artifacts instead of being confined to reads.
Add a read-only IAM role for CodeArtifact in the MCD account (763944545891), scoped to codeartifact:GetAuthorizationToken/GetRepositoryEndpoint/ReadFromRepository (no publish actions), mirroring legacy's GithubActions_Schema_CodeArtifact_ReadOnly. Terraform for the MCD publish role lives in omf-core-data-opentofu's iam-github-actions.tf.
Once the role exists, #747 needs to switch aws_iam_role_name from the publish role to it.
Part of OvertureMaps/ops-team#520.
#747 points
reusable-check-python-package-versions.yaml's PR-time version-existence check at MCD (763944545891), reusingcodeartifact-pypi-publish-oidc-overturemapssince there's no MCD read-only role yet. Copilot flagged that as a real risk: that role also has publish/write access, and its OIDC trust policy allows assumption from any workflow context in the repo, includingpull_request. A PR that gains control of the workflow's post-assumption steps could use those credentials to publish or overwrite artifacts instead of being confined to reads.Add a read-only IAM role for CodeArtifact in the MCD account (
763944545891), scoped tocodeartifact:GetAuthorizationToken/GetRepositoryEndpoint/ReadFromRepository(no publish actions), mirroring legacy'sGithubActions_Schema_CodeArtifact_ReadOnly. Terraform for the MCD publish role lives inomf-core-data-opentofu'siam-github-actions.tf.Once the role exists, #747 needs to switch
aws_iam_role_namefrom the publish role to it.