Skip to content

[CloudOps Support Request] Add read-only CodeArtifact IAM role in MCD account #749

Description

@lowlydba

Part of OvertureMaps/ops-team#520.

#747 points reusable-check-python-package-versions.yaml's PR-time version-existence check at MCD (763944545891), reusing codeartifact-pypi-publish-oidc-overturemaps since there's no MCD read-only role yet. Copilot flagged that as a real risk: that role also has publish/write access, and its OIDC trust policy allows assumption from any workflow context in the repo, including pull_request. A PR that gains control of the workflow's post-assumption steps could use those credentials to publish or overwrite artifacts instead of being confined to reads.

Add a read-only IAM role for CodeArtifact in the MCD account (763944545891), scoped to codeartifact:GetAuthorizationToken/GetRepositoryEndpoint/ReadFromRepository (no publish actions), mirroring legacy's GithubActions_Schema_CodeArtifact_ReadOnly. Terraform for the MCD publish role lives in omf-core-data-opentofu's iam-github-actions.tf.

Once the role exists, #747 needs to switch aws_iam_role_name from the publish role to it.

Activity

  1. lowlydba commented on Sep 14, 2026

    @lowlydba
    ContributorAuthor

    Created in the wrong repo by mistake; refiled in OvertureMaps/ops-team.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions