Skip to content

Commit a39b345

Browse files
committed
sync with account purge
1 parent babb3bd commit a39b345

File tree

2 files changed

+2
-126
lines changed

2 files changed

+2
-126
lines changed

terraform/aws-users.tf

Lines changed: 0 additions & 119 deletions
Original file line numberDiff line numberDiff line change
@@ -1,14 +1,3 @@
1-
// Create user and assign to group(s)
2-
module "iam_user_JimmyJuarez10" {
3-
source = "./modules/aws-users"
4-
5-
user_name = "JimmyJuarez10"
6-
user_tags = {
7-
"Project" = "civic-tech-jobs"
8-
}
9-
user_groups = ["read-only-group"]
10-
}
11-
121
module "iam_user_tylerthome" {
132
source = "./modules/aws-users"
143

@@ -20,82 +9,6 @@ module "iam_user_tylerthome" {
209
user_groups = ["read-only-group"]
2110
}
2211

23-
module "iam_user_brittanyms" {
24-
source = "./modules/aws-users"
25-
26-
user_name = "brittanyms"
27-
user_tags = {
28-
"Project" = "devops-security"
29-
"Access Level" = "1"
30-
}
31-
user_groups = ["read-only-group"]
32-
}
33-
34-
module "iam_user_freaky4wrld" {
35-
source = "./modules/aws-users"
36-
37-
user_name = "freaky4wrld"
38-
user_tags = {
39-
"Project" = "devops-security"
40-
"Access Level" = "1"
41-
}
42-
user_groups = ["read-only-group"]
43-
}
44-
45-
module "iam_user_shikha0428" {
46-
source = "./modules/aws-users"
47-
48-
user_name = "shikha0428"
49-
user_tags = {
50-
"Project" = "devops-security"
51-
"Access Level" = "1"
52-
}
53-
user_groups = ["read-only-group"]
54-
}
55-
56-
module "iam_user_shinjonathan" {
57-
source = "./modules/aws-users"
58-
59-
user_name = "shinjonathan"
60-
user_tags = {
61-
"Project" = "devops-security"
62-
"Access Level" = "1"
63-
}
64-
user_groups = ["read-only-group"]
65-
}
66-
67-
module "iam_user_samuelusc" {
68-
source = "./modules/aws-users"
69-
70-
user_name = "samuelusc"
71-
user_tags = {
72-
"Project" = "devops-security"
73-
"Access Level" = "1"
74-
}
75-
user_groups = ["read-only-group"]
76-
}
77-
78-
module "iam_user_abbyz123" {
79-
source = "./modules/aws-users"
80-
81-
user_name = "abbyz123"
82-
user_tags = {
83-
"Project" = "devops-security"
84-
"Access Level" = "1"
85-
}
86-
user_groups = ["read-only-group"]
87-
}
88-
89-
module "iam_user_awlFCCamp" {
90-
source = "./modules/aws-users"
91-
92-
user_name = "awlFCCamp"
93-
user_tags = {
94-
"Project" = "devops-security"
95-
"Access Level" = "1"
96-
}
97-
user_groups = ["read-only-group"]
98-
}
9912

10013
module "iam_user_testiamuser" {
10114
source = "./modules/aws-users"
@@ -119,27 +32,6 @@ module "iam_user_chelseyb" {
11932
user_groups = ["read-only-group", "iam-services-supervisor-group"]
12033
}
12134

122-
module "iam_user_jbubar" {
123-
source = "./modules/aws-users"
124-
125-
user_name = "jbubar"
126-
user_tags = {
127-
"Project" = "vrms"
128-
"Access Level" = "1"
129-
}
130-
user_groups = ["read-only-group"]
131-
}
132-
133-
module "iam_user_spiteless" {
134-
source = "./modules/aws-users"
135-
136-
user_name = "spiteless"
137-
user_tags = {
138-
"Project" = "vrms"
139-
"Access Level" = "1"
140-
}
141-
user_groups = ["read-only-group"]
142-
}
14335

14436
module "iam_user_alexe" {
14537
source = "./modules/aws-users"
@@ -185,17 +77,6 @@ module "iam_user_drakeredwind01" {
18577
user_groups = ["read-only-group"]
18678
}
18779

188-
module "iam_user_lsousadev" {
189-
source = "./modules/aws-users"
190-
191-
user_name = "lsousadev"
192-
user_tags = {
193-
"Project" = "devops-security"
194-
"Access Level" = "1"
195-
}
196-
user_groups = ["read-only-group"]
197-
}
198-
19980
module "iam_user_srinipandiyan" {
20081
source = "./modules/aws-users"
20182

terraform/modules/aws-gha-oidc-providers/main.tf

Lines changed: 2 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -61,18 +61,13 @@ resource "aws_iam_role" "github_actions_oidc" {
6161
"Federated" : "arn:aws:iam::${data.aws_caller_identity.current.account_id}:oidc-provider/${local.oidc_github_idp}"
6262
},
6363
"Action" : "sts:AssumeRoleWithWebIdentity",
64-
"Condition" : var.use_wildcard ? {
64+
"Condition" : {
6565
"StringLike" : {
66-
"token.actions.githubusercontent.com:sub" : local.oidc_gha_sub
66+
"token.actions.githubusercontent.com:sub" : [local.oidc_gha_sub, "repo:${var.github_repo}:pull_request"]
6767
},
6868
"StringEquals" : {
6969
"token.actions.githubusercontent.com:aud" : local.oidc_aws_audience,
7070
}
71-
} : {
72-
"StringEquals" : {
73-
"token.actions.githubusercontent.com:aud" : local.oidc_aws_audience,
74-
"token.actions.githubusercontent.com:sub" : local.oidc_gha_sub
75-
}
7671
}
7772
}]
7873
})

0 commit comments

Comments
 (0)