Skip to content

Commit dcb03ee

Browse files
committed
[IT-4658] Fix GH OIDC for bixarena-infra
permission to deploy to bixarena stage/prod account from Sage-Bionetworks-IT/bixarea-infra repo was removed in PR #1480 We need to add it back because we still want to deploy from there.
1 parent 08c1eec commit dcb03ee

File tree

1 file changed

+6
-3
lines changed

1 file changed

+6
-3
lines changed

org-formation/650-identity-providers/_tasks.yaml

Lines changed: 6 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -945,7 +945,7 @@ GithubOidcBixArenaDevInfra:
945945
GithubOidcBixArenaInfra:
946946
Type: update-stacks
947947
DependsOn: GithubOidcSageBionetworks
948-
Template: https://raw.githubusercontent.com/Sage-Bionetworks/aws-infra/v0.10.2/templates/IAM/github-oidc-provider.j2
948+
Template: https://raw.githubusercontent.com/Sage-Bionetworks/aws-infra/v0.10.4/templates/IAM/github-oidc-provider.j2
949949
StackName: !Sub ${resourcePrefix}-${appName}-bixarena-infra
950950
Parameters:
951951
ProviderArn: !CopyValue [ !Sub '${resourcePrefix}-${appName}-ProviderArn' ]
@@ -955,10 +955,13 @@ GithubOidcBixArenaInfra:
955955
- "arn:aws:iam::aws:policy/AdministratorAccess"
956956
- "arn:aws:iam::aws:policy/AWSKeyManagementServicePowerUser"
957957
TemplatingContext:
958-
GitHubOrg: "Sage-Bionetworks"
959958
Repositories:
960-
- name: "sage-monorepo"
959+
- owner: "Sage-Bionetworks"
960+
name: "sage-monorepo"
961961
branches: ["infra/bixarena/*"]
962+
- owner: "Sage-Bionetworks-IT"
963+
name: "bixarena-infra"
964+
branches: ["stage"]
962965
DefaultOrganizationBinding:
963966
Account:
964967
- !Ref BixArenaProdAccount

0 commit comments

Comments
 (0)