In order to check stateless services are running correctly, we need a new cross-acct role that bastion can use to run the smoke-tests inside each of the respective accounts.
Related to OrcaBus/service-dragen-wgts-dna-pipeline-manager#122
Permissions would include:
What I can't figure out is where to stick this:
https://github.com/umccr/infrastructure/tree/master/terraform/stacks/cdk_bootstrap is deprecated and uses the umccr-unimelb toolchain as the trusted account rather than the bastion account
https://github.com/umccr/infrastructure/blob/master/terraform/stacks/bootstrap is also deprecated
https://github.com/umccr/infrastructure/blob/master/scripts/aws_bootstrap/bootstrap-template.yaml seems like the right spot but then bootstrap-update-all.sh appears to only apply this to the unimelb accounts, not the umccr accounts?
In order to check stateless services are running correctly, we need a new cross-acct role that bastion can use to run the smoke-tests inside each of the respective accounts.
Related to OrcaBus/service-dragen-wgts-dna-pipeline-manager#122
Permissions would include:
CloudFormationDiscovery
LambdaInvocation (would be dryrun only but I don't think I can control that from a policy side)
StepFunctions (Describe only)
SSMParameter (Read only)
IamRoleInspection
What I can't figure out is where to stick this:
https://github.com/umccr/infrastructure/tree/master/terraform/stacks/cdk_bootstrap is deprecated and uses the umccr-unimelb toolchain as the trusted account rather than the bastion account
https://github.com/umccr/infrastructure/blob/master/terraform/stacks/bootstrap is also deprecated
https://github.com/umccr/infrastructure/blob/master/scripts/aws_bootstrap/bootstrap-template.yaml seems like the right spot but then bootstrap-update-all.sh appears to only apply this to the unimelb accounts, not the umccr accounts?