|
| 1 | +#!/usr/bin/env bash |
| 2 | +# check-aws-iam-parity.sh |
| 3 | +# |
| 4 | +# Asserts that the AWS IAM action lists granted to the CUDly runtime and to the |
| 5 | +# customer-deployed federation roles are identical across every IaC flavor that |
| 6 | +# encodes them, so CloudFormation and Terraform deployments of the same code |
| 7 | +# cannot silently drift apart (the AWS sibling of check-azure-role-parity.sh). |
| 8 | +# |
| 9 | +# Three comparisons: |
| 10 | +# |
| 11 | +# 1. runtime : cloudformation/stacks/CUDly/template.yaml |
| 12 | +# == terraform/modules/compute/aws/lambda/main.tf |
| 13 | +# == terraform/modules/compute/aws/fargate/main.tf |
| 14 | +# 2. federation cross-account pair (incl. the optional org-discovery |
| 15 | +# statement, which exists in both as an opt-in): |
| 16 | +# iac/federation/aws-cross-account/cloudformation/template.yaml |
| 17 | +# == iac/federation/aws-cross-account/terraform/main.tf |
| 18 | +# 3. federation core (org discovery excluded: the CLI quick-onboarding |
| 19 | +# scripts and the aws-target WIF flavor intentionally do not offer it): |
| 20 | +# both files from (2) |
| 21 | +# == iac/federation/aws-target/cloudformation/template.yaml |
| 22 | +# == iac/federation/aws-target/terraform/main.tf |
| 23 | +# == internal/iacfiles/templates/aws-cross-account-cli.sh.tmpl |
| 24 | +# == internal/iacfiles/templates/aws-wif-cli.sh.tmpl |
| 25 | +# |
| 26 | +# Only actions in the cloud-API namespaces the application code calls are |
| 27 | +# compared (see ACTION_PREFIXES). Platform plumbing (logs, dynamodb, ses, sns, |
| 28 | +# secretsmanager, sts, ssmmessages, lambda) legitimately differs per deployment |
| 29 | +# flavor and is excluded. |
| 30 | +# |
| 31 | +# Exit 0 = all lists match. |
| 32 | +# Exit 1 = drift found; the diff is printed to stderr. |
| 33 | +# Exit 2 = usage / environment error. |
| 34 | +# |
| 35 | +# Usage: |
| 36 | +# scripts/check-aws-iam-parity.sh [--root <path>] |
| 37 | +# |
| 38 | +# --root lets the test harness point at a fixture tree that mirrors the repo |
| 39 | +# layout without touching the real sources. |
| 40 | + |
| 41 | +set -euo pipefail |
| 42 | + |
| 43 | +REPO_ROOT="$(cd "$(dirname "${BASH_SOURCE[0]}")/.." && pwd)" |
| 44 | + |
| 45 | +while [[ $# -gt 0 ]]; do |
| 46 | + case "$1" in |
| 47 | + --root) |
| 48 | + if [[ $# -lt 2 || -z "${2:-}" ]]; then |
| 49 | + echo "ERROR: --root requires a path value" >&2 |
| 50 | + exit 2 |
| 51 | + fi |
| 52 | + REPO_ROOT="$2" |
| 53 | + shift 2 |
| 54 | + ;; |
| 55 | + *) echo "Unknown flag: $1" >&2; exit 2 ;; |
| 56 | + esac |
| 57 | +done |
| 58 | + |
| 59 | +# IAM action namespaces owned by the application code. Keep in sync with the |
| 60 | +# services the providers/aws code actually calls. |
| 61 | +ACTION_PREFIXES='ce|ec2|rds|elasticache|es|redshift|memorydb|savingsplans|organizations' |
| 62 | + |
| 63 | +# --- extraction --------------------------------------------------------------- |
| 64 | +# Pull every token shaped like <prefix>:<CamelCaseAction> out of a file, |
| 65 | +# regardless of whether it is YAML, HCL, or an embedded JSON heredoc. IAM |
| 66 | +# actions always start with an uppercase letter after the colon, which keeps |
| 67 | +# ARNs (region segments are lowercase) out of the match. |
| 68 | + |
| 69 | +extract_actions() { |
| 70 | + local file="$1" |
| 71 | + local exclude_orgs="${2:-}" |
| 72 | + |
| 73 | + if [[ ! -f "$file" ]]; then |
| 74 | + echo "ERROR: file not found: $file" >&2 |
| 75 | + exit 2 |
| 76 | + fi |
| 77 | + |
| 78 | + local actions |
| 79 | + actions=$(grep -oE "(^|[^A-Za-z])(${ACTION_PREFIXES}):[A-Z][A-Za-z]+" "$file" \ |
| 80 | + | sed 's/^[^a-zA-Z]//' \ |
| 81 | + | sort -u) |
| 82 | + |
| 83 | + if [[ "$exclude_orgs" == "no-orgs" ]]; then |
| 84 | + actions=$(printf '%s\n' "$actions" | grep -v '^organizations:' || true) |
| 85 | + fi |
| 86 | + |
| 87 | + if [[ -z "$actions" ]]; then |
| 88 | + echo "ERROR: no IAM actions extracted from: $file" >&2 |
| 89 | + echo " Did the policy move or change format?" >&2 |
| 90 | + exit 2 |
| 91 | + fi |
| 92 | + |
| 93 | + printf '%s\n' "$actions" |
| 94 | +} |
| 95 | + |
| 96 | +# --- comparison --------------------------------------------------------------- |
| 97 | + |
| 98 | +FAILURES=0 |
| 99 | + |
| 100 | +compare_pair() { |
| 101 | + local label="$1" ref_name="$2" ref_actions="$3" other_name="$4" other_actions="$5" |
| 102 | + |
| 103 | + local diff_out |
| 104 | + diff_out=$(diff <(printf '%s\n' "$ref_actions") <(printf '%s\n' "$other_actions") || true) |
| 105 | + |
| 106 | + if [[ -n "$diff_out" ]]; then |
| 107 | + { |
| 108 | + echo "ERROR [$label]: IAM action drift between:" |
| 109 | + echo " < $ref_name" |
| 110 | + echo " > $other_name" |
| 111 | + echo "$diff_out" |
| 112 | + echo "" |
| 113 | + } >&2 |
| 114 | + FAILURES=$((FAILURES + 1)) |
| 115 | + fi |
| 116 | +} |
| 117 | + |
| 118 | +# --- 1. runtime: CFN stack vs TF lambda vs TF fargate -------------------------- |
| 119 | + |
| 120 | +CFN_STACK="$REPO_ROOT/cloudformation/stacks/CUDly/template.yaml" |
| 121 | +TF_LAMBDA="$REPO_ROOT/terraform/modules/compute/aws/lambda/main.tf" |
| 122 | +TF_FARGATE="$REPO_ROOT/terraform/modules/compute/aws/fargate/main.tf" |
| 123 | + |
| 124 | +cfn_stack_actions=$(extract_actions "$CFN_STACK") |
| 125 | +tf_lambda_actions=$(extract_actions "$TF_LAMBDA") |
| 126 | +tf_fargate_actions=$(extract_actions "$TF_FARGATE") |
| 127 | + |
| 128 | +compare_pair "runtime" "$CFN_STACK" "$cfn_stack_actions" "$TF_LAMBDA" "$tf_lambda_actions" |
| 129 | +compare_pair "runtime" "$TF_LAMBDA" "$tf_lambda_actions" "$TF_FARGATE" "$tf_fargate_actions" |
| 130 | + |
| 131 | +# --- 2. federation cross-account pair (all namespaces) ------------------------- |
| 132 | + |
| 133 | +FED_XACC_CFN="$REPO_ROOT/iac/federation/aws-cross-account/cloudformation/template.yaml" |
| 134 | +FED_XACC_TF="$REPO_ROOT/iac/federation/aws-cross-account/terraform/main.tf" |
| 135 | + |
| 136 | +fed_cfn_actions=$(extract_actions "$FED_XACC_CFN") |
| 137 | +fed_tf_actions=$(extract_actions "$FED_XACC_TF") |
| 138 | + |
| 139 | +compare_pair "federation cross-account" "$FED_XACC_CFN" "$fed_cfn_actions" "$FED_XACC_TF" "$fed_tf_actions" |
| 140 | + |
| 141 | +# --- 3. federation core across all flavors (org discovery excluded) ------------ |
| 142 | + |
| 143 | +FED_WIF_CFN="$REPO_ROOT/iac/federation/aws-target/cloudformation/template.yaml" |
| 144 | +FED_WIF_TF="$REPO_ROOT/iac/federation/aws-target/terraform/main.tf" |
| 145 | +FED_XACC_CLI="$REPO_ROOT/internal/iacfiles/templates/aws-cross-account-cli.sh.tmpl" |
| 146 | +FED_WIF_CLI="$REPO_ROOT/internal/iacfiles/templates/aws-wif-cli.sh.tmpl" |
| 147 | + |
| 148 | +fed_core_ref=$(extract_actions "$FED_XACC_CFN" no-orgs) |
| 149 | + |
| 150 | +for f in "$FED_XACC_TF" "$FED_WIF_CFN" "$FED_WIF_TF" "$FED_XACC_CLI" "$FED_WIF_CLI"; do |
| 151 | + compare_pair "federation core" "$FED_XACC_CFN" "$fed_core_ref" "$f" "$(extract_actions "$f" no-orgs)" |
| 152 | +done |
| 153 | + |
| 154 | +# --- result -------------------------------------------------------------------- |
| 155 | + |
| 156 | +if [[ "$FAILURES" -gt 0 ]]; then |
| 157 | + echo "FAILED: $FAILURES IAM parity comparison(s) drifted. Update the lagging file(s) so all lists match." >&2 |
| 158 | + exit 1 |
| 159 | +fi |
| 160 | + |
| 161 | +echo "OK: AWS IAM action lists are in parity across CloudFormation, Terraform, and CLI onboarding templates." |
| 162 | +exit 0 |
0 commit comments