Skip to content

Fix cdk exec policy for bootstraping linked accounts (#763) #31

Fix cdk exec policy for bootstraping linked accounts (#763)

Fix cdk exec policy for bootstraping linked accounts (#763) #31

Workflow file for this run

name: CDK Nag
on:
workflow_dispatch:
push:
paths:
- "deploy/**"
branches:
- main
pull_request:
paths:
- "deploy/**"
branches:
- main
permissions:
id-token: write
contents: read
jobs:
cdk-nag:
strategy:
matrix:
python-version: [3.8]
env:
AWS_DEFAULT_REGION: us-east-1
runs-on: ubuntu-latest
steps:
- name: Git clone
uses: actions/checkout@v3
- name: configure aws credentials
uses: aws-actions/configure-aws-credentials@v4
with:
role-to-assume: arn:aws:iam::109658928441:role/aws-dataall-github-actions
role-session-name: dataall-gh-act
aws-region: ${{ env.AWS_DEFAULT_REGION }}
- name: Set up Node.js
uses: actions/setup-node@v3
- name: Install CDK
run: |
npm install -g aws-cdk cdk-nag
cdk --version
- name: Set up Python ${{ matrix.python-version }}
uses: actions/setup-python@v4
with:
python-version: ${{ matrix.python-version }}
- name: Upgrade Pip
run: python -m pip install --upgrade pip
- name: Install Requirements
run: python -m pip install -r deploy/requirements.txt
- name: CDK Synth
run: npx cdk synth