Skip to content

Condition the scheduler role on the group Scheduler actually presents - #71

Merged
hannahhoward merged 1 commit into
mainfrom
fix/scheduler-role-trust
Sep 21, 2026
Merged

hannahhoward merged 1 commit into
mainfrom
fix/scheduler-role-trust

Conversation

@hannahhoward

Copy link
Copy Markdown
Contributor

Summary

The staging deploy of #60 failed on all twenty-seven schedules with ValidationException: The execution role you provide must allow AWS EventBridge Scheduler to assume the role. My regression, from the last commit on that PR.

The trust policy conditioned aws:SourceArn on a schedule ARN. EventBridge Scheduler presents the schedule group when it assumes the execution role, so the condition could never match. CreateSchedule checks the role is assumable before it creates anything, which is why every schedule failed rather than some.

Confirmed against the account rather than inferred:

What the deployed policy requires arn:aws:scheduler:us-east-2:654654381893:schedule/staging-clockwork-tasks/*
What the group's ARN actually is arn:aws:scheduler:us-east-2:654654381893:schedule-group/staging-clockwork-tasks

I also ruled out the other candidate: the role was created seventy-six seconds before the first CreateSchedule, so this is not IAM propagation.

Both conditions stay rather than being dropped. The account still pins the role to one account, and the group is as narrow as Scheduler permits. The group's name and ARN now come from a single local so the two cannot drift again.

Deliverables

File Status Summary
deploy/app/schedules.tf Modified source ARN names the schedule group; group name and ARN share one local

Test plan

  • tofu validate and tofu fmt on the prod workspace
  • The constructed ARN matches aws scheduler get-schedule-group for the live staging group, character for character
  • The staging deploy creates the schedules, which is the real proof

Staging is serving normally in the meantime: the apply failed after the service rolled, so only the schedules are missing, and the group exists with none in it.

🤖 Generated with Claude Code

https://claude.ai/code/session_01RzTEVpxi5LHTXSZywnFjea

Every schedule in the staging deploy failed with "The execution role you
provide must allow AWS EventBridge Scheduler to assume the role". The trust
policy conditioned aws:SourceArn on a schedule ARN, and Scheduler presents
the schedule group when it assumes the role, so the condition could never
match. CreateSchedule checks the role is assumable before it creates
anything, which is why all twenty-seven failed rather than some.

The condition now names the group. Both conditions stay: the account still
pins the role to one account, and the group is as narrow as Scheduler
allows. The group's name and ARN come from one local so they cannot drift.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01RzTEVpxi5LHTXSZywnFjea
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 21, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-09-21T02:52:40.636622Z c23f2e4 PR opened
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@hannahhoward
hannahhoward merged commit c075b2b into main Sep 21, 2026
12 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant