Attach permissions boundary to all Lambda execution roles

Applies seahaven-lambda-execution-boundary to all SAM auto-generated
function execution roles via Globals.Function.PermissionsBoundary.
Required so the github-cfn-execution-role scope-down (INFRA-97) can
safely constrain role creation without blocking Lambda deploys.

No explicit AWS::IAM::Role resources exist in this template.

Refs: INFRA-103
This commit is contained in:
Adam Moussa 2026-06-10 13:51:17 -04:00
parent efa4bc569d
commit 266d08f707

View file

@ -21,6 +21,7 @@ Globals:
MemorySize: 1024
Architectures:
- arm64
PermissionsBoundary: arn:aws:iam::328440206208:policy/seahaven-lambda-execution-boundary
# Access logging + default throttling on the implicit HTTP API (audit M-18).
HttpApi:
AccessLogSettings: