From 266d08f70704e02899fb5609e28f69dffbd4cc66 Mon Sep 17 00:00:00 2001 From: Adam Moussa Date: Wed, 10 Jun 2026 13:51:17 -0400 Subject: [PATCH] Attach permissions boundary to all Lambda execution roles Applies seahaven-lambda-execution-boundary to all SAM auto-generated function execution roles via Globals.Function.PermissionsBoundary. Required so the github-cfn-execution-role scope-down (INFRA-97) can safely constrain role creation without blocking Lambda deploys. No explicit AWS::IAM::Role resources exist in this template. Refs: INFRA-103 --- template.yaml | 1 + 1 file changed, 1 insertion(+) diff --git a/template.yaml b/template.yaml index a6307b5..172e603 100644 --- a/template.yaml +++ b/template.yaml @@ -21,6 +21,7 @@ Globals: MemorySize: 1024 Architectures: - arm64 + PermissionsBoundary: arn:aws:iam::328440206208:policy/seahaven-lambda-execution-boundary # Access logging + default throttling on the implicit HTTP API (audit M-18). HttpApi: AccessLogSettings: