Attach permissions boundary to all Lambda execution roles (#105)
Some checks are pending
Deploy / deploy (push) Waiting to run

Applies seahaven-lambda-execution-boundary to all SAM auto-generated
function execution roles via Globals.Function.PermissionsBoundary.
Required so the github-cfn-execution-role scope-down (INFRA-97) can
safely constrain role creation without blocking Lambda deploys.

No explicit AWS::IAM::Role resources exist in this template.

Refs: INFRA-103
This commit is contained in:
Adam Moussa 2026-06-10 14:14:46 -04:00 • committed by GitHub
parent efa4bc569d
commit 424be7c2da
No known key found for this signature in database
GPG key ID: B5690EEEBB952194

View file

@ -21,6 +21,7 @@ Globals:
MemorySize: 1024
Architectures:
- arm64
PermissionsBoundary: arn:aws:iam::328440206208:policy/seahaven-lambda-execution-boundary
# Access logging + default throttling on the implicit HTTP API (audit M-18).
HttpApi:
AccessLogSettings: