From 424be7c2da0aa624f4840b8ba7a92cf613761947 Mon Sep 17 00:00:00 2001 From: Adam Moussa <166072409+amoussa1229@users.noreply.github.com> Date: Wed, 10 Jun 2026 14:14:46 -0400 Subject: [PATCH] Attach permissions boundary to all Lambda execution roles (#105) Applies seahaven-lambda-execution-boundary to all SAM auto-generated function execution roles via Globals.Function.PermissionsBoundary. Required so the github-cfn-execution-role scope-down (INFRA-97) can safely constrain role creation without blocking Lambda deploys. No explicit AWS::IAM::Role resources exist in this template. Refs: INFRA-103 --- template.yaml | 1 + 1 file changed, 1 insertion(+) diff --git a/template.yaml b/template.yaml index a6307b5..172e603 100644 --- a/template.yaml +++ b/template.yaml @@ -21,6 +21,7 @@ Globals: MemorySize: 1024 Architectures: - arm64 + PermissionsBoundary: arn:aws:iam::328440206208:policy/seahaven-lambda-execution-boundary # Access logging + default throttling on the implicit HTTP API (audit M-18). HttpApi: AccessLogSettings: