mirror of
https://github.com/Sea-Haven-Industries/front-integrations.git
synced 2026-10-03 07:53:11 +00:00
Attach permissions boundary to all Lambda roles
Adds the seahaven-lambda-execution-boundary policy as a PermissionsBoundary on all auto-generated Lambda execution roles via Globals.Function, enabling the cfn-execution-role scope-down from INFRA-97 to safely allow iam:CreateRole. No explicit AWS::IAM::Role resources exist in this stack; the Globals entry covers both SlaMonitorFunction and UserSyncFunction. Refs: INFRA-103
This commit is contained in:
parent
6b689851d2
commit
d7499cca3a
1 changed files with 1 additions and 0 deletions
|
|
@ -51,6 +51,7 @@ Globals:
|
||||||
MemorySize: 256
|
MemorySize: 256
|
||||||
Architectures:
|
Architectures:
|
||||||
- arm64
|
- arm64
|
||||||
|
PermissionsBoundary: arn:aws:iam::328440206208:policy/seahaven-lambda-execution-boundary
|
||||||
|
|
||||||
Resources:
|
Resources:
|
||||||
# ---------------------------------------------------------------------------
|
# ---------------------------------------------------------------------------
|
||||||
|
|
|
||||||
Loading…
Add table
Reference in a new issue