Attach permissions boundary to all Lambda roles (#7)
Some checks are pending
Deploy / deploy (push) Waiting to run

Adds the seahaven-lambda-execution-boundary policy as a
PermissionsBoundary on all auto-generated Lambda execution
roles via Globals.Function, enabling the cfn-execution-role
scope-down from INFRA-97 to safely allow iam:CreateRole.

No explicit AWS::IAM::Role resources exist in this stack;
the Globals entry covers both SlaMonitorFunction and
UserSyncFunction.

Refs: INFRA-103
This commit is contained in:
Adam Moussa 2026-06-10 14:14:58 -04:00 • committed by GitHub
parent 6b689851d2
commit e50c8f0876
No known key found for this signature in database
GPG key ID: B5690EEEBB952194

View file

@ -51,6 +51,7 @@ Globals:
MemorySize: 256
Architectures:
- arm64
PermissionsBoundary: arn:aws:iam::328440206208:policy/seahaven-lambda-execution-boundary
Resources:
# ---------------------------------------------------------------------------