From e50c8f08769b824a7ce746150ee98d35ade49e32 Mon Sep 17 00:00:00 2001 From: Adam Moussa <166072409+amoussa1229@users.noreply.github.com> Date: Wed, 10 Jun 2026 14:14:58 -0400 Subject: [PATCH] Attach permissions boundary to all Lambda roles (#7) Adds the seahaven-lambda-execution-boundary policy as a PermissionsBoundary on all auto-generated Lambda execution roles via Globals.Function, enabling the cfn-execution-role scope-down from INFRA-97 to safely allow iam:CreateRole. No explicit AWS::IAM::Role resources exist in this stack; the Globals entry covers both SlaMonitorFunction and UserSyncFunction. Refs: INFRA-103 --- template.yaml | 1 + 1 file changed, 1 insertion(+) diff --git a/template.yaml b/template.yaml index 81f40aa..09baba5 100644 --- a/template.yaml +++ b/template.yaml @@ -51,6 +51,7 @@ Globals: MemorySize: 256 Architectures: - arm64 + PermissionsBoundary: arn:aws:iam::328440206208:policy/seahaven-lambda-execution-boundary Resources: # ---------------------------------------------------------------------------