mirror of
https://github.com/Sea-Haven-Industries/meal-order-manager.git
synced 2026-09-30 05:23:13 +00:00
Attach permissions boundary to all IAM roles (#25)
Some checks are pending
Deploy / deploy (push) Waiting to run
Some checks are pending
Deploy / deploy (push) Waiting to run
Scope-down requirement from INFRA-97: github-cfn-execution-role needs iam:CreateRole scoped to roles that carry the org boundary, so every role this stack creates must declare it. - Globals.Function.PermissionsBoundary: applies to all six SAM auto-generated Lambda execution roles - AdminAuthorizerInvokeRole: adds PermissionsBoundary + Path /cfn-managed/ (explicit AWS::IAM::Role) The only consumer of AdminAuthorizerInvokeRole is the HttpApi authorizer's FunctionInvokeRole, which references it via !GetAtt AdminAuthorizerInvokeRole.Arn — no hardcoded ARN strings, so the path change is safe. Refs: INFRA-103
This commit is contained in:
parent
75fb3280f5
commit
921efe2c04
1 changed files with 3 additions and 0 deletions
|
|
@ -37,6 +37,7 @@ Globals:
|
|||
- arm64
|
||||
Timeout: 30
|
||||
MemorySize: 256
|
||||
PermissionsBoundary: arn:aws:iam::328440206208:policy/seahaven-lambda-execution-boundary
|
||||
Environment:
|
||||
Variables:
|
||||
TABLE_NAME: !Ref OrdersTable
|
||||
|
|
@ -384,6 +385,8 @@ Resources:
|
|||
AdminAuthorizerInvokeRole:
|
||||
Type: AWS::IAM::Role
|
||||
Properties:
|
||||
Path: /cfn-managed/
|
||||
PermissionsBoundary: arn:aws:iam::328440206208:policy/seahaven-lambda-execution-boundary
|
||||
AssumeRolePolicyDocument:
|
||||
Version: '2012-10-17'
|
||||
Statement:
|
||||
|
|
|
|||
Loading…
Add table
Reference in a new issue