Attach permissions boundary to all IAM roles (#25)
Some checks are pending
Deploy / deploy (push) Waiting to run

Scope-down requirement from INFRA-97: github-cfn-execution-role
needs iam:CreateRole scoped to roles that carry the org boundary,
so every role this stack creates must declare it.

- Globals.Function.PermissionsBoundary: applies to all six
  SAM auto-generated Lambda execution roles
- AdminAuthorizerInvokeRole: adds PermissionsBoundary + Path
  /cfn-managed/ (explicit AWS::IAM::Role)

The only consumer of AdminAuthorizerInvokeRole is the HttpApi
authorizer's FunctionInvokeRole, which references it via
!GetAtt AdminAuthorizerInvokeRole.Arn — no hardcoded ARN
strings, so the path change is safe.

Refs: INFRA-103
This commit is contained in:
Adam Moussa 2026-06-10 14:14:54 -04:00 • committed by GitHub
parent 75fb3280f5
commit 921efe2c04
No known key found for this signature in database
GPG key ID: B5690EEEBB952194

View file

@ -37,6 +37,7 @@ Globals:
- arm64
Timeout: 30
MemorySize: 256
PermissionsBoundary: arn:aws:iam::328440206208:policy/seahaven-lambda-execution-boundary
Environment:
Variables:
TABLE_NAME: !Ref OrdersTable
@ -384,6 +385,8 @@ Resources:
AdminAuthorizerInvokeRole:
Type: AWS::IAM::Role
Properties:
Path: /cfn-managed/
PermissionsBoundary: arn:aws:iam::328440206208:policy/seahaven-lambda-execution-boundary
AssumeRolePolicyDocument:
Version: '2012-10-17'
Statement: