From 921efe2c04ec6806e272f5c17e9aca8b1cb0aabf Mon Sep 17 00:00:00 2001 From: Adam Moussa <166072409+amoussa1229@users.noreply.github.com> Date: Wed, 10 Jun 2026 14:14:54 -0400 Subject: [PATCH] Attach permissions boundary to all IAM roles (#25) MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Scope-down requirement from INFRA-97: github-cfn-execution-role needs iam:CreateRole scoped to roles that carry the org boundary, so every role this stack creates must declare it. - Globals.Function.PermissionsBoundary: applies to all six SAM auto-generated Lambda execution roles - AdminAuthorizerInvokeRole: adds PermissionsBoundary + Path /cfn-managed/ (explicit AWS::IAM::Role) The only consumer of AdminAuthorizerInvokeRole is the HttpApi authorizer's FunctionInvokeRole, which references it via !GetAtt AdminAuthorizerInvokeRole.Arn — no hardcoded ARN strings, so the path change is safe. Refs: INFRA-103 --- template.yaml | 3 +++ 1 file changed, 3 insertions(+) diff --git a/template.yaml b/template.yaml index c62a1f8..2c4ab01 100644 --- a/template.yaml +++ b/template.yaml @@ -37,6 +37,7 @@ Globals: - arm64 Timeout: 30 MemorySize: 256 + PermissionsBoundary: arn:aws:iam::328440206208:policy/seahaven-lambda-execution-boundary Environment: Variables: TABLE_NAME: !Ref OrdersTable @@ -384,6 +385,8 @@ Resources: AdminAuthorizerInvokeRole: Type: AWS::IAM::Role Properties: + Path: /cfn-managed/ + PermissionsBoundary: arn:aws:iam::328440206208:policy/seahaven-lambda-execution-boundary AssumeRolePolicyDocument: Version: '2012-10-17' Statement: