mirror of
https://github.com/Sea-Haven-Industries/meal-order-manager.git
synced 2026-10-07 06:58:54 +00:00
Attach permissions boundary to all IAM roles (#25)
Some checks are pending
Deploy / deploy (push) Waiting to run
Some checks are pending
Deploy / deploy (push) Waiting to run
Scope-down requirement from INFRA-97: github-cfn-execution-role needs iam:CreateRole scoped to roles that carry the org boundary, so every role this stack creates must declare it. - Globals.Function.PermissionsBoundary: applies to all six SAM auto-generated Lambda execution roles - AdminAuthorizerInvokeRole: adds PermissionsBoundary + Path /cfn-managed/ (explicit AWS::IAM::Role) The only consumer of AdminAuthorizerInvokeRole is the HttpApi authorizer's FunctionInvokeRole, which references it via !GetAtt AdminAuthorizerInvokeRole.Arn — no hardcoded ARN strings, so the path change is safe. Refs: INFRA-103
This commit is contained in:
parent
75fb3280f5
commit
921efe2c04
1 changed files with 3 additions and 0 deletions
|
|
@ -37,6 +37,7 @@ Globals:
|
||||||
- arm64
|
- arm64
|
||||||
Timeout: 30
|
Timeout: 30
|
||||||
MemorySize: 256
|
MemorySize: 256
|
||||||
|
PermissionsBoundary: arn:aws:iam::328440206208:policy/seahaven-lambda-execution-boundary
|
||||||
Environment:
|
Environment:
|
||||||
Variables:
|
Variables:
|
||||||
TABLE_NAME: !Ref OrdersTable
|
TABLE_NAME: !Ref OrdersTable
|
||||||
|
|
@ -384,6 +385,8 @@ Resources:
|
||||||
AdminAuthorizerInvokeRole:
|
AdminAuthorizerInvokeRole:
|
||||||
Type: AWS::IAM::Role
|
Type: AWS::IAM::Role
|
||||||
Properties:
|
Properties:
|
||||||
|
Path: /cfn-managed/
|
||||||
|
PermissionsBoundary: arn:aws:iam::328440206208:policy/seahaven-lambda-execution-boundary
|
||||||
AssumeRolePolicyDocument:
|
AssumeRolePolicyDocument:
|
||||||
Version: '2012-10-17'
|
Version: '2012-10-17'
|
||||||
Statement:
|
Statement:
|
||||||
|
|
|
||||||
Loading…
Add table
Reference in a new issue