fix(iam): attach per-workload lambda permissions boundary (PLAT-52) (#148)

* fix(iam): attach per-workload lambda permissions boundary (PLAT-52)

* fix(iam): skip boundary delete on weekly-menu role (PLAT-52)
This commit is contained in:
Adam Moussa 2026-08-20 16:02:46 -04:00 • committed by GitHub
parent a247f2f45a
commit c5c29b2bef
No known key found for this signature in database
GPG key ID: B5690EEEBB952194
3 changed files with 18 additions and 8 deletions

View file

@ -1,10 +1,10 @@
# Execution roles for the seven Lambda functions plus the API Gateway role that # Execution roles for the seven Lambda functions plus the API Gateway role that
# invokes the admin authorizer. # invokes the admin authorizer.
# #
# Every role is created under the /tf-managed/ path and carries the account's # Every Lambda execution role is created under the /tf-managed/ path and
# seahaven-lambda-execution-boundary permissions boundary. The path is what # carries seahaven-lambda-execution-boundary-meal-order-manager (PLAT-52).
# distinguishes Terraform-owned roles from the /cfn-managed/ roles the retired # The path distinguishes Terraform-owned roles from the retired SAM
# SAM stack created. # /cfn-managed/ roles.
# #
# The inline policies below are hand-expanded from the SAM policy templates in # The inline policies below are hand-expanded from the SAM policy templates in
# template.yaml (DynamoDBCrudPolicy, DynamoDBReadPolicy, S3CrudPolicy, # template.yaml (DynamoDBCrudPolicy, DynamoDBReadPolicy, S3CrudPolicy,

View file

@ -47,8 +47,18 @@ resource "aws_iam_role" "weekly_menu" {
path = "/tf-managed/" path = "/tf-managed/"
description = "GitHub Actions weekly-menu scrape/publish for meal-order-manager" description = "GitHub Actions weekly-menu scrape/publish for meal-order-manager"
assume_role_policy = data.aws_iam_policy_document.weekly_menu_assume.json assume_role_policy = data.aws_iam_policy_document.weekly_menu_assume.json
permissions_boundary = local.boundary_arn
max_session_duration = 3600 max_session_duration = 3600
# Not a Lambda execution role. Config omits permissions_boundary so a later
# apply will not PutRolePermissionsBoundary the Lambda ceiling back. Live still
# has seahaven-lambda-execution-boundary; omitting without ignore_changes would
# plan DeleteRolePermissionsBoundary, which hcptf-meal-order-manager is denied
# (DenyBoundaryTampering). Ignore the attribute so this apply does not touch
# the ceiling. An administrator deletes the live attachment, then a follow-up
# drops this lifecycle after refresh-only updates state to null.
lifecycle {
ignore_changes = [permissions_boundary]
}
} }
data "aws_iam_policy_document" "weekly_menu" { data "aws_iam_policy_document" "weekly_menu" {

View file

@ -2,9 +2,9 @@ locals {
project = "meal-order-manager" project = "meal-order-manager"
account_id = "011934824531" account_id = "011934824531"
# Every execution role in this configuration is created under /tf-managed/ and # Lambda execution roles under /tf-managed/ carry the per-workload ceiling
# carries the account's Lambda execution boundary. # (PLAT-52). githubdeploy-meal-order-manager-weekly-menu must not.
boundary_arn = "arn:aws:iam::${local.account_id}:policy/seahaven-lambda-execution-boundary" boundary_arn = "arn:aws:iam::${local.account_id}:policy/seahaven-lambda-execution-boundary-meal-order-manager"
form_bucket_name = "${local.project}-form-${local.account_id}" form_bucket_name = "${local.project}-form-${local.account_id}"
reports_bucket_name = "${local.project}-reports-${local.account_id}" reports_bucket_name = "${local.project}-reports-${local.account_id}"