This repository has been archived on 2026-08-04. You can view files and clone it, but cannot push or open issues or pull requests.
orchestrator/security-review/iam
Adam Moussa acdba9a4d4 fix(secrev): apply IAM cross-review FIXes
GPT-4.1 IAM cross-review 2026-06-18: APPROVE, no BLOCKs. Applied FIXes:
- trust policy: add aws:SourceAccount=328440206208 (confused-deputy guard)
  alongside the existing aws:SourceArn trust-anchor pin
- readonly policy: remove ec2:DescribeImages (data minimization — AMIs are
  not an idle-spend signal)
- aws:RequestedRegion NIT: deliberately SKIPPED — ce:* and s3:ListAllMyBuckets
  are global-endpoint services a blanket region condition could DENY; rationale
  recorded in aws-posture-readonly-policy.rationale.md
- rationale.md + CROSS-REVIEW-PACKET.md: record APPROVE + FIXes + NIT answers
  (snapshots=account-owned idle signal; s3 list=names-only; no logs:* needed)
2026-06-18 16:17:56 -04:00
..
aws-posture-readonly-policy.json fix(secrev): apply IAM cross-review FIXes 2026-06-18 16:17:56 -04:00
aws-posture-readonly-policy.rationale.md fix(secrev): apply IAM cross-review FIXes 2026-06-18 16:17:56 -04:00
aws-posture-trust-policy.json fix(secrev): apply IAM cross-review FIXes 2026-06-18 16:17:56 -04:00
CROSS-REVIEW-PACKET.md fix(secrev): apply IAM cross-review FIXes 2026-06-18 16:17:56 -04:00
README.md feat(secrev): Phase-3 IAM artifacts for cross-review (aws-posture gated) 2026-06-18 16:17:56 -04:00
roles-anywhere-config.json feat(secrev): Phase-3 IAM artifacts for cross-review (aws-posture gated) 2026-06-18 16:17:56 -04:00
step-ca-config-sketch.md feat(secrev): Phase-3 IAM artifacts for cross-review (aws-posture gated) 2026-06-18 16:17:56 -04:00

security-review/iam/ — Phase-3 IAM artifacts (authored for cross-review, NOT applied)

These are the IAM / Roles Anywhere / step-ca artifacts for the R720 agent-team aws-posture checker (design docs/r720-agent-team-design.md D5 / §4 / §6.3 / §7 Phase 3).

Nothing here is applied to AWS. They are FILES for the mandatory GPT-4.1 IAM cross-review. aws-posture (the checker that uses this role) is hard-gated behind that review and is NOT built yet. Provisioning happens only after the review is recorded (design §7, B3) — and a VM snapshot is taken first per feedback_ec2_replacement_snapshot.

Decision (D5): the box stays read-only and authenticates to AWS via Roles Anywhere short-lived leaf certs issued by a new internal step-ca — no long-lived AWS key on the box.

File Purpose
CROSS-REVIEW-PACKET.md Start here. End-to-end trust model, least-privilege rationale, blast radius, exercised rollback, and the specific items for the reviewer.
aws-posture-readonly-policy.json Least-privilege read-only permission policy (valid, applyable IAM JSON).
aws-posture-readonly-policy.rationale.md Statement-by-statement rationale (IAM JSON can't carry comments).
aws-posture-trust-policy.json Role trust policy — pins Roles Anywhere + the leaf subject/issuer CN + trust-anchor ARN.
roles-anywhere-config.json Trust-anchor (pins step-ca root) + profile (1h session) config.
step-ca-config-sketch.md Internal CA config + systemd-timer auto-renewal of the short-lived leaf.

Per global instructions this IAM change also requires the GPT-4.1 cross-family review via orchestrator/run.py; this directory is that review's input.