Attach org permissions boundary to all Lambda roles (#43)
Some checks are pending
Deploy / deploy (push) Waiting to run

Adds seahaven-lambda-execution-boundary to Globals.Function so every
SAM-auto-generated Lambda execution role carries the boundary. Required
for the INFRA-97 github-cfn-execution-role scope-down to safely permit
iam:CreateRole on this stack.

No explicit AWS::IAM::Role resources exist in this template; the
Globals entry covers all six functions.

Refs: INFRA-103
This commit is contained in:
Adam Moussa 2026-06-10 14:14:50 -04:00 • committed by GitHub
parent 699928116d
commit 0d4f3f69b4
No known key found for this signature in database
GPG key ID: B5690EEEBB952194

View file

@ -9,6 +9,7 @@ Globals:
- arm64
Timeout: 30
MemorySize: 256
PermissionsBoundary: arn:aws:iam::328440206208:policy/seahaven-lambda-execution-boundary
Environment:
Variables:
TABLE_NAME: !Ref DashboardTable