Attach org permissions boundary to all Lambda roles

Adds seahaven-lambda-execution-boundary to Globals.Function so every
SAM-auto-generated Lambda execution role carries the boundary. Required
for the INFRA-97 github-cfn-execution-role scope-down to safely permit
iam:CreateRole on this stack.

No explicit AWS::IAM::Role resources exist in this template; the
Globals entry covers all six functions.

Refs: INFRA-103
This commit is contained in:
Adam Moussa 2026-06-10 13:51:27 -04:00
parent 699928116d
commit 3513f5de98

View file

@ -9,6 +9,7 @@ Globals:
- arm64
Timeout: 30
MemorySize: 256
PermissionsBoundary: arn:aws:iam::328440206208:policy/seahaven-lambda-execution-boundary
Environment:
Variables:
TABLE_NAME: !Ref DashboardTable