From 3513f5de98ea626a47fa0ab0186edcf3c10fbccf Mon Sep 17 00:00:00 2001 From: Adam Moussa Date: Wed, 10 Jun 2026 13:51:27 -0400 Subject: [PATCH] Attach org permissions boundary to all Lambda roles Adds seahaven-lambda-execution-boundary to Globals.Function so every SAM-auto-generated Lambda execution role carries the boundary. Required for the INFRA-97 github-cfn-execution-role scope-down to safely permit iam:CreateRole on this stack. No explicit AWS::IAM::Role resources exist in this template; the Globals entry covers all six functions. Refs: INFRA-103 --- template.yaml | 1 + 1 file changed, 1 insertion(+) diff --git a/template.yaml b/template.yaml index b9b643e..bbad6f0 100644 --- a/template.yaml +++ b/template.yaml @@ -9,6 +9,7 @@ Globals: - arm64 Timeout: 30 MemorySize: 256 + PermissionsBoundary: arn:aws:iam::328440206208:policy/seahaven-lambda-execution-boundary Environment: Variables: TABLE_NAME: !Ref DashboardTable