fix(iam): allow API Gateway authorizer role passing
Some checks are pending
Deploy / deploy-management (push) Waiting to run
Deploy / deploy-external-dev (push) Waiting to run
Deploy / deploy-security (push) Waiting to run
Deploy / deploy-dev (push) Waiting to run
Deploy / deploy-prod (push) Waiting to run

This commit is contained in:
Adam Moussa 2026-08-03 14:38:39 -04:00 • committed by GitHub
parent 5d0e8480d4
commit c09cf1110d
No known key found for this signature in database
GPG key ID: B5690EEEBB952194

View file

@ -1243,3 +1243,16 @@ Resources:
StringEquals: StringEquals:
"iam:PassedToService": "lambda.amazonaws.com" "iam:PassedToService": "lambda.amazonaws.com"
# API Gateway assumes SAM authorizer invocation roles. Keep this
# separate from Lambda PassRole so each target service and role
# pattern remains independently constrained.
- Sid: IAMPassAuthorizerRole
Effect: Allow
Action:
- iam:PassRole
Resource:
- !Sub "arn:aws:iam::${AWS::AccountId}:role/cfn-managed/*AuthorizerInvokeRole-*"
Condition:
StringEquals:
"iam:PassedToService": "apigateway.amazonaws.com"