fix(iam): allow API Gateway authorizer role passing

This commit is contained in:
Adam Moussa 2026-08-03 14:34:45 -04:00
parent 5d0e8480d4
commit db1cc5300f
No known key found for this signature in database

View file

@ -1243,3 +1243,16 @@ Resources:
StringEquals:
"iam:PassedToService": "lambda.amazonaws.com"
# API Gateway assumes SAM authorizer invocation roles. Keep this
# separate from Lambda PassRole so each target service and role
# pattern remains independently constrained.
- Sid: IAMPassAuthorizerRole
Effect: Allow
Action:
- iam:PassRole
Resource:
- !Sub "arn:aws:iam::${AWS::AccountId}:role/cfn-managed/*AuthorizerInvokeRole-*"
Condition:
StringEquals:
"iam:PassedToService": "apigateway.amazonaws.com"