docs(iam): correct shared boundary size and scoping notes (PLAT-52)

The dev floor is the same 708-character document as the shared policy.
691 was stale. The scoping note now says the shared document is the
four-statement floor, and allow-list retirement is a follow-up.

Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com>
This commit is contained in:
Cursor Agent 2026-09-28 01:06:48 +00:00
parent 06c0be8314
commit 59645952ef
No known key found for this signature in database

View file

@ -149,9 +149,10 @@ Description: >-
# seahaven-lambda-execution-boundary-seahaven-site: 1159 / 6 statements
# seahaven-lambda-execution-boundary-seahaven-door-unlock-api: measure after deploy (PLAT-76)
# seahaven-lambda-execution-boundary-paychex-integrations: 3250 / 10 statements (PLAT-228)
# Dev copies are floor-only (691 / 4) via IsProdAccount, except
# meal-order-manager (PLAT-210): DynamoDB/S3/SSM/invoke plus the
# seahaven-dev slack-bot-token ARN. SNS, SQS (Paychex), and SES stay prod.
# The same four floor statements measure 708 / 4 on the dev policies once
# IsProdAccount drops the prod-only statements. meal-order-manager
# (PLAT-210) also keeps DynamoDB/S3/SSM/invoke plus the seahaven-dev
# slack-bot-token ARN. SNS, SQS (Paychex), and SES stay prod.
#
# Guardrail PolicyDocuments also cap at 6,144. Each extra allow-list ARN
# is copied into four Sids in EACH of SamCfnIamManagementPolicy and
@ -216,16 +217,15 @@ Resources:
# intersection of the role's own policies and this boundary, so a misconfigured
# SAM role can never exceed what is listed here.
#
# SCOPING RULE (PLAT-52 phase 1, 2026-08-13). New workloads get their own
# ManagedPolicy seahaven-lambda-execution-boundary-<workload>: the fleet-wide
# floor (CloudWatchLogsWrite / CloudWatchLogsDescribe / XRay / Ec2Eni) plus
# that workload's data plane, derived from ITS OWN template. Do not add new
# data-plane statements to the shared seahaven-lambda-execution-boundary
# document — it is the legacy ceiling for roles not yet retargeted and stays
# unchanged until PermissionsBoundaryUsageCount is 0. INFRA-186 reduced this
# copy to a floor and later migrations packed data plane back into it under
# the 6,144-character cap (PLAT-93 / PLAT-100). Per-workload policies are
# the escape hatch from that cap and from the shared-ceiling residual.
# SCOPING RULE (PLAT-52). New workloads get their own ManagedPolicy
# seahaven-lambda-execution-boundary-<workload>: the four-statement floor
# (CloudWatchLogsWrite / CloudWatchLogsDescribe / XRay / Ec2Eni) plus that
# workload's data plane, derived from its own template. The shared
# seahaven-lambda-execution-boundary document is that same four-statement
# floor. Do not add data-plane statements to it. PermissionsBoundaryUsageCount
# is 0 in prod and dev, so the packed IsProdAccount statements are removed.
# Retiring the SAM allow-list of boundary ARNs in SamCfnIamManagementPolicy
# is a follow-up pull request.
#
# A resource pattern that genuinely CANNOT be scoped keeps its wildcard WITH a
# written justification on the statement: CloudWatchLogsDescribe, XRay and
@ -533,12 +533,12 @@ Resources:
# ---------------------------------------------------------------------------
# Per-workload Lambda execution boundaries (PLAT-52 phase 1)
#
# Each policy is the fleet floor plus that workload's data plane, split from
# the shared document above without editing it. Live roles keep the shared
# ARN until app-repo retargets. Guardrail StringEquals lists include both.
# Floor statements are YAML-anchored on AfiBackupMonitorBoundary; later
# policies alias them. Floor rationale lives on LambdaExecutionBoundary.
# Prod-only data plane stays behind IsProdAccount (same as the shared copy).
# Each policy is the fleet floor plus that workload's data plane.
# Guardrail StringEquals lists still include the shared ARN and each
# per-workload ARN until the allow-list follow-up. Floor statements are
# YAML-anchored on AfiBackupMonitorBoundary; later policies alias them.
# Floor rationale lives on LambdaExecutionBoundary.
# Prod-only data plane on these policies stays behind IsProdAccount.
# ---------------------------------------------------------------------------
AfiBackupMonitorBoundary:
Type: AWS::IAM::ManagedPolicy