mirror of
https://github.com/Sea-Haven-Industries/seahaven-org-baseline.git
synced 2026-10-03 22:23:12 +00:00
docs(iam): correct shared boundary size and scoping notes (PLAT-52)
The dev floor is the same 708-character document as the shared policy. 691 was stale. The scoping note now says the shared document is the four-statement floor, and allow-list retirement is a follow-up. Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com>
This commit is contained in:
parent
06c0be8314
commit
59645952ef
1 changed files with 19 additions and 19 deletions
|
|
@ -149,9 +149,10 @@ Description: >-
|
|||
# seahaven-lambda-execution-boundary-seahaven-site: 1159 / 6 statements
|
||||
# seahaven-lambda-execution-boundary-seahaven-door-unlock-api: measure after deploy (PLAT-76)
|
||||
# seahaven-lambda-execution-boundary-paychex-integrations: 3250 / 10 statements (PLAT-228)
|
||||
# Dev copies are floor-only (691 / 4) via IsProdAccount, except
|
||||
# meal-order-manager (PLAT-210): DynamoDB/S3/SSM/invoke plus the
|
||||
# seahaven-dev slack-bot-token ARN. SNS, SQS (Paychex), and SES stay prod.
|
||||
# The same four floor statements measure 708 / 4 on the dev policies once
|
||||
# IsProdAccount drops the prod-only statements. meal-order-manager
|
||||
# (PLAT-210) also keeps DynamoDB/S3/SSM/invoke plus the seahaven-dev
|
||||
# slack-bot-token ARN. SNS, SQS (Paychex), and SES stay prod.
|
||||
#
|
||||
# Guardrail PolicyDocuments also cap at 6,144. Each extra allow-list ARN
|
||||
# is copied into four Sids in EACH of SamCfnIamManagementPolicy and
|
||||
|
|
@ -216,16 +217,15 @@ Resources:
|
|||
# intersection of the role's own policies and this boundary, so a misconfigured
|
||||
# SAM role can never exceed what is listed here.
|
||||
#
|
||||
# SCOPING RULE (PLAT-52 phase 1, 2026-08-13). New workloads get their own
|
||||
# ManagedPolicy seahaven-lambda-execution-boundary-<workload>: the fleet-wide
|
||||
# floor (CloudWatchLogsWrite / CloudWatchLogsDescribe / XRay / Ec2Eni) plus
|
||||
# that workload's data plane, derived from ITS OWN template. Do not add new
|
||||
# data-plane statements to the shared seahaven-lambda-execution-boundary
|
||||
# document — it is the legacy ceiling for roles not yet retargeted and stays
|
||||
# unchanged until PermissionsBoundaryUsageCount is 0. INFRA-186 reduced this
|
||||
# copy to a floor and later migrations packed data plane back into it under
|
||||
# the 6,144-character cap (PLAT-93 / PLAT-100). Per-workload policies are
|
||||
# the escape hatch from that cap and from the shared-ceiling residual.
|
||||
# SCOPING RULE (PLAT-52). New workloads get their own ManagedPolicy
|
||||
# seahaven-lambda-execution-boundary-<workload>: the four-statement floor
|
||||
# (CloudWatchLogsWrite / CloudWatchLogsDescribe / XRay / Ec2Eni) plus that
|
||||
# workload's data plane, derived from its own template. The shared
|
||||
# seahaven-lambda-execution-boundary document is that same four-statement
|
||||
# floor. Do not add data-plane statements to it. PermissionsBoundaryUsageCount
|
||||
# is 0 in prod and dev, so the packed IsProdAccount statements are removed.
|
||||
# Retiring the SAM allow-list of boundary ARNs in SamCfnIamManagementPolicy
|
||||
# is a follow-up pull request.
|
||||
#
|
||||
# A resource pattern that genuinely CANNOT be scoped keeps its wildcard WITH a
|
||||
# written justification on the statement: CloudWatchLogsDescribe, XRay and
|
||||
|
|
@ -533,12 +533,12 @@ Resources:
|
|||
# ---------------------------------------------------------------------------
|
||||
# Per-workload Lambda execution boundaries (PLAT-52 phase 1)
|
||||
#
|
||||
# Each policy is the fleet floor plus that workload's data plane, split from
|
||||
# the shared document above without editing it. Live roles keep the shared
|
||||
# ARN until app-repo retargets. Guardrail StringEquals lists include both.
|
||||
# Floor statements are YAML-anchored on AfiBackupMonitorBoundary; later
|
||||
# policies alias them. Floor rationale lives on LambdaExecutionBoundary.
|
||||
# Prod-only data plane stays behind IsProdAccount (same as the shared copy).
|
||||
# Each policy is the fleet floor plus that workload's data plane.
|
||||
# Guardrail StringEquals lists still include the shared ARN and each
|
||||
# per-workload ARN until the allow-list follow-up. Floor statements are
|
||||
# YAML-anchored on AfiBackupMonitorBoundary; later policies alias them.
|
||||
# Floor rationale lives on LambdaExecutionBoundary.
|
||||
# Prod-only data plane on these policies stays behind IsProdAccount.
|
||||
# ---------------------------------------------------------------------------
|
||||
AfiBackupMonitorBoundary:
|
||||
Type: AWS::IAM::ManagedPolicy
|
||||
|
|
|
|||
Loading…
Add table
Reference in a new issue