From 59645952ef477dfe48702a6550578fc653c49894 Mon Sep 17 00:00:00 2001 From: Cursor Agent Date: Mon, 28 Sep 2026 01:06:48 +0000 Subject: [PATCH] docs(iam): correct shared boundary size and scoping notes (PLAT-52) The dev floor is the same 708-character document as the shared policy. 691 was stale. The scoping note now says the shared document is the four-statement floor, and allow-list retirement is a follow-up. Co-authored-by: Adam Moussa --- .../deploy-substrate.template.yaml | 38 +++++++++---------- 1 file changed, 19 insertions(+), 19 deletions(-) diff --git a/lib/deploy-substrate/deploy-substrate.template.yaml b/lib/deploy-substrate/deploy-substrate.template.yaml index e5c3c9f..638277c 100644 --- a/lib/deploy-substrate/deploy-substrate.template.yaml +++ b/lib/deploy-substrate/deploy-substrate.template.yaml @@ -149,9 +149,10 @@ Description: >- # seahaven-lambda-execution-boundary-seahaven-site: 1159 / 6 statements # seahaven-lambda-execution-boundary-seahaven-door-unlock-api: measure after deploy (PLAT-76) # seahaven-lambda-execution-boundary-paychex-integrations: 3250 / 10 statements (PLAT-228) -# Dev copies are floor-only (691 / 4) via IsProdAccount, except -# meal-order-manager (PLAT-210): DynamoDB/S3/SSM/invoke plus the -# seahaven-dev slack-bot-token ARN. SNS, SQS (Paychex), and SES stay prod. +# The same four floor statements measure 708 / 4 on the dev policies once +# IsProdAccount drops the prod-only statements. meal-order-manager +# (PLAT-210) also keeps DynamoDB/S3/SSM/invoke plus the seahaven-dev +# slack-bot-token ARN. SNS, SQS (Paychex), and SES stay prod. # # Guardrail PolicyDocuments also cap at 6,144. Each extra allow-list ARN # is copied into four Sids in EACH of SamCfnIamManagementPolicy and @@ -216,16 +217,15 @@ Resources: # intersection of the role's own policies and this boundary, so a misconfigured # SAM role can never exceed what is listed here. # - # SCOPING RULE (PLAT-52 phase 1, 2026-08-13). New workloads get their own - # ManagedPolicy seahaven-lambda-execution-boundary-: the fleet-wide - # floor (CloudWatchLogsWrite / CloudWatchLogsDescribe / XRay / Ec2Eni) plus - # that workload's data plane, derived from ITS OWN template. Do not add new - # data-plane statements to the shared seahaven-lambda-execution-boundary - # document — it is the legacy ceiling for roles not yet retargeted and stays - # unchanged until PermissionsBoundaryUsageCount is 0. INFRA-186 reduced this - # copy to a floor and later migrations packed data plane back into it under - # the 6,144-character cap (PLAT-93 / PLAT-100). Per-workload policies are - # the escape hatch from that cap and from the shared-ceiling residual. + # SCOPING RULE (PLAT-52). New workloads get their own ManagedPolicy + # seahaven-lambda-execution-boundary-: the four-statement floor + # (CloudWatchLogsWrite / CloudWatchLogsDescribe / XRay / Ec2Eni) plus that + # workload's data plane, derived from its own template. The shared + # seahaven-lambda-execution-boundary document is that same four-statement + # floor. Do not add data-plane statements to it. PermissionsBoundaryUsageCount + # is 0 in prod and dev, so the packed IsProdAccount statements are removed. + # Retiring the SAM allow-list of boundary ARNs in SamCfnIamManagementPolicy + # is a follow-up pull request. # # A resource pattern that genuinely CANNOT be scoped keeps its wildcard WITH a # written justification on the statement: CloudWatchLogsDescribe, XRay and @@ -533,12 +533,12 @@ Resources: # --------------------------------------------------------------------------- # Per-workload Lambda execution boundaries (PLAT-52 phase 1) # - # Each policy is the fleet floor plus that workload's data plane, split from - # the shared document above without editing it. Live roles keep the shared - # ARN until app-repo retargets. Guardrail StringEquals lists include both. - # Floor statements are YAML-anchored on AfiBackupMonitorBoundary; later - # policies alias them. Floor rationale lives on LambdaExecutionBoundary. - # Prod-only data plane stays behind IsProdAccount (same as the shared copy). + # Each policy is the fleet floor plus that workload's data plane. + # Guardrail StringEquals lists still include the shared ARN and each + # per-workload ARN until the allow-list follow-up. Floor statements are + # YAML-anchored on AfiBackupMonitorBoundary; later policies alias them. + # Floor rationale lives on LambdaExecutionBoundary. + # Prod-only data plane on these policies stays behind IsProdAccount. # --------------------------------------------------------------------------- AfiBackupMonitorBoundary: Type: AWS::IAM::ManagedPolicy