mirror of
https://github.com/Sea-Haven-Industries/seahaven-org-baseline.git
synced 2026-09-30 05:43:17 +00:00
fix(iam): reconcile the remaining substrate divergences from the mgmt copy
Review of the DenySelfMutation port found the header's 'reconciled' claim was not yet true: mgmt Phase A also added the CloudWatch Logs metric-filter actions (afterhours-shift-manager creates an AWS::Logs::MetricFilter through this role), and without them a migrating SAM stack fails mid-deploy with AccessDenied. Ports those three actions and corrects two stale header notes. Every IAM statement in the three shared resources is now byte-identical across both files, verified programmatically; the only delta left is the DependsOn ordering line.
This commit is contained in:
parent
62f6a76e6c
commit
61a94da4fc
1 changed files with 15 additions and 4 deletions
|
|
@ -30,16 +30,21 @@ Description: >-
|
|||
# first deploy failed with ServiceLimitExceeded (2026-07-27). Effective
|
||||
# permissions are unchanged — verified by comparing the full 27-statement
|
||||
# set before and after the move (identical), since identity policies are
|
||||
# unioned and an explicit Deny still wins. NOTE for the mgmt remediation:
|
||||
# mgmt needs this same restructure before its Deny statements can be added,
|
||||
# unioned and an explicit Deny still wins. mgmt received this same
|
||||
# restructure in Phase B (.github PR #98), so this is no longer a
|
||||
# divergence,
|
||||
# - SECURITY FIX (now in BOTH copies): iam:DeleteRolePermissionsBoundary
|
||||
# removed from Sid IAMPutPermissionsBoundary and explicit Deny statements
|
||||
# (DenyBoundaryTampering / DenyBoundaryPolicyEdit / DenySelfMutation)
|
||||
# added. The mgmt copy was remediated 2026-07-27 (.github PRs #95 Phase A
|
||||
# + #98 Phase B); DenySelfMutation and the widened policy/seahaven-*
|
||||
# DenyBoundaryPolicyEdit scope were then ported back here, so the two
|
||||
# copies' statement sets are reconciled as of that date. If a substrate
|
||||
# statement changes again, change BOTH files in the same piece of work.
|
||||
# copies' statement sets are reconciled as of that date — every IAM
|
||||
# statement in LambdaExecutionBoundary, SamCfnIamManagementPolicy and
|
||||
# SamCfnExecutionRole is byte-identical across the two files; the only
|
||||
# remaining delta is the DependsOn line above, which is ordering, not
|
||||
# permission. If a substrate statement changes again, change BOTH files
|
||||
# in the same piece of work.
|
||||
#
|
||||
# This template is deployed via lib/deploy-substrate-stack.ts
|
||||
# (cloudformation-include) as stack seahaven-deploy-substrate, once per
|
||||
|
|
@ -525,6 +530,12 @@ Resources:
|
|||
- logs:DescribeDestinations
|
||||
- logs:AssociateKmsKey
|
||||
- logs:DisassociateKmsKey
|
||||
# Ported from the mgmt copy (Phase A): afterhours-shift-manager
|
||||
# creates an AWS::Logs::MetricFilter through this role, so a
|
||||
# SAM stack migrating here fails mid-deploy without these.
|
||||
- logs:PutMetricFilter
|
||||
- logs:DeleteMetricFilter
|
||||
- logs:DescribeMetricFilters
|
||||
Resource: "*"
|
||||
|
||||
# ── EventBridge / CloudWatch Events (scheduled Lambdas) ───────────
|
||||
|
|
|
|||
Loading…
Add table
Reference in a new issue