diff --git a/lib/deploy-substrate/deploy-substrate.template.yaml b/lib/deploy-substrate/deploy-substrate.template.yaml index 29f48d2..ce16245 100644 --- a/lib/deploy-substrate/deploy-substrate.template.yaml +++ b/lib/deploy-substrate/deploy-substrate.template.yaml @@ -30,16 +30,21 @@ Description: >- # first deploy failed with ServiceLimitExceeded (2026-07-27). Effective # permissions are unchanged — verified by comparing the full 27-statement # set before and after the move (identical), since identity policies are -# unioned and an explicit Deny still wins. NOTE for the mgmt remediation: -# mgmt needs this same restructure before its Deny statements can be added, +# unioned and an explicit Deny still wins. mgmt received this same +# restructure in Phase B (.github PR #98), so this is no longer a +# divergence, # - SECURITY FIX (now in BOTH copies): iam:DeleteRolePermissionsBoundary # removed from Sid IAMPutPermissionsBoundary and explicit Deny statements # (DenyBoundaryTampering / DenyBoundaryPolicyEdit / DenySelfMutation) # added. The mgmt copy was remediated 2026-07-27 (.github PRs #95 Phase A # + #98 Phase B); DenySelfMutation and the widened policy/seahaven-* # DenyBoundaryPolicyEdit scope were then ported back here, so the two -# copies' statement sets are reconciled as of that date. If a substrate -# statement changes again, change BOTH files in the same piece of work. +# copies' statement sets are reconciled as of that date — every IAM +# statement in LambdaExecutionBoundary, SamCfnIamManagementPolicy and +# SamCfnExecutionRole is byte-identical across the two files; the only +# remaining delta is the DependsOn line above, which is ordering, not +# permission. If a substrate statement changes again, change BOTH files +# in the same piece of work. # # This template is deployed via lib/deploy-substrate-stack.ts # (cloudformation-include) as stack seahaven-deploy-substrate, once per @@ -525,6 +530,12 @@ Resources: - logs:DescribeDestinations - logs:AssociateKmsKey - logs:DisassociateKmsKey + # Ported from the mgmt copy (Phase A): afterhours-shift-manager + # creates an AWS::Logs::MetricFilter through this role, so a + # SAM stack migrating here fails mid-deploy without these. + - logs:PutMetricFilter + - logs:DeleteMetricFilter + - logs:DescribeMetricFilters Resource: "*" # ── EventBridge / CloudWatch Events (scheduled Lambdas) ───────────