diff --git a/lib/deploy-substrate/deploy-substrate.template.yaml b/lib/deploy-substrate/deploy-substrate.template.yaml index 301af15..aa91a40 100644 --- a/lib/deploy-substrate/deploy-substrate.template.yaml +++ b/lib/deploy-substrate/deploy-substrate.template.yaml @@ -1243,3 +1243,16 @@ Resources: StringEquals: "iam:PassedToService": "lambda.amazonaws.com" + # API Gateway assumes SAM authorizer invocation roles. Keep this + # separate from Lambda PassRole so each target service and role + # pattern remains independently constrained. + - Sid: IAMPassAuthorizerRole + Effect: Allow + Action: + - iam:PassRole + Resource: + - !Sub "arn:aws:iam::${AWS::AccountId}:role/cfn-managed/*AuthorizerInvokeRole-*" + Condition: + StringEquals: + "iam:PassedToService": "apigateway.amazonaws.com" +