docs(iam): cite INFRA-187 as the per-workload boundary end state

Replaces the placeholder 'tracked as its own ticket' references with the real
key, and records the load-bearing constraint inline so the next reader does not
rediscover it: both guardrail policies pin ONE literal boundary ARN inside
StringEquals iam:PermissionsBoundary, and loosening that to a wildcard weakens
the gate rather than merely relaxing it.
This commit is contained in:
Adam Moussa 2026-07-30 19:09:27 -04:00
parent 32f06e74eb
commit e791005af0
No known key found for this signature in database

View file

@ -132,7 +132,7 @@ Description: >-
# the boundary itself) removed that pressure entirely. If the budget tightens
# again as workloads land, the end-state fix is per-workload boundaries
# (seahaven-lambda-execution-boundary-<workload>), which also resolves the
# shared-ceiling residual — tracked as its own ticket, do not improvise it.
# shared-ceiling residual — tracked as INFRA-187, do not improvise it.
# CRITICAL: unlike the 2026-07-27 inline-limit incident,
# there is NO restructure available when this cap is reached — a role has exactly
# ONE permissions boundary, so statements cannot be spilled into a second attached
@ -498,7 +498,10 @@ Resources:
#
# The end-state fix for the shared-ceiling residual (one boundary =
# every SAM workload reaches every other's data plane once they land)
# is per-workload boundaries — tracked separately, see the header.
# is per-workload boundaries — tracked as INFRA-187. Do not improvise
# it: the load-bearing problem there is that both guardrail policies
# pin ONE literal boundary ARN inside StringEquals conditions, and
# loosening that to a wildcard weakens the gate.
# ---------------------------------------------------------------------------
# Shared CloudFormation execution role (SAM stacks) — INFRA-97 scoped
#