Adam Moussa
a81acbf18d
Merge pull request #105 from Sea-Haven-Industries/chore/strip-pascalcase-wo-iam-pins
...
Deploy / deploy-management (push) Waiting to run
Deploy / deploy-external-dev (push) Waiting to run
Deploy / deploy-security (push) Waiting to run
Deploy / deploy-dev (push) Waiting to run
Deploy / deploy-prod (push) Waiting to run
chore(iam): drop PascalCase WO Dynamo and alarm ARNs (PLAT-11)
2026-08-14 12:12:48 -04:00
5fa4267798
chore(iam): drop PascalCase WO Dynamo and alarm ARNs
2026-08-14 11:58:41 -04:00
Adam Moussa
a2e9449ef1
Merge pull request #104 from Sea-Haven-Industries/feature/per-workload-lambda-boundaries
...
Deploy / deploy-management (push) Waiting to run
Deploy / deploy-external-dev (push) Waiting to run
Deploy / deploy-security (push) Waiting to run
Deploy / deploy-dev (push) Waiting to run
Deploy / deploy-prod (push) Waiting to run
feat(iam): add per-workload lambda execution boundaries (PLAT-52)
2026-08-13 17:51:53 -04:00
0f84d7808b
feat(iam): add per-workload lambda execution boundaries
...
Shared seahaven-lambda-execution-boundary stays unchanged for live roles.
New named policies plus an enumerated StringEquals allow-list unblock the
next PLAT-71 widen without growing the 6144-character shared document.
2026-08-13 16:47:53 -04:00
Adam Moussa
ef1afab33b
Merge pull request #103 from Sea-Haven-Industries/fix/meal-order-weekly-menu-execute-api
...
Deploy / deploy-management (push) Has been cancelled
Deploy / deploy-external-dev (push) Has been cancelled
Deploy / deploy-security (push) Has been cancelled
Deploy / deploy-dev (push) Has been cancelled
Deploy / deploy-prod (push) Has been cancelled
fix(iam): meal-order weekly-menu execute-api boundary (PLAT-100)
2026-08-10 16:05:18 -04:00
81cc8eb4f9
fix(iam): consolidate meal-order boundary Sid under PolicySize cap
2026-08-10 15:57:08 -04:00
7c43c867e3
fix(iam): allow execute-api Invoke for meal-order weekly-menu boundary
2026-08-10 15:42:12 -04:00
Adam Moussa
7ad46d9528
Merge pull request #102 from Sea-Haven-Industries/fix/meal-order-log-delivery
...
Deploy / deploy-management (push) Waiting to run
Deploy / deploy-external-dev (push) Waiting to run
Deploy / deploy-security (push) Waiting to run
Deploy / deploy-dev (push) Waiting to run
Deploy / deploy-prod (push) Waiting to run
fix(iam): allow API GW Log Delivery on meal-order apply role (PLAT-99)
2026-08-10 15:27:34 -04:00
b76d0578e0
fix(iam): drop PutResourcePolicy from meal-order apply role
...
Pre-grant delivery.logs write via MealOrderApiAccessLogResourcePolicy on
substrate so the HCP apply role cannot mutate account-wide log resource
policies.
2026-08-10 14:57:17 -04:00
e10462d25e
fix(iam): allow API GW Log Delivery on meal-order apply role
2026-08-10 14:47:30 -04:00
Adam Moussa
84aa1a803e
Merge pull request #101 from Sea-Haven-Industries/fix/meal-order-passrole-apigateway
...
Deploy / deploy-management (push) Waiting to run
Deploy / deploy-external-dev (push) Waiting to run
Deploy / deploy-security (push) Waiting to run
Deploy / deploy-dev (push) Waiting to run
Deploy / deploy-prod (push) Waiting to run
fix(iam): allow PassRole to apigateway for meal-order authorizer (PLAT-97)
2026-08-10 14:05:35 -04:00
6bb2d54814
fix(iam): allow PassRole to apigateway for meal-order authorizer
2026-08-10 13:46:12 -04:00
Adam Moussa
35c1b96257
Merge pull request #100 from Sea-Haven-Industries/fix/meal-order-ssm-list-tags
...
fix(iam): allow ssm:ListTagsForResource on meal-order plan role (PLAT-96)
2026-08-10 13:30:58 -04:00
1bb5e79ea0
fix(iam): allow ssm:ListTagsForResource on meal-order plan role
2026-08-10 13:23:56 -04:00
Adam Moussa
f44b88732e
fix(iam): allow ssm:DescribeParameters for meal-order hcptf roles ( #99 )
Deploy / deploy-management (push) Has been cancelled
Deploy / deploy-external-dev (push) Has been cancelled
Deploy / deploy-security (push) Has been cancelled
Deploy / deploy-dev (push) Has been cancelled
Deploy / deploy-prod (push) Has been cancelled
2026-08-08 00:11:48 +00:00
Adam Moussa
3605215a28
refactor(iam): consolidate boundary statements under PolicySize cap ( #98 )
...
Deploy / deploy-management (push) Waiting to run
Deploy / deploy-external-dev (push) Waiting to run
Deploy / deploy-security (push) Waiting to run
Deploy / deploy-dev (push) Waiting to run
Deploy / deploy-prod (push) Waiting to run
Merge workload secret/DDB/S3 SIDs and trim meal-order extras so the
shared lambda execution boundary fits under the 6144-character limit.
2026-08-07 23:54:28 +00:00
Adam Moussa
44b672ae9a
feat(iam): add hcptf roles and boundary widen for meal-order-manager (PLAT-70) ( #97 )
...
* feat(iam): add hcptf roles and boundary widen for meal-order-manager
Append plan/apply OIDC roles for meal-order-manager-prod and widen the lambda execution boundary with exact prod secret ARN and data-plane statements.
* fix(iam): make meal-order plan role Lambda refresh read-only
Replace plan-role lambda:* with Get*/List* so plan-phase credentials cannot mutate functions or layers.
2026-08-07 19:36:20 -04:00
Adam Moussa
a6f22880db
feat(waf): add seahaven-prod shared CloudFront WebACL (PLAT-92) ( #96 )
...
Deploy / deploy-management (push) Waiting to run
Deploy / deploy-external-dev (push) Waiting to run
Deploy / deploy-security (push) Waiting to run
Deploy / deploy-dev (push) Waiting to run
Deploy / deploy-prod (push) Waiting to run
* feat(waf): add seahaven-prod shared CloudFront WebACL stack
Stand up AppWebAcl in a thin prod stack and widen seahaven-site HCP
roles to read the SSM ARN so CloudFront can associate the ACL in-account.
* fix(deploy): add app-web-acl-prod to deploy.yaml
2026-08-07 17:07:04 -04:00
dependabot[bot]
2789f3cbcf
chore(deps): bump callable-dependency-review.yaml ( #94 )
...
Deploy / deploy-management (push) Waiting to run
Deploy / deploy-external-dev (push) Waiting to run
Deploy / deploy-security (push) Waiting to run
Deploy / deploy-dev (push) Waiting to run
Deploy / deploy-prod (push) Waiting to run
Bumps [Sea-Haven-Industries/.github/.github/workflows/callable-dependency-review.yaml](https://github.com/sea-haven-industries/.github ) from 1.0.3 to 1.0.6.
- [Release notes](https://github.com/sea-haven-industries/.github/releases )
- [Commits](3f74677422...7ac3528750 )
---
updated-dependencies:
- dependency-name: Sea-Haven-Industries/.github/.github/workflows/callable-dependency-review.yaml
dependency-version: 1.0.6
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-08-07 15:36:05 -04:00
dependabot[bot]
2ee38a9dd5
chore(deps): bump callable-labeler.yaml ( #93 )
...
Bumps [Sea-Haven-Industries/.github/.github/workflows/callable-labeler.yaml](https://github.com/sea-haven-industries/.github ) from 1.0.3 to 1.0.6.
- [Release notes](https://github.com/sea-haven-industries/.github/releases )
- [Commits](3f74677422...7ac3528750 )
---
updated-dependencies:
- dependency-name: Sea-Haven-Industries/.github/.github/workflows/callable-labeler.yaml
dependency-version: 1.0.6
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-08-07 19:33:26 +00:00
dependabot[bot]
775f9a5809
chore(deps): bump Sea-Haven-Industries/.github/.github/workflows/ci-typescript-cdk.yaml ( #92 )
...
Bumps [Sea-Haven-Industries/.github/.github/workflows/ci-typescript-cdk.yaml](https://github.com/sea-haven-industries/.github ) from 1.0.3 to 1.0.6.
- [Release notes](https://github.com/sea-haven-industries/.github/releases )
- [Commits](3f74677422...7ac3528750 )
---
updated-dependencies:
- dependency-name: Sea-Haven-Industries/.github/.github/workflows/ci-typescript-cdk.yaml
dependency-version: 1.0.6
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-08-07 19:29:12 +00:00
dependabot[bot]
06c8dfccbc
chore(deps): bump cd-cdk.yaml ( #91 )
...
Bumps [Sea-Haven-Industries/.github/.github/workflows/cd-cdk.yaml](https://github.com/sea-haven-industries/.github ) from 1.0.3 to 1.0.6.
- [Release notes](https://github.com/sea-haven-industries/.github/releases )
- [Commits](3f74677422...7ac3528750 )
---
updated-dependencies:
- dependency-name: Sea-Haven-Industries/.github/.github/workflows/cd-cdk.yaml
dependency-version: 1.0.6
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-08-07 19:26:26 +00:00
Adam Moussa
35461d9267
feat(iam): add hcptf-seahaven-site plan/apply roles (PLAT-91) ( #89 )
...
Deploy / deploy-management (push) Waiting to run
Deploy / deploy-external-dev (push) Waiting to run
Deploy / deploy-security (push) Waiting to run
Deploy / deploy-dev (push) Waiting to run
Deploy / deploy-prod (push) Waiting to run
* feat(iam): add hcptf-seahaven-site plan/apply roles
Static-site HCP substrate for seahaven-site-prod plus boundary widen for
the TF-managed content-deploy role (S3 origin + CloudFront invalidate).
* fix(iam): allow seahaven-site HCP roles to read GitHub OIDC provider
Plan refresh needs iam:GetOpenIDConnectProvider for the content-deploy
role trust data source (PLAT-91 first-plan AccessDenied).
2026-08-07 15:09:57 -04:00
Adam Moussa
e12944a42d
fix(iam): allow kebab WO tables on lambda execution boundary ( #90 )
...
Widen ProcurementIngestDynamoDB so workorder Lambdas can read/write
work-orders and work-order-comments after the PLAT-11 rename.
2026-08-07 14:20:40 -04:00
Adam Moussa
ff77ffd421
fix(iam): allow HCP procurement-ingest kebab WO Dynamo tables ( #88 )
...
Deploy / deploy-management (push) Waiting to run
Deploy / deploy-external-dev (push) Waiting to run
Deploy / deploy-security (push) Waiting to run
Deploy / deploy-dev (push) Waiting to run
Deploy / deploy-prod (push) Waiting to run
Widen hcptf-procurement-ingest apply and plan-refresh DynamoDB/CloudWatch
ARN pins for work-orders and work-order-comments (PLAT-11 rename).
2026-08-07 13:53:42 -04:00
Adam Moussa
eb2fcfd40b
Merge pull request #87 from Sea-Haven-Industries/fix/hcptf-procurement-ingest-tagging
...
Deploy / deploy-management (push) Waiting to run
Deploy / deploy-external-dev (push) Waiting to run
Deploy / deploy-security (push) Waiting to run
Deploy / deploy-dev (push) Waiting to run
Deploy / deploy-prod (push) Waiting to run
fix(iam): allow API GW and ESM tagging for procurement-ingest (PLAT-86)
2026-08-07 11:09:25 -04:00
202103041c
fix(iam): allow API GW and ESM tagging for procurement-ingest
...
Provider default_tags need apigateway /tags/* and unconditioned ESM
TagResource after import-in-place.
2026-08-07 11:09:06 -04:00
Adam Moussa
33a1ab9ba6
Merge pull request #86 from Sea-Haven-Industries/fix/hcptf-procurement-ingest-plan-refresh
...
fix(iam): widen procurement-ingest plan refresh for import (PLAT-86)
2026-08-07 11:01:12 -04:00
a5997f878b
fix(iam): widen procurement-ingest plan refresh for import
...
Add GetEventSourceMapping, SSM GetParameter pins, and Resource "*" for
kms:ListAliases so the first HCP import plan can refresh.
2026-08-07 11:00:49 -04:00
Adam Moussa
a5fa0b16a3
feat(iam): add hcptf roles and boundary for procurement-ingest (PLAT-86) ( #85 )
...
* feat(iam): add hcptf roles and boundary for procurement-ingest
* fix(iam): tighten procurement-ingest apply and plan scopes
Replace kms:* and secret-value writes on shell statements; split IAM
collection APIs onto Resource "*".
2026-08-07 10:41:12 -04:00
Adam Moussa
dd45c1ca07
ci(policy): bump callable-pr-policy pin to v1.0.6 ( #83 )
Deploy / deploy-management (push) Has been cancelled
Deploy / deploy-external-dev (push) Has been cancelled
Deploy / deploy-security (push) Has been cancelled
Deploy / deploy-dev (push) Has been cancelled
Deploy / deploy-prod (push) Has been cancelled
2026-08-05 19:24:38 -04:00
Adam Moussa
69f31842cb
feat(iam): add hcptf roles for sh-openswe-traces-prod (PLAT-73) ( #80 )
...
Deploy / deploy-management (push) Waiting to run
Deploy / deploy-external-dev (push) Waiting to run
Deploy / deploy-security (push) Waiting to run
Deploy / deploy-dev (push) Waiting to run
Deploy / deploy-prod (push) Waiting to run
* feat(iam): add hcptf roles for sh-openswe-traces-prod
Storage/IAM-user apply and plan roles for the HCP workspace. No Lambda
boundary widen; explicit IAM user CRUD because hcptf-iam-management is
role-path-only.
* fix(iam): pin CreateSecret to exact export secret name
Remove CreateSecret and UpdateSecret from the ARN-prefix shell grant so
apply cannot create longer-named secrets or overwrite SecretString.
2026-08-05 22:46:32 +00:00
Adam Moussa
fc64b03e3d
feat(iam): hcptf front-integrations roles and boundary (PLAT-72) ( #81 )
...
* feat(iam): add hcptf front-integrations roles and boundary widen
Add plan/apply OIDC roles for front-integrations-prod and widen the
Lambda execution boundary with exact prod secret ARNs plus DynamoDB
CRUD on front-sla-alerts.
* fix(iam): restrict front-integrations plan role to lambda Get/List
Keep mutate APIs on the apply role so a compromised plan-phase
OIDC session cannot update or delete front-* functions.
2026-08-05 18:33:31 -04:00
Adam Moussa
9ee4d4a3d7
docs(iam): codify hcp terraform migration checklist from PLAT-56 ( #79 )
...
Deploy / deploy-management (push) Waiting to run
Deploy / deploy-external-dev (push) Waiting to run
Deploy / deploy-security (push) Waiting to run
Deploy / deploy-dev (push) Waiting to run
Deploy / deploy-prod (push) Waiting to run
Expand the README playbook to steps 0–10 and document the required
plan-refresh sidecar plus prefix-scoped apply-role wildcards so the
next workload copies afi patterns instead of relearning first-apply misses.
2026-08-05 16:14:16 -04:00
Adam Moussa
2c5c644a5e
Merge pull request #78 from Sea-Haven-Industries/fix/hcptf-afi-provider-read-actions
...
Deploy / deploy-management (push) Waiting to run
Deploy / deploy-external-dev (push) Waiting to run
Deploy / deploy-security (push) Waiting to run
Deploy / deploy-dev (push) Waiting to run
Deploy / deploy-prod (push) Waiting to run
fix(iam): use lambda:* and events:* on afi hcptf apply scope (PLAT-56)
2026-08-05 12:59:34 -04:00
46829fc2c1
fix(iam): use lambda:* and events:* on afi hcptf apply scope
...
Provider refresh needs GetFunctionCodeSigningConfig and similar reads;
keep blast radius on afi-* function/layer/rule ARNs only.
2026-08-05 12:59:19 -04:00
Adam Moussa
991cff8333
Merge pull request #77 from Sea-Haven-Industries/fix/hcptf-afi-s3-bucket-acl
...
fix(iam): afi hcptf plan refresh and artifact s3:* (PLAT-56)
2026-08-05 12:57:39 -04:00
f4292832fe
fix(iam): add plan-role refresh reads for afi terraform state
...
ViewOnlyAccess omits iam:GetRole and events:DescribeRule; without a
scoped refresh policy, HCP plans fail after the first partial apply.
2026-08-05 12:57:23 -04:00
3512214d14
fix(iam): allow s3:* on afi artifact bucket for provider reads
...
First HCP apply failed on s3:GetBucketAcl after CreateBucket; scope
remains the single artifact bucket ARN.
2026-08-05 12:56:24 -04:00
Adam Moussa
4e1cf4c0bd
feat(iam): add hcptf roles/boundary widen - afi-backup-monitor (PLAT-56) ( #76 )
...
* feat(iam): add hcptf roles and boundary widen for afi-backup-monitor
Provision plan/apply OIDC roles for workspace afi-backup-monitor-prod
and widen the prod Lambda boundary with the two exact secret ARNs.
* fix(iam): split DescribeLogGroups and allow afi artifact bucket
logs:DescribeLogGroups cannot be resource-scoped; grant it on *. Add
S3 permissions for the HCP Lambda artifact bucket used by PLAT-56.
2026-08-05 12:44:52 -04:00
Adam Moussa
517f41eb7f
ci: add org PR policy caller ( #74 )
...
Deploy / deploy-management (push) Waiting to run
Deploy / deploy-external-dev (push) Waiting to run
Deploy / deploy-security (push) Waiting to run
Deploy / deploy-dev (push) Waiting to run
Deploy / deploy-prod (push) Waiting to run
Refs: PLAT-62
2026-08-04 11:56:30 -04:00
Adam Moussa
c09cf1110d
fix(iam): allow API Gateway authorizer role passing
Deploy / deploy-management (push) Waiting to run
Deploy / deploy-external-dev (push) Waiting to run
Deploy / deploy-security (push) Waiting to run
Deploy / deploy-dev (push) Waiting to run
Deploy / deploy-prod (push) Waiting to run
2026-08-03 14:38:39 -04:00
dependabot[bot]
5d0e8480d4
build(deps): bump Sea-Haven-Industries/.github/.github/workflows/cd-cdk.yaml ( #69 )
...
Deploy / deploy-management (push) Has been cancelled
Deploy / deploy-external-dev (push) Has been cancelled
Deploy / deploy-security (push) Has been cancelled
Deploy / deploy-dev (push) Has been cancelled
Deploy / deploy-prod (push) Has been cancelled
Bumps [Sea-Haven-Industries/.github/.github/workflows/cd-cdk.yaml](https://github.com/sea-haven-industries/.github ) from 1.0.2 to 1.0.3.
- [Release notes](https://github.com/sea-haven-industries/.github/releases )
- [Commits](0170a57c0d...3f74677422 )
---
updated-dependencies:
- dependency-name: Sea-Haven-Industries/.github/.github/workflows/cd-cdk.yaml
dependency-version: 1.0.3
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-08-02 00:18:43 +00:00
dependabot[bot]
c73680207a
build(deps): bump Sea-Haven-Industries/.github/.github/workflows/ci-typescript-cdk.yaml ( #70 )
...
Bumps [Sea-Haven-Industries/.github/.github/workflows/ci-typescript-cdk.yaml](https://github.com/sea-haven-industries/.github ) from 1.0.2 to 1.0.3.
- [Release notes](https://github.com/sea-haven-industries/.github/releases )
- [Commits](0170a57c0d...3f74677422 )
---
updated-dependencies:
- dependency-name: Sea-Haven-Industries/.github/.github/workflows/ci-typescript-cdk.yaml
dependency-version: 1.0.3
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-08-01 20:17:55 -04:00
dependabot[bot]
8b5414f879
build(deps): bump Sea-Haven-Industries/.github/.github/workflows/callable-labeler.yaml ( #71 )
...
Deploy / deploy-management (push) Waiting to run
Deploy / deploy-external-dev (push) Waiting to run
Deploy / deploy-security (push) Waiting to run
Deploy / deploy-dev (push) Waiting to run
Deploy / deploy-prod (push) Waiting to run
Bumps [Sea-Haven-Industries/.github/.github/workflows/callable-labeler.yaml](https://github.com/sea-haven-industries/.github ) from 1.0.2 to 1.0.3.
- [Release notes](https://github.com/sea-haven-industries/.github/releases )
- [Commits](0170a57c0d...3f74677422 )
---
updated-dependencies:
- dependency-name: Sea-Haven-Industries/.github/.github/workflows/callable-labeler.yaml
dependency-version: 1.0.3
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-31 20:49:28 -04:00
dependabot[bot]
3b54a64e52
build(deps): bump Sea-Haven-Industries/.github/.github/workflows/callable-dependency-review.yaml ( #72 )
...
Deploy / deploy-management (push) Waiting to run
Deploy / deploy-external-dev (push) Waiting to run
Deploy / deploy-security (push) Waiting to run
Deploy / deploy-dev (push) Waiting to run
Deploy / deploy-prod (push) Waiting to run
Bumps [Sea-Haven-Industries/.github/.github/workflows/callable-dependency-review.yaml](https://github.com/sea-haven-industries/.github ) from 1.0.2 to 1.0.3.
- [Release notes](https://github.com/sea-haven-industries/.github/releases )
- [Commits](0170a57c0d...3f74677422 )
---
updated-dependencies:
- dependency-name: Sea-Haven-Industries/.github/.github/workflows/callable-dependency-review.yaml
dependency-version: 1.0.3
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-31 19:44:45 -04:00
Adam Moussa
9faf0295d5
Merge pull request #68 from Sea-Haven-Industries/feature/INFRA-186-boundary-prod-dev-scoping
...
Deploy / deploy-management (push) Waiting to run
Deploy / deploy-external-dev (push) Waiting to run
Deploy / deploy-security (push) Waiting to run
Deploy / deploy-dev (push) Waiting to run
Deploy / deploy-prod (push) Waiting to run
refactor(iam): reduce prod/dev Lambda execution boundary to a fleet-wide floor (INFRA-186)
2026-07-31 13:49:55 -04:00
16a82c2a36
docs(iam): qualify mgmt-only verification claims per cross-review round 2
2026-07-31 13:46:29 -04:00
08a1d41b05
docs(iam): resolve confirmed review findings from both INFRA-186 gates
...
Cross-family round 1 plus the /sh-security-review verifier confirmed 11
findings on the floor reduction, all documentation defects; no policy
statement changes. The one HIGH: the Terraform migration checklist never
widened the boundary, so a Lambda-bearing Terraform migration would deploy
green and lose every data-plane call at first invoke. Checklist step 2 now
carries the widening requirement, step 3 verifies deployed boundary content,
and the terraform-substrate header no longer reads as 'Terraform path
unaffected'. Also corrected: Description is a REPLACEMENT property (a
Description edit wedges the custom-named policy and CFN's remedy is the
forbidden rename), the sanctioned-source contradiction, the false
AWSLambdaVPCAccessExecutionRole parity claim, the KMS log-group category
error, stale size numbers (691/5,453), the same-PR widening contradiction,
per-workload residue text, a LoggingConfig silent-log-loss note, the
us-east-1 region pin rationale, and ENI DoS deferral now tracked as
INFRA-200.
2026-07-31 13:44:21 -04:00
a1086e04fb
docs(readme): describe the boundary floor, not the superseded prefix design
2026-07-31 13:23:20 -04:00