Commit graph

3 commits

Author SHA1 Message Date
Cursor Agent
e3adfc3cdc
feat(scp): deny iam changes on role/platform unless the platform principal (PLAT-233)
Adds ProtectPlatformPath beside the existing name denies in the
prod/nonprod SCP and the security OU copy. New hcptf-bootstrap
creates use /platform/. Existing roles are not recreated.

Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com>
2026-09-28 00:49:48 +00:00
Adam Moussa
4f0d84cddb
fix(iam): use unique HCP bootstrap workspace names (PLAT-143) (#138)
Some checks are pending
Deploy / deploy-management (push) Waiting to run
Deploy / deploy-external-dev (push) Waiting to run
Deploy / deploy-security (push) Waiting to run
Deploy / deploy-dev (push) Waiting to run
Deploy / deploy-prod (push) Waiting to run
HCP workspace names are org-unique, so prod and dev cannot both be iam-bootstrap. Pin trust to iam-bootstrap-prod and iam-bootstrap-dev.
2026-09-02 15:51:39 +00:00
Adam Moussa
b02f52b805
feat(iam): lock app-owned HCP IAM and add bootstrap SCP (PLAT-143) (#137)
* feat(iam): lock app-owned HCP IAM and add bootstrap SCP (PLAT-143)

* fix(iam): pin HCP boundary ARNs and bootstrap trust window (PLAT-143)

Null on iam:PermissionsBoundary accepted any ceiling, including AdministratorAccess. Import apply cannot self-mutate hcptf-* while bootstrap trust is iam-bootstrap only; add a time-boxed exact StringEquals workspace grant instead of StringLike.
2026-09-02 15:22:48 +00:00