mirror of
https://github.com/Sea-Haven-Industries/seahaven-org-baseline.git
synced 2026-09-30 08:03:19 +00:00
The first deploy of seahaven-deploy-substrate failed in both prod and dev with ServiceLimitExceeded: 'Maximum policy size of 10240 bytes exceeded for role github-cfn-execution-role'. The role's inline policies already sat ~94 bytes under IAM's hard 10,240-byte per-role limit, so the two Deny statements added to close the boundary-removal escalation did not fit (10,656 total). Moves the whole boundary-gated IAM block (6 Allow + 2 Deny statements) into an attached managed policy, which carries its own separate 6,144-byte budget. Inline drops to 8,285 with ~1.9 KB of headroom; the managed policy sits at 2,371. Effective permissions are unchanged: the union of role statements (inline + attached) is byte-identical as a sorted set before and after the move (27 statements both sides), identity policies are unioned, and an explicit Deny still wins. Boundary and trust policy untouched. Both failed stacks rolled back cleanly with zero orphaned resources and were deleted before this retry. |
||
|---|---|---|
| .. | ||
| deploy-substrate.template.yaml | ||