mirror of
https://github.com/Sea-Haven-Industries/seahaven-org-baseline.git
synced 2026-10-02 09:43:21 +00:00
The seahaven-cfn-exec-iam-management policy in prod and dev carried only DenyBoundaryTampering + DenyBoundaryPolicyEdit: the mgmt Phase A review later showed a Deny-in-a-managed-policy control is self-detachable (iam:DetachRolePolicy on * is unconditioned), so without DenySelfMutation the exec role can detach the very policy carrying the Denies and reinstate the boundary-removal escalation. Latent today (no PassRole grants, zero SAM stacks in prod/dev) but must be closed before the first SAM workload migrates. Ports verbatim from .github/oidc-deploy-roles.yaml (mgmt, PRs #95/#98): - DenySelfMutation over role/github-cfn-execution-role + githubdeploy-* - DenyBoundaryPolicyEdit widened to policy/seahaven-* Statement set verified byte-identical to the mgmt copy (9 sids); provenance header updated - the two copies are reconciled. |
||
|---|---|---|
| .. | ||
| deploy-substrate | ||
| scp | ||
| account-baseline-stack.ts | ||
| alarm-topic-stack.ts | ||
| backup-offsite-stack.ts | ||
| backup-stack.ts | ||
| bedrock-logging-regional.ts | ||
| bedrock-logging.ts | ||
| cis-monitoring.ts | ||
| deploy-substrate-stack.ts | ||
| detective-controls.ts | ||
| dynamodb-cmk-stack.ts | ||
| flow-logs.ts | ||
| governance-toggles.ts | ||
| logs-key.ts | ||
| member-baseline-stack.ts | ||
| org-governance-stack.ts | ||
| regional-baseline-stack.ts | ||
| ses-monitoring.ts | ||
| web-acl.ts | ||