mirror of
https://github.com/Sea-Haven-Industries/seahaven-org-baseline.git
synced 2026-10-01 15:33:18 +00:00
The seahaven-cfn-exec-iam-management policy in prod and dev carried only DenyBoundaryTampering + DenyBoundaryPolicyEdit: the mgmt Phase A review later showed a Deny-in-a-managed-policy control is self-detachable (iam:DetachRolePolicy on * is unconditioned), so without DenySelfMutation the exec role can detach the very policy carrying the Denies and reinstate the boundary-removal escalation. Latent today (no PassRole grants, zero SAM stacks in prod/dev) but must be closed before the first SAM workload migrates. Ports verbatim from .github/oidc-deploy-roles.yaml (mgmt, PRs #95/#98): - DenySelfMutation over role/github-cfn-execution-role + githubdeploy-* - DenyBoundaryPolicyEdit widened to policy/seahaven-* Statement set verified byte-identical to the mgmt copy (9 sids); provenance header updated - the two copies are reconciled. |
||
|---|---|---|
| .. | ||
| deploy-substrate.template.yaml | ||