seahaven-org-baseline/lib/deploy-substrate
Adam Moussa 62f6a76e6c
fix(iam): port DenySelfMutation self-protection into the prod/dev deploy substrate
The seahaven-cfn-exec-iam-management policy in prod and dev carried only
DenyBoundaryTampering + DenyBoundaryPolicyEdit: the mgmt Phase A review
later showed a Deny-in-a-managed-policy control is self-detachable
(iam:DetachRolePolicy on * is unconditioned), so without DenySelfMutation
the exec role can detach the very policy carrying the Denies and
reinstate the boundary-removal escalation. Latent today (no PassRole
grants, zero SAM stacks in prod/dev) but must be closed before the first
SAM workload migrates.

Ports verbatim from .github/oidc-deploy-roles.yaml (mgmt, PRs #95/#98):
- DenySelfMutation over role/github-cfn-execution-role + githubdeploy-*
- DenyBoundaryPolicyEdit widened to policy/seahaven-*

Statement set verified byte-identical to the mgmt copy (9 sids);
provenance header updated - the two copies are reconciled.
2026-07-27 18:37:39 -04:00
..
deploy-substrate.template.yaml fix(iam): port DenySelfMutation self-protection into the prod/dev deploy substrate 2026-07-27 18:37:39 -04:00