seahaven-org-baseline/lib/deploy-substrate
Adam Moussa 055feca605
fix(iam): shrink shared lambda boundary to the four-statement floor (PLAT-52) (#158)
* fix(iam): shrink shared lambda boundary to the four-statement floor (PLAT-52)

PermissionsBoundaryUsageCount is 0 in prod and dev, so the shared
seahaven-lambda-execution-boundary drops the packed IsProdAccount
data-plane statements and keeps CloudWatchLogsWrite,
CloudWatchLogsDescribe, XRay, and Ec2Eni.

Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com>

* docs(iam): correct shared boundary size and scoping notes (PLAT-52)

The dev floor is the same 708-character document as the shared policy.
691 was stale. The scoping note now says the shared document is the
four-statement floor, and allow-list retirement is a follow-up.

Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com>

* docs(iam): limit scoping rule to remaining SAM workloads (PLAT-52)

The shared boundary shrink is unchanged. The scoping note now matches
the HCP path already stated later in the same file.

Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com>

* docs(iam): record the shared floor size as 691 characters (PLAT-52)

The stated measurement, with the account id resolved, is 691 characters
and 4 statements for the shared boundary and for the dev floor copies.
Headroom is 5453.

Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com>

---------

Co-authored-by: Cursor Agent <cursoragent@cursor.com>
Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com>
2026-09-28 13:46:18 -04:00
..
deploy-substrate.template.yaml fix(iam): shrink shared lambda boundary to the four-statement floor (PLAT-52) (#158) 2026-09-28 13:46:18 -04:00