mirror of
https://github.com/Sea-Haven-Industries/seahaven-org-baseline.git
synced 2026-10-02 17:53:24 +00:00
Security review (6 detectors + proof-or-kill verifier) confirmed 1 critical and 1 high in the first revision, both inherited by mirroring the SAM copy's Resource "*" role grants: - C1 (critical): iam:UpdateAssumeRolePolicy on "*" with DenySelfMutation covering only three name patterns lets the principal repoint the AdministratorAccess CDK bootstrap role's trust policy to an external account. - C2 (high): the SAM justification for role/* (SAM auto-roles land at path / with no settable RolePath) does not transfer -- Terraform's aws_iam_role supports path. Fixes, closing the class at the root rather than by denylist: - All role writes, boundary sets and PassRole confined to role/tf-managed/*; reads split into a separate statement that keeps Resource "*". - DenySelfMutation extended to cdk-hnb659fds-*, OrganizationAccountAccessRole and seahaven-* as defense in depth. - OIDC provider made conditional (CreateOIDCProvider), mirroring the sibling substrate, so a first-create rollback is recoverable rather than wedging the stack in ROLLBACK_COMPLETE against a Retained orphan. - README corrected: the guardrail policy is NOT Retain (only the provider is), so the Deny backstops do not survive a stack delete. checkov CKV_AWS_109 no longer fires on this template, so no suppression is needed. The template header records every divergence from the SAM copy. |
||
|---|---|---|
| .. | ||
| terraform-substrate.template.yaml | ||