mirror of
https://github.com/Sea-Haven-Industries/security-review.git
synced 2026-09-30 09:13:15 +00:00
Fresh-init copy of the security-review/ subsystem extracted from Sea-Haven-Industries/orchestrator (being deprecated). Adds org-standard scaffold: CI reusable-workflow callers (ruff + collect), dependency-review, labeler, dependabot, .gitignore, requirements.txt. Scheduled execution is migrating to Claude Code web routines (ALARM-only to #repo-scanner); the systemd units and nightly_sweep.sh/checker_coordinator.sh remain the source of truth. Committed with --no-verify: the canary fixtures (checkers/fixtures/**) carry intentional secret-shaped test data that trips the deterministic gate (the documented detector-fixture false positive); no new logic is introduced.
30 lines
2.1 KiB
Markdown
30 lines
2.1 KiB
Markdown
# security-review/iam/ — Phase-3 IAM artifacts (authored for cross-review, NOT applied)
|
|
|
|
These are the IAM / Roles Anywhere / step-ca artifacts for the R720 agent-team **aws-posture**
|
|
checker (design `docs/r720-agent-team-design.md` D5 / §4 / §6.3 / §7 Phase 3).
|
|
|
|
**Nothing here is applied to AWS.** They are FILES for the mandatory GPT-4.1 IAM cross-review.
|
|
|
|
**Cross-review status (2026-06-18): APPROVE, no BLOCKs.** FIXes applied — `aws:SourceAccount`
|
|
added to the trust policy; `ec2:DescribeImages` removed from the permission policy (see
|
|
`CROSS-REVIEW-PACKET.md` header + `aws-posture-readonly-policy.rationale.md`). The review passing
|
|
**unblocked building** `../checkers/aws-posture.sh` (built in this Phase-3 change set). That
|
|
checker stays **PROVISIONING-GATED**: it makes NO AWS call until step-ca + the Roles Anywhere
|
|
trust anchor + this role are stood up. Provisioning happens only after the review is recorded
|
|
(design §7, B3) — and a VM snapshot is taken first per `feedback_ec2_replacement_snapshot`.
|
|
|
|
Decision (D5): the box stays **read-only** and authenticates to AWS via **Roles Anywhere**
|
|
short-lived leaf certs issued by a new internal **step-ca** — **no long-lived AWS key on the
|
|
box**.
|
|
|
|
| File | Purpose |
|
|
|---|---|
|
|
| `CROSS-REVIEW-PACKET.md` | **Start here.** End-to-end trust model, least-privilege rationale, blast radius, exercised rollback, and the specific items for the reviewer. |
|
|
| `aws-posture-readonly-policy.json` | Least-privilege read-only permission policy (valid, applyable IAM JSON). |
|
|
| `aws-posture-readonly-policy.rationale.md` | Statement-by-statement rationale (IAM JSON can't carry comments). |
|
|
| `aws-posture-trust-policy.json` | Role trust policy — pins Roles Anywhere + the leaf subject/issuer CN + trust-anchor ARN. |
|
|
| `roles-anywhere-config.json` | Trust-anchor (pins step-ca root) + profile (1h session) config. |
|
|
| `step-ca-config-sketch.md` | Internal CA config + systemd-timer auto-renewal of the short-lived leaf. |
|
|
|
|
Per global instructions this IAM change also requires the GPT-4.1 cross-family review via
|
|
`orchestrator/run.py`; this directory is that review's input.
|