security-review/iam
Adam Moussa 58aa07d8be
feat: re-home cross-family reviewer CLI, retire Path B host artifacts (#5)
* feat: add router-less cross-family reviewer CLI (cross_review.py)

Re-homes the archived orchestrator repo's GPT-4.1 cross_reviewer as a
direct OpenAI SDK CLI: verbatim system prompt, same model id, ported
3-attempt exponential-backoff retry. Reads OPENAI_API_KEY from the
environment or the gitignored repo-root .env. Lazy openai import so
--help works without the package.

* feat: create machine-level suppressions dir on --global hook install

install-hooks.sh --global now mkdir -p's
${SH_SECURITY_SUPPRESSIONS_DIR:-~/.config/sea-haven/security-review} and
states the convention: machine-level <dir>/<repo-basename>/suppressions.json
is preferred over repo-local .security-review/suppressions.json, with
review.sh merging both when run without --suppressions.

* docs: describe sh-build-review as cross-family GPT-4.1 pass via cross_review.py

* chore: retire Path B VM host artifacts, repoint xmodel hook to cross_review.py

- delete systemd/ units and DEPLOY-R720.md (VM destroyed; recoverable
  from git history)
- nightly_sweep.sh: retained for reference — header notes the VM-based
  Path B sweep is retired; ENABLE_XMODEL_HOOK now calls this repo's
  cross_review.py instead of the archived orchestrator's run.py
- sweep-targets.txt: drop the stale ~/orchestrator warning block
- README: document the Claude Code web cloud routines
  (repo-scanner-nightly-sweep 08:00 ET, repo-checkers-plane1 07:30 ET,
  ALARM-only to #repo-scanner) and add the cross_review.py section

* docs(iam): repoint cross-family review invocations to cross_review.py

* fix(ci): exclude canary corpus from ruff, add import smoke test

CI has been red repo-wide: the latest ruff wants to reformat the
intentionally-vulnerable canary fixtures (whose line numbers are keyed
in canary-meta/KEY.md), and pytest --collect-only exits 5 with zero
tests. Exclude canary/ via ruff.toml and add a root-level import smoke
test so collection is non-empty and imports cross_review.py.
2026-07-14 19:24:01 -04:00
..
aws-posture-readonly-policy.json chore: import security-review gate, sweep, and Plane-1 checkers into standalone repo 2026-06-29 11:41:41 -04:00
aws-posture-readonly-policy.rationale.md chore: import security-review gate, sweep, and Plane-1 checkers into standalone repo 2026-06-29 11:41:41 -04:00
aws-posture-trust-policy.json chore: import security-review gate, sweep, and Plane-1 checkers into standalone repo 2026-06-29 11:41:41 -04:00
CROSS-REVIEW-PACKET.md feat: re-home cross-family reviewer CLI, retire Path B host artifacts (#5) 2026-07-14 19:24:01 -04:00
README.md feat: re-home cross-family reviewer CLI, retire Path B host artifacts (#5) 2026-07-14 19:24:01 -04:00
roles-anywhere-config.json chore: import security-review gate, sweep, and Plane-1 checkers into standalone repo 2026-06-29 11:41:41 -04:00
step-ca-config-sketch.md chore: import security-review gate, sweep, and Plane-1 checkers into standalone repo 2026-06-29 11:41:41 -04:00

security-review/iam/ — Phase-3 IAM artifacts (authored for cross-review, NOT applied)

These are the IAM / Roles Anywhere / step-ca artifacts for the R720 agent-team aws-posture checker (design docs/r720-agent-team-design.md D5 / §4 / §6.3 / §7 Phase 3).

Nothing here is applied to AWS. They are FILES for the mandatory GPT-4.1 IAM cross-review.

Cross-review status (2026-06-18): APPROVE, no BLOCKs. FIXes applied — aws:SourceAccount added to the trust policy; ec2:DescribeImages removed from the permission policy (see CROSS-REVIEW-PACKET.md header + aws-posture-readonly-policy.rationale.md). The review passing unblocked building ../checkers/aws-posture.sh (built in this Phase-3 change set). That checker stays PROVISIONING-GATED: it makes NO AWS call until step-ca + the Roles Anywhere trust anchor + this role are stood up. Provisioning happens only after the review is recorded (design §7, B3) — and a VM snapshot is taken first per feedback_ec2_replacement_snapshot.

Decision (D5): the box stays read-only and authenticates to AWS via Roles Anywhere short-lived leaf certs issued by a new internal step-ca — no long-lived AWS key on the box.

File Purpose
CROSS-REVIEW-PACKET.md Start here. End-to-end trust model, least-privilege rationale, blast radius, exercised rollback, and the specific items for the reviewer.
aws-posture-readonly-policy.json Least-privilege read-only permission policy (valid, applyable IAM JSON).
aws-posture-readonly-policy.rationale.md Statement-by-statement rationale (IAM JSON can't carry comments).
aws-posture-trust-policy.json Role trust policy — pins Roles Anywhere + the leaf subject/issuer CN + trust-anchor ARN.
roles-anywhere-config.json Trust-anchor (pins step-ca root) + profile (1h session) config.
step-ca-config-sketch.md Internal CA config + systemd-timer auto-renewal of the short-lived leaf.

Per global instructions this IAM change also requires the GPT-4.1 cross-family review via python3 ~/Documents/repositories/seahaven/security-review/cross_review.py "<task>"; this directory is that review's input.