fix(ci): grant exec role cloudformation:CreateChangeSet on the SAM transform (#2)
Some checks failed
Deploy / deploy (push) Has been cancelled

The dedicated CFN exec role hit AccessDenied on CreateChangeSet against
arn:...:aws:transform/Serverless-2016-10-31 during the first CI deploy
(template uses Transform: AWS::Serverless-2016-10-31). Scoped grant on that
transform ARN only. Cross-review: APPROVE (non-escalating).
This commit is contained in:
Adam Moussa 2026-07-10 16:08:49 -04:00 • committed by GitHub
parent 1ec33d2937
commit 6e9749fe07
No known key found for this signature in database
GPG key ID: B5690EEEBB952194

View file

@ -121,6 +121,13 @@ Resources:
- "iam:ListAttachedUserPolicies" - "iam:ListAttachedUserPolicies"
- "iam:ListGroupsForUser" - "iam:ListGroupsForUser"
Resource: !Sub "arn:aws:iam::${AWS::AccountId}:user/sh-openswe-traces-*" Resource: !Sub "arn:aws:iam::${AWS::AccountId}:user/sh-openswe-traces-*"
# Required because template.yaml uses Transform: AWS::Serverless-2016-10-31.
# CloudFormation (as this exec role) must CreateChangeSet on the AWS-managed
# SAM transform macro. Scoped to only that transform ARN.
- Sid: SamTransform
Effect: Allow
Action: "cloudformation:CreateChangeSet"
Resource: !Sub "arn:aws:cloudformation:${AWS::Region}:aws:transform/Serverless-2016-10-31"
DeployRole: DeployRole:
Type: AWS::IAM::Role Type: AWS::IAM::Role