fix(ci): grant exec role cloudformation:CreateChangeSet on the SAM transform

The dedicated CFN exec role hit AccessDenied on CreateChangeSet against
arn:...:aws:transform/Serverless-2016-10-31 during the first CI deploy
(template uses Transform: AWS::Serverless-2016-10-31). Scoped grant on that
transform ARN only. Cross-review: APPROVE (non-escalating).
This commit is contained in:
Adam Moussa 2026-07-10 16:07:42 -04:00
parent 1ec33d2937
commit e9678a0105
No known key found for this signature in database

View file

@ -121,6 +121,13 @@ Resources:
- "iam:ListAttachedUserPolicies"
- "iam:ListGroupsForUser"
Resource: !Sub "arn:aws:iam::${AWS::AccountId}:user/sh-openswe-traces-*"
# Required because template.yaml uses Transform: AWS::Serverless-2016-10-31.
# CloudFormation (as this exec role) must CreateChangeSet on the AWS-managed
# SAM transform macro. Scoped to only that transform ARN.
- Sid: SamTransform
Effect: Allow
Action: "cloudformation:CreateChangeSet"
Resource: !Sub "arn:aws:cloudformation:${AWS::Region}:aws:transform/Serverless-2016-10-31"
DeployRole:
Type: AWS::IAM::Role