From e9678a01051107779c36cf2e0eb354d1b9957cb9 Mon Sep 17 00:00:00 2001 From: Adam Moussa Date: Fri, 10 Jul 2026 16:07:42 -0400 Subject: [PATCH] fix(ci): grant exec role cloudformation:CreateChangeSet on the SAM transform The dedicated CFN exec role hit AccessDenied on CreateChangeSet against arn:...:aws:transform/Serverless-2016-10-31 during the first CI deploy (template uses Transform: AWS::Serverless-2016-10-31). Scoped grant on that transform ARN only. Cross-review: APPROVE (non-escalating). --- bootstrap.yaml | 7 +++++++ 1 file changed, 7 insertions(+) diff --git a/bootstrap.yaml b/bootstrap.yaml index 88cc0f5..ce05c19 100644 --- a/bootstrap.yaml +++ b/bootstrap.yaml @@ -121,6 +121,13 @@ Resources: - "iam:ListAttachedUserPolicies" - "iam:ListGroupsForUser" Resource: !Sub "arn:aws:iam::${AWS::AccountId}:user/sh-openswe-traces-*" + # Required because template.yaml uses Transform: AWS::Serverless-2016-10-31. + # CloudFormation (as this exec role) must CreateChangeSet on the AWS-managed + # SAM transform macro. Scoped to only that transform ARN. + - Sid: SamTransform + Effect: Allow + Action: "cloudformation:CreateChangeSet" + Resource: !Sub "arn:aws:cloudformation:${AWS::Region}:aws:transform/Serverless-2016-10-31" DeployRole: Type: AWS::IAM::Role