The dedicated CFN exec role hit AccessDenied on CreateChangeSet against
arn:...:aws:transform/Serverless-2016-10-31 during the first CI deploy
(template uses Transform: AWS::Serverless-2016-10-31). Scoped grant on that
transform ARN only. Cross-review: APPROVE (non-escalating).
Storage-only SAM stack (S3 + KMS CMK + write-only IAM writer + Secrets Manager
holder) as the S3 destination for LangSmith Bulk Export of Open SWE traces, for
long-horizon auditing and prompt improvement (Athena over Parquet).
- template.yaml: versioned SSE-KMS bucket, access-log bucket, TLS-only policy,
DEEP_ARCHIVE lifecycle; least-privilege LangSmith writer (bucket-wide PutObject,
ViaService-scoped KMS, no read/delete).
- bootstrap.yaml: dedicated OIDC deploy role + least-privilege CFN exec role so CI
never touches the shared execution role.
- CI/CD via reusable ci-python-sam / cd-sam workflows.
IAM passed GPT-4.1 cross-review + /sh-security-review (no blocking findings).