(pipelines/bootstrap): add Permission Boundary to bootstrap resources
See original GitHub issueThe cdk bootstrap
command will be able to be invoked as follows:
$ cdk bootstrap --permissions-boundary=arn:aws:iam::account-id:policy/policy-name-with-path
This sets the CloudFormation Execution Role up to enforce its use.
When users add:
{
"context": {
"@aws-cdk/core.permissionsBoundary": "arn:aws:iam::account-id:policy/policy-name-with-path"
}
}
To their cdk.json
, all Roles in all stacks will be provisioned with that permission boundary automatically.
This is a 🚀 Feature Request
Issue Analytics
- State:
- Created 3 years ago
- Reactions:13
- Comments:12 (5 by maintainers)
Top Results From Across the Web
How to deploy CDK v2 to an account that requires boundary ...
AWS CDK bootstrapping assumes that the AWS role has all of the necessary permissions to create the initial resources.
Read more >AWS CDK How to Set Permission Boundary to New Roles ...
My CDK project failed when it tries to create new roles within the pipeline. API: iam:CreateRole User: arn:aws:sts::305326993135:assumed-role/ ...
Read more >Bootstrapping AWS CDK in a Secure Environment - Medium
Find each AWS::IAM::Role resource in the template and, each one, add the ... You will need to use the appropriate permissions boundary policy...
Read more >Production-Ready CDK - Bootstrapping - Luminis
We call the process of setting these resources bootstrapping. ... the command will probably fail because of the permissions boundary.
Read more >IAM Permission Boundary does not prevent CDK escalating ...
In fact, cdk deploy essentially just creates a CloudFormation stack and calls the CloudFormation service which performs the actual resources creation. CDK ...
Read more >
Top Related Medium Post
No results found
Top Related StackOverflow Question
No results found
Troubleshoot Live Code
Lightrun enables developers to add logs, metrics and snapshots to live code - no restarts or redeploys required.
Start Free
Top Related Reddit Thread
No results found
Top Related Hackernoon Post
No results found
Top Related Tweet
No results found
Top Related Dev.to Post
No results found
Top Related Hashnode Post
No results found
Yes, that’s mine.
pat
On Mon, Feb 7, 2022 at 12:05 PM Kevin Johnson @.***> wrote:
– @.*** @.*** https://www.facebook.com/patrick.m.ryan1 http://www.imageryan.com
@patrickmryan Thank you. Can you also please attach example policy for boundary in GH repo? I have issues with defining that policy due to lack of knowledge about AWS policies and boundary permissions.