Skip to content

fix: restrict Quickstart IAM user - #12

Merged
neebs12 merged 1 commit into
mainfrom
fix/restrict-quickstart-user
Jul 5, 2026
Merged

neebs12 merged 1 commit into
mainfrom
fix/restrict-quickstart-user

Conversation

@neebs12

@neebs12 neebs12 commented Jul 5, 2026

Copy link
Copy Markdown
Owner

Summary

  • use the operator's local AWS credentials as the privileged bootstrap authority
  • restrict the stored Quickstart IAM user to image artifacts, exact-role passing, and Lambda MicroVM lifecycle
  • add regression assertions preventing IAM, OIDC, bucket, and log bootstrap permissions from returning
  • document the setup and credential-rotation boundary

Validation

  • npm run check
  • shellcheck scripts/*.sh test/scripts/*.sh
  • actionlint .github/workflows/*.yml examples/*.yml
  • git diff --check
  • no Terraform references

@neebs12
neebs12 merged commit d110213 into main Jul 5, 2026
2 checks passed
@neebs12
neebs12 deleted the fix/restrict-quickstart-user branch July 5, 2026 23:02
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant