Files
miti99bot/aws/iam-rollback-fullaccess.sh
T
tiennm99 1d3aca439d feat(security): scoped IAM inline policy + rollback script for github-deploy-miti99bot (F1)
Replaces the 10x *FullAccess managed policies with a single
stack-scoped inline policy (miti99bot-deploy) on the role.

Policy boundaries:
- All resource ARNs scoped to miti99bot* (covers future miti99bot-dev)
- iam:PassRole conditioned on iam:PassedToService = lambda + scheduler
- iam:UpdateAssumeRolePolicy excluded (no trust-rewrite escalation)
- iam:AttachRolePolicy excluded (SAM uses inline PutRolePolicy)
- Wildcards limited to actions with no resource-level support
  (sts:GetCallerIdentity, s3:ListAllMyBuckets,
  cloudformation:ListStacks, cloudformation:ValidateTemplate)

Rollback: aws/iam-rollback-fullaccess.sh re-attaches all 10
FullAccess policies with retry-on-throttle + final verification.

Apply via Phase 4 two-stage cutover (dual-attach trial then detach).
Policy is committed but NOT yet attached -- Phase 4 applies it.

Plan: plans/260518-1019-iam-least-privilege/phase-03-draft-custom-policy.md
Audit: plans/reports/code-reviewer-260518-1019-security-aws-infra.md
2026-05-18 16:57:15 +07:00

52 lines
1.7 KiB
Bash
Executable File

#!/bin/sh
# Re-attaches the 10 FullAccess managed policies to github-deploy-miti99bot.
# Idempotent: attach-role-policy succeeds even if policy already attached.
# Use as emergency rollback during Phase 4 cutover (plans/260518-1019-iam-least-privilege).
#
# Usage:
# bash aws/iam-rollback-fullaccess.sh
# AWS_PROFILE=admin bash aws/iam-rollback-fullaccess.sh
ROLE=github-deploy-miti99bot
POLICIES="
arn:aws:iam::aws:policy/AWSCloudFormationFullAccess
arn:aws:iam::aws:policy/AWSLambda_FullAccess
arn:aws:iam::aws:policy/AmazonDynamoDBFullAccess
arn:aws:iam::aws:policy/AmazonEventBridgeFullAccess
arn:aws:iam::aws:policy/AmazonSQSFullAccess
arn:aws:iam::aws:policy/AmazonSSMFullAccess
arn:aws:iam::aws:policy/CloudWatchLogsFullAccess
arn:aws:iam::aws:policy/AWSBudgetsActionsWithAWSResourceControlAccess
arn:aws:iam::aws:policy/IAMFullAccess
arn:aws:iam::aws:policy/AmazonS3FullAccess
"
PROFILE_FLAG=""
if [ -n "$AWS_PROFILE" ]; then
PROFILE_FLAG="--profile $AWS_PROFILE"
fi
for arn in $POLICIES; do
for try in 1 2 3 4 5; do
if aws iam attach-role-policy --role-name "$ROLE" --policy-arn "$arn" $PROFILE_FLAG 2>&1; then
break
fi
echo "retry $try for $arn after throttle..."
sleep $((try * 2))
done
done
# Verify final state -- exit non-zero if anything is missing.
ATTACHED=$(aws iam list-attached-role-policies --role-name "$ROLE" $PROFILE_FLAG \
--query 'AttachedPolicies[].PolicyArn' --output text)
MISSING=0
for arn in $POLICIES; do
echo "$ATTACHED" | grep -q "$arn" || { echo "MISSING: $arn"; MISSING=1; }
done
if [ "$MISSING" = 0 ]; then
echo "Rollback complete -- all 10 FullAccess policies attached."
else
echo "Rollback INCOMPLETE -- see MISSING lines above. Re-run or attach via console."
exit 1
fi