mirror of
https://github.com/tiennm99/miti99bot.git
synced 2026-09-20 04:23:43 +00:00
Replaces the 10x *FullAccess managed policies with a single stack-scoped inline policy (miti99bot-deploy) on the role. Policy boundaries: - All resource ARNs scoped to miti99bot* (covers future miti99bot-dev) - iam:PassRole conditioned on iam:PassedToService = lambda + scheduler - iam:UpdateAssumeRolePolicy excluded (no trust-rewrite escalation) - iam:AttachRolePolicy excluded (SAM uses inline PutRolePolicy) - Wildcards limited to actions with no resource-level support (sts:GetCallerIdentity, s3:ListAllMyBuckets, cloudformation:ListStacks, cloudformation:ValidateTemplate) Rollback: aws/iam-rollback-fullaccess.sh re-attaches all 10 FullAccess policies with retry-on-throttle + final verification. Apply via Phase 4 two-stage cutover (dual-attach trial then detach). Policy is committed but NOT yet attached -- Phase 4 applies it. Plan: plans/260518-1019-iam-least-privilege/phase-03-draft-custom-policy.md Audit: plans/reports/code-reviewer-260518-1019-security-aws-infra.md
52 lines
1.7 KiB
Bash
Executable File
52 lines
1.7 KiB
Bash
Executable File
#!/bin/sh
|
|
# Re-attaches the 10 FullAccess managed policies to github-deploy-miti99bot.
|
|
# Idempotent: attach-role-policy succeeds even if policy already attached.
|
|
# Use as emergency rollback during Phase 4 cutover (plans/260518-1019-iam-least-privilege).
|
|
#
|
|
# Usage:
|
|
# bash aws/iam-rollback-fullaccess.sh
|
|
# AWS_PROFILE=admin bash aws/iam-rollback-fullaccess.sh
|
|
ROLE=github-deploy-miti99bot
|
|
POLICIES="
|
|
arn:aws:iam::aws:policy/AWSCloudFormationFullAccess
|
|
arn:aws:iam::aws:policy/AWSLambda_FullAccess
|
|
arn:aws:iam::aws:policy/AmazonDynamoDBFullAccess
|
|
arn:aws:iam::aws:policy/AmazonEventBridgeFullAccess
|
|
arn:aws:iam::aws:policy/AmazonSQSFullAccess
|
|
arn:aws:iam::aws:policy/AmazonSSMFullAccess
|
|
arn:aws:iam::aws:policy/CloudWatchLogsFullAccess
|
|
arn:aws:iam::aws:policy/AWSBudgetsActionsWithAWSResourceControlAccess
|
|
arn:aws:iam::aws:policy/IAMFullAccess
|
|
arn:aws:iam::aws:policy/AmazonS3FullAccess
|
|
"
|
|
|
|
PROFILE_FLAG=""
|
|
if [ -n "$AWS_PROFILE" ]; then
|
|
PROFILE_FLAG="--profile $AWS_PROFILE"
|
|
fi
|
|
|
|
for arn in $POLICIES; do
|
|
for try in 1 2 3 4 5; do
|
|
if aws iam attach-role-policy --role-name "$ROLE" --policy-arn "$arn" $PROFILE_FLAG 2>&1; then
|
|
break
|
|
fi
|
|
echo "retry $try for $arn after throttle..."
|
|
sleep $((try * 2))
|
|
done
|
|
done
|
|
|
|
# Verify final state -- exit non-zero if anything is missing.
|
|
ATTACHED=$(aws iam list-attached-role-policies --role-name "$ROLE" $PROFILE_FLAG \
|
|
--query 'AttachedPolicies[].PolicyArn' --output text)
|
|
MISSING=0
|
|
for arn in $POLICIES; do
|
|
echo "$ATTACHED" | grep -q "$arn" || { echo "MISSING: $arn"; MISSING=1; }
|
|
done
|
|
|
|
if [ "$MISSING" = 0 ]; then
|
|
echo "Rollback complete -- all 10 FullAccess policies attached."
|
|
else
|
|
echo "Rollback INCOMPLETE -- see MISSING lines above. Re-run or attach via console."
|
|
exit 1
|
|
fi
|