Vertical slice 1 of Phase 56 (REQ-116). Offline-testable deliverables
landed; the live IAM apply step is escalated (D-095) below.
terraform/bootstrap/spike_runner_policy.json — extended with the minimum
permissions to terraform apply + probe CAP-017..022:
- cloudfront:* (CAP-020 static-assets stack)
- wafv2:* (CAP-020 WAF ACL)
- lambda:* on function:acdl-* (CAP-018 contract-ingestor)
- dynamodb:* on acdl-contracts + acdl-change-requests (CAP-017)
- secretsmanager:GetSecretValue on secret:acdl/* (CAP-018 github-token)
- sns:* on acdl-* (CAP-017 acdl-sod-halt)
- ce:Get* (REQ-119 Cost Explorer read-only)
- kms:* (CAP-017 platform + per-stack CMKs)
- iam:CreateOpenIDConnectProvider + iam:CreateRole (CAP-022 OIDC re-create)
.ciagent/IAM_POLICY.md — new baseline document. Original grants
(v1.1–v1.10) + v1.11 grants table + least-privilege scoping notes +
OIDC act_runner role plan + D-095 escalation note.
tests/test_iam_policy_baseline.py — 15 tests. Asserts the required
actions are present per service group, Lambda scoped to acdl-*, CE
read-only, no iam:PassRole to Resource:*, DynamoDB acdl-contracts in
resource. Regression-testable: any future permission drift surfaces as
a test failure at milestone COMPLETE (D-091 gate).
Test results: 15/15 pass. Full offline suite 509/509 pass (pre-existing
test_seeded_registry_runs_and_reports_honest_status in
test_verify_regression_mode.py hangs without AWS creds — environmental,
not introduced here).
---ci---
project: acdl
phase: 56
milestone: v1.11
status: execute
escalation:
type: deploy
id: D-095
reason: ACDL_BOOTSTRAP_AWS_* not set in the execution environment
blocking: live IAM policy apply (aws iam put-user-policy) + OIDC role
re-creation (CAP-022) — requires an admin AWS principal
action_required: provide fresh ACDL_BOOTSTRAP_AWS_ACCESS_KEY_ID +
ACDL_BOOTSTRAP_AWS_SECRET_ACCESS_KEY to the run environment, then
re-invoke ciagent-run to resume Phase 56 live step
fallback: none (D-095 confirmed: escalate to human, no silent fallback
to the deck-marking path)
---/ci---
5.8 KiB
ACDL — IAM Policy Baseline (v1.11, REQ-116)
Source of truth:
terraform/bootstrap/spike_runner_policy.json. Regression-tested by:tests/test_iam_policy_baseline.py(Phase 56).
The acdl-spike-runner IAM user is the principal that runs the ACDL
platform pipeline (plan + apply) against account 581513795199. This
document is the baseline of the permissions it holds, scoped to the
minimum required for the v1.11 milestone (Operating Model + Deploy
Verification, REQ-116..122). Any future grant must be documented here
and covered by the baseline test.
Original grants (v1.1–v1.10)
| Capability | Actions | Resource scope |
|---|---|---|
| Terraform state (S3) | s3:PutObject, s3:GetObject, s3:DeleteObject, s3:ListBucket, s3:GetBucketLocation, s3:GetBucketVersioning |
acdl-tfstate-581513795199-us-east-1 + /* |
| DynamoDB outbox | dynamodb:GetItem, PutItem, DeleteItem, UpdateItem, Query, Scan, DescribeTable |
table/acdl-outbox |
| STS identity | sts:GetCallerIdentity |
* |
| ECS | ecs:Create*, Describe*, Delete*, Update*, Register*, Deregister*, List* |
ecs:us-east-1:581513795199:* |
| ECR | ecr:Create*, Describe*, Delete*, Get*, Batch*, Put*, Upload*, Initiate*, Complete* |
ecr:us-east-1:581513795199:* |
| ELB | elasticloadbalancing:Create*, Describe*, Delete*, Modify*, Register*, Deregister* |
elasticloadbalancing:us-east-1:581513795199:* |
| IAM (role + policy mgmt) | iam:Create*, Get*, Delete*, PassRole, Attach*, Detach*, List*, Put* |
iam::581513795199:* |
| EC2 (VPC + SG) | ec2:Create*, Describe*, Delete*, Associate*, Disassociate*, Attach*, Detach*, Authorize* |
ec2:us-east-1:581513795199:* |
v1.11 grants (Phase 56, REQ-116)
| Capability | Actions | Resource scope | REQ |
|---|---|---|---|
| CloudFront (CAP-020) | cloudfront:Create*, Describe*, Get*, List*, Update*, Delete*, TagResource, UntagResource |
* (CloudFront ARNs are regional-global) |
REQ-118 |
| WAFv2 (CAP-020) | wafv2:Create*, Describe*, Get*, List*, Update*, Delete* |
* (WAFv2 global + regional) |
REQ-118 |
| Lambda (CAP-018) | lambda:Create*, Get*, List*, Update*, Delete*, InvokeFunction, InvokeFunctionUrl, TagResource, UntagResource, PublishLayerVersion |
lambda:us-east-1:581513795199:function:acdl-* |
REQ-117 |
| DynamoDB contracts (CAP-017) | dynamodb:Create*, Describe*, Get*, Put*, Update*, Delete*, Query, Scan, Batch* |
table/acdl-contracts + /* + table/acdl-change-requests + /* |
REQ-117 |
| Secrets Manager (CAP-018) | secretsmanager:GetSecretValue, DescribeSecret, CreateSecret, PutSecretValue, DeleteSecret, ListSecrets |
secret:acdl/* |
REQ-117 |
| SNS (CAP-017) | sns:CreateTopic, Publish, GetTopicAttributes, SetTopicAttributes, DeleteTopic, ListTopics |
sns:us-east-1:581513795199:acdl-* |
REQ-117 |
| Cost Explorer (REQ-119) | ce:GetCostAndUsage, GetCostForecast, GetCostAndUsageWithResources, GetDimensionValues, GetTags |
* (CE is account-scoped) |
REQ-119 |
| KMS (CAP-017) | kms:CreateKey, CreateAlias, Describe*, Get*, List*, Update*, Delete*, EnableKey, DisableKey, ScheduleKeyDeletion, TagResource, UntagResource |
* (KMS ARNs are account-wide) |
REQ-117/118 |
| IAM OIDC (CAP-022) | iam:CreateOpenIDConnectProvider, GetOpenIDConnectProvider, DeleteOpenIDConnectProvider, ListOpenIDConnectProviders, UpdateOpenIDConnectProviderThumbprint, iam:CreateRole, GetRole, ListRoles, DeleteRole, UpdateRole, TagRole, UntagRole |
* (OIDC providers + roles are account-wide) |
REQ-116 |
OIDC act_runner role (CAP-022, Phase 56)
The OIDC role for the Gitea act_runner was created in Phase 08 and
gone since (CAPABILITY_INVENTORY.md CAP-022). Phase 56 re-creates it
with a trust policy for the Gitea runner ARN. The role grants the
spike-runner-equivalent permissions to the runner via sts:AssumeRole,
so the runner does not need a long-lived access key. This closes the
chicken-and-egg: the spike-runner creates the OIDC role using the
bootstrap root key; the runner then assumes the role.
Note: Real OIDC federation (D-039) is blocked on
go-gitea/gitea#36988. Phase 56 re-creates the IAM role + trust policy; act_runner adoption is out of scope for v1.11 (see REQUIREMENTS.md §Out of Scope v1.11). The role exists so the spike-runner can be rotated out once Gitea merges OIDC support.
Least-privilege scoping notes
- CloudFront/WAF/KMS/CE/OIDC use
Resource: "*"because these services use account-scoped or global ARNs that cannot be resource- restricted at the statement level. Scope is bounded by the action list (e.g. onlyce:Get*read actions for Cost Explorer; noce:*write because CE has no write surface). - Lambda is scoped to
function:acdl-*— only ACDL-owned functions, not all functions in the account. - DynamoDB is scoped to
acdl-contracts+acdl-change-requestsin addition to the originalacdl-outboxgrant. The spike-runner cannot touch other tables in the account. - Secrets Manager is scoped to
secret:acdl/*— only ACDL-owned secrets. - SNS is scoped to
acdl-*topic names. - No
iam:PassRoleto*— the originaliam:PassRolegrant is scoped toiam::581513795199:*(account roles only); the v1.11 grant does not extend it.
Escalation (D-095)
Applying this policy requires the bootstrap root key
(ACDL_BOOTSTRAP_AWS_*). If the key is invalid (D-034 closed the
original root key), the run escalates to human for fresh access keys
— no silent fallback to the deck-marking path. The escalation is
committed as a ---ci--- block with escalation type and the run
pauses for the user.