Skip to content

Permissions boundary#2131

Draft
cadmiumcat wants to merge 5 commits into
mainfrom
permissions-boundary
Draft

Permissions boundary#2131
cadmiumcat wants to merge 5 commits into
mainfrom
permissions-boundary

Conversation

@cadmiumcat
Copy link
Copy Markdown
Contributor

What problem does this pull request solve?

Trello card:

Things to consider when reviewing

  • Ensure that you consider the wider context.
  • Does it work when run on your machine?
  • Is it clear what the code is doing?
  • Do the commit messages explain why the changes were made?
  • Are there all the unit tests needed?
  • Has all relevant documentation been updated?

Reminders

If you've made changes to the deployer role (files in modules/deployer-access):

  • Remember to run make <environment> forms/account apply on the relevant environments (dev, staging and/or prod)
  • Check the #govuk-forms-deployment-notifications Slack channel to ensure the apply-forms-terraform-<environment> pipelines have run successfully

When we assign this policy to a role we want to make sure it's not able to
change the boundaries
We want to prevent priviledge escalation of the deployer role. Any role created
by the deployer role should have at least the same permissions boundary as the
deployer
@cadmiumcat cadmiumcat force-pushed the permissions-boundary branch from d50f556 to dc898a9 Compare May 27, 2026 10:02
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant