Skip to content

[codex] Document conditioned account-root trust calibration#75

Merged
InfoSecHack merged 1 commit into
mainfrom
codex/admin-reachability-conditioned-root-trust-design
Jun 6, 2026
Merged

[codex] Document conditioned account-root trust calibration#75
InfoSecHack merged 1 commit into
mainfrom
codex/admin-reachability-conditioned-root-trust-design

Conversation

@InfoSecHack

Copy link
Copy Markdown
Owner

Summary: Adds a docs-only design note for the next admin_reachability calibration candidate: whether conditioned account-root trust narrowed by aws:PrincipalArn can count as a clean AssumeRole trust witness. Captures the real-pilot trigger, candidate safe clean-trust rule, ambiguous cases, required tests, expected impact, risks, non-claims, and exact next slice. Validation: targeted greps passed; account and ARN hygiene scans clean; Terraform/raw artifact scan clean; scripts/check.sh passed; scripts/test_fast.sh passed with 2059 tests; git diff --check passed.

@InfoSecHack InfoSecHack marked this pull request as ready for review June 6, 2026 18:40
@InfoSecHack InfoSecHack merged commit e200aaa into main Jun 6, 2026
6 checks passed
@InfoSecHack InfoSecHack deleted the codex/admin-reachability-conditioned-root-trust-design branch June 6, 2026 18:40
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant