aws-samples / aws-samples/sample-autonomous-cloud-coding-agents

feat(bootstrap): resource-action-map for synth-time validation

Ouverte
#124 3 commentaires 0 réactions 0 personnes assignées Voir sur GitHub
enhancement infra-cdk security
Langage dominant
TypeScript
Étoiles
143
Forks
46
Merge moyen
3 j 10 h
PR mergées (30 j)
24

Description

## Parent

Sub-issue 4 of #120 (RFC: Least-privilege CDK bootstrap policies as code)

## Branch strategy

`feat/bootstrap-action-map` → targets `feat/bootstrap-template`

## Estimated review time: ~25 min

## Summary

Create a mapping from CloudFormation resource types to the IAM actions required to manage them (CRUD lifecycle), scoped to the ~30 resource types used by this app. This map powers the synth-time Aspect (Sub-issue 5) and informs the preflight validator (Sub-issue 6).

## Deliverables

- [ ] Create `cdk/src/bootstrap/preflight/resource-action-map.ts`:
- Export a typed map: `Record`
- Cover all CF resource types present in `cdk.out/` after synth (e.g., `AWS::DynamoDB::Table`, `AWS::Lambda::Function`, `AWS::ApiGateway::RestApi`, `AWS::EC2::VPC`, `AWS::Cognito::UserPool`, `AWS::WAFv2::WebACL`, `AWS::Bedrock::Guardrail`, etc.)
- Each entry's action list is the minimum CloudFormation needs to manage the resource lifecycle
- [ ] Create `cdk/src/bootstrap/preflight/index.ts` — barrel export
- [ ] Create `cdk/test/bootstrap/resource-action-map.test.ts`:
- All resource types in the synthesized template have a mapping entry (synth → extract types → assert coverage)
- Each action list is non-empty
- All actions use valid IAM action format (`service:ActionName`)
- Combined action set is a subset of the three policy documents' action sets (the map doesn't require more than what policies allow)

## Key design decisions

- **Scoped to this app's resources** — not all 800+ AWS CF resource types. Keeps maintenance tractable.
- Actions derived from [CloudFormation resource type documentation](https://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-template-resource-type-ref.html) and validated against CloudTrail from prior deployments.
- Unknown resource types (not in map) produce a **warning**, not an error — allows new constructs to be added without immediately updating the map.
- Map is a plain TypeScript object (not loaded from JSON) — benefits from IDE autocomplete and type checking.

## Acceptance criteria

- `mise //cdk:synth` followed by resource-type extraction shows 100% map coverage of current template
- All tests pass
- No circular imports between `preflight/` and `policies/`

Guide de contribution

Ouvrir le guide de contribution

Piste de recherche

Commencez par le cdk/src/bootstrap/ existant et les trois documents de politique, puis exécutez mise //cdk:synth et extrayez les types de ressources depuis cdk.out/. Implémentez cdk/src/bootstrap/preflight/resource-action-map.ts et son export barrel, puis cdk/test/bootstrap/resource-action-map.test.ts. Le travail est terminé lorsque les types de ressources actuellement synthétisés disposent de mappages d’actions valides et non vides, que les actions sont couvertes par les politiques et que les tests passent sans imports circulaires.

Rédigé par le modèle d'indexation à partir du texte de l'issue.

Évaluation

Stack technique
aws, typescript
Domaine
cloud, infrastructure, security
Type d'issue
Fonctionnalité
Difficulté
4/5
Temps estimé
3-5 jours
Activité
Calme
Clarté
Clairement spécifiée
Accessibilité débutants
48/100

Recevez les nouvelles issues par e-mail

Un résumé court des issues GitHub adaptées aux débutants.