Skip to content

fix(iac/aws): ce:GetCostAndUsage is granted in no IaC flavor; ladder baselines are denied #1967

Description

@cristim

Summary

A scheduled ladder run computes its usage baseline through GetOnDemandSeries, which calls costexplorer.GetCostAndUsage under the ambient Lambda or Fargate execution role. None of the IaC flavors that encode CUDly's runtime IAM grant ce:GetCostAndUsage: the Cost Explorer statement lists only the six Reservation and Savings Plans actions. Every ladder run therefore fails its baseline with AccessDenied and is recorded as Errored with no plan produced. scripts/check-aws-iam-parity.sh cannot catch this because it compares the templates against each other, never against the SDK calls the Go code makes, so a uniform omission passes.

Location

  • terraform/modules/compute/aws/lambda/main.tf:381-386 at 3c0f8ac
  • terraform/modules/compute/aws/fargate/main.tf:373-378
  • cloudformation/stacks/CUDly/template.yaml:423-428
  • caller: providers/aws/recommendations/ondemand_series.go:182 via providers/aws/ladder/factory.go:85 (onDemandSeriesAdapter) and internal/api/handler_ladder.go:306 (GetUsageBaseline); wired at internal/server/app.go:570

Failure scenario

An operator enables a ladder config on a Lambda or Fargate deployment provisioned from any of the three templates. The scheduled ladder task runs GetUsageBaseline, the GetCostAndUsage call returns AccessDeniedException, and the run ends Errored. No ladder plan is ever produced on a stock deployment. The only ce:* wildcard in the tree is the permissions-boundary ceiling in policy_boundary.tf:163, which caps but never grants.

Evidence

Action = [
  "ce:GetReservationUtilization",
  "ce:GetReservationPurchaseRecommendation",
  "ce:GetReservationCoverage",
  "ce:GetSavingsPlansPurchaseRecommendation",
  "ce:GetSavingsPlansUtilization",
  "ce:GetSavingsPlansCoverage",
]

Suggested fix

Add ce:GetCostAndUsage to the runtime Cost Explorer statement in the Lambda and Fargate modules and the CloudFormation template, and add a guard (a Go test or an extension of check-aws-iam-parity.sh) asserting that every ce: action the SDK code calls appears in each flavor.


Found by the 2026-09-02 codebase audit, finding A13-001, reported by one reviewer and independently confirmed by a second. Full report: docs/audits/codebase-audit-2026-09-02.md.

Activity

  1. added a commit that references this issue on Sep 14, 2026
    667f404
  2. cristim commented on Sep 14, 2026

    @cristim
    MemberAuthor

    Merged PR #2077 as efd6e95 after native macOS verification, fresh-context independent Astra review, substantive clean full CodeRabbit review and all28 exact-HEAD check/status entries passing. Reviewed HEAD899ab790d and merge commit have the identical tree39f40be04a616331f686ec61250d0398fbd99c4a; parent is the reviewed base81f2fc3.

    Verified: six missing CE/EC2 grants across allthree runtime IaC flavors; native stdlib Go/race/parity tests; exact-main failure, corrected candidate pass and seven omission/comment mutations; source, Allow/role attachment and RI-only tag scope inspected. Final evidence is linked in the PR body. No checks were bypassed.

    Post-merge workflows are being watched. No manual apply, purchase, listing, cancellation or tagging was performed. Deployed IAM acceptance, seller eligibility and cross-account runtime behavior are not claimed verified. AWS Sanity credentialed steps were skipped due to absent read-only role configuration.

    Follow-ups remain LeanerCloud/cloud-commitments-platform#42 and LeanerCloud/cloud-commitments-go#107 for unsupported/unproved tagging contracts; LeanerCloud/cloud-commitments-platform#261 for Marketplace credentials, LeanerCloud/cloud-commitments-platform#27 for polling/seller checks and LeanerCloud/cloud-commitments-platform#335 for failed compensating cancellation. This merge addresses the missing-grant scope only; auto-closure of #1967/#1968 does not close those separate issues.

  3. cristim commented on Sep 14, 2026

    @cristim
    MemberAuthor

    Post-merge verification for #2077 is complete: all eight workflows at efd6e95 passed, including the three cloud deployment workflows and their health/smoke checks. Detailed proof and limits: #2077 (comment) . This does not claim live purchase, Marketplace or tagging acceptance; the previously linked follow-up issues remain open.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions