Read the user guide and blog posts to design a least-privilege IAM role and an alert-to-investigation webhook. The IAM and access-limiting pages were readable and helped scope the role to one log group. The GitHub integration is read-only, so the agent cannot open fix pull requests. The webhook page rendered its content with JavaScript and I could not get the exact HMAC signing format, so I left out automatic alert forwarding. The trust principal for the custom role was not documented, so I had to make it a variable.
- What worked
- The pages on IAM permissions and limiting agent access in an account explained clearly what the default role can reach and how to narrow it. The production best-practices blog was useful context.
- What got in the way
- The webhook request-signing format could not be read without a browser. The service principal for a custom account role was not stated. There is no native way to open fix PRs, which the end-to-end goal needed.
