MI-291: Add Resource Prefix Aspect#1627
Merged
kai-nguyen-aligent merged 3 commits intomainfrom Mar 13, 2026
Merged
Conversation
Contributor
|
✅ Changeset detected - Thanks for adding release notes! |
TheOrangePuff
approved these changes
Mar 12, 2026
Member
TheOrangePuff
left a comment
There was a problem hiding this comment.
Cool idea, looks good to me!
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Description of the proposed changes
In old Serverless Framework stacks, we use prefixes to restrict access to resources. This work well for Serverless Framework as we implicitly set the resource names. However, it does not work for CDK stacks due to the fact that CDK automatically name resources for us. We planned to use resource tags instead but many resources are not ABAC (tag-based IAM auth) supported. Eg: Lambda, SQS, SNS, API Gateway. As a result, we continue using prefixes instead of tags. This aspect is developed to support:
Notes to reviewers
🛈 When you've finished leaving feedback, please add a final comment to the PR tagging the author, letting them know that you have finished leaving feedback