Skip to content

fix: authorize state machine alias events on the underlying ARN - #4005

Open
proton0210 wants to merge 1 commit into
aws:developfrom
proton0210:feature/sam-state-machine-alias-permissions
Open

proton0210 wants to merge 1 commit into
aws:developfrom
proton0210:feature/sam-state-machine-alias-permissions

Conversation

@proton0210

Copy link
Copy Markdown

Issue #, if available

Closes #3720.

Description of changes

With UseAliasAsEventTarget: true, SAM grants states:StartExecution on the alias ARN, so EventBridge cannot start the state machine. Step Functions authorizes alias invocations against the underlying state machine ARN.

Pass the underlying state machine to event-role construction while keeping the alias as the invocation target. This fixes the shared permission path for EventBridgeRule, CloudWatchEvent, Schedule, ScheduleV2 and Api events.

Description of how you validated changes

  • make pr on Python 3.12: all checks passed, 4,660 tests passed, 95.62% coverage.
  • Five regression cases fail before the fix and pass afterward; all 254 focused tests pass.
  • Compared 48 transforms before and after the fix across three partitions, covering alias/non-alias targets, custom schedule roles, permissions boundaries and conditional resources. Only the intended IAM policy resources change.

No live AWS deployment was run.

Checklist

By submitting this pull request, I confirm that my contribution is made under the terms of the Apache 2.0 license.

@proton0210
proton0210 requested a review from a team as a code owner October 5, 2026 17:34

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

StateMachine-UseAliasAsEventTarget property creates IAM role with incorrect permissions

1 participant