Summary
execute:ri-exchange is missing from adminCarvedOuts (internal/auth/types.go), which lists only {execute, purchases}, {approve_any, purchases} and {retry_any, purchases}. Because of that omission, permissionsAllow (internal/auth/service_group.go) returns true unconditionally for an admin:* holder on execute:ri-exchange, bypassing the account, provider, service and region dimensions and the spend cap.
Why this matters now
This is pre-existing, but it has just become load-bearing. The Azure RI exchange execute work (issue #596 / PR #1515) extends the verb's blast radius from AWS-only to Azure, on an operation the code itself repeatedly describes as financially irreversible. Every guardrail added on that path - including the source-region fix in PR #1515 - is skipped for an admin-wildcard holder.
The separation-of-duties rationale that put execute:purchases in the carve-out list (#923) applies at least as strongly here: an RI exchange consumes existing commitments and buys replacements, and cannot be undone.
Fix direction
Add {execute, ri-exchange} to adminCarvedOuts so an admin must hold an explicit, constrained execute:ri-exchange grant like everyone else. Check for callers/tests that rely on the wildcard shortcut before landing, and mirror whatever migration/communication #923 used for execute:purchases.
Found during adversarial review of PR #1515. Out of scope for that PR.
Summary
execute:ri-exchangeis missing fromadminCarvedOuts(internal/auth/types.go), which lists only{execute, purchases},{approve_any, purchases}and{retry_any, purchases}. Because of that omission,permissionsAllow(internal/auth/service_group.go) returns true unconditionally for anadmin:*holder onexecute:ri-exchange, bypassing the account, provider, service and region dimensions and the spend cap.Why this matters now
This is pre-existing, but it has just become load-bearing. The Azure RI exchange execute work (issue #596 / PR #1515) extends the verb's blast radius from AWS-only to Azure, on an operation the code itself repeatedly describes as financially irreversible. Every guardrail added on that path - including the source-region fix in PR #1515 - is skipped for an admin-wildcard holder.
The separation-of-duties rationale that put
execute:purchasesin the carve-out list (#923) applies at least as strongly here: an RI exchange consumes existing commitments and buys replacements, and cannot be undone.Fix direction
Add
{execute, ri-exchange}toadminCarvedOutsso an admin must hold an explicit, constrainedexecute:ri-exchangegrant like everyone else. Check for callers/tests that rely on the wildcard shortcut before landing, and mirror whatever migration/communication #923 used forexecute:purchases.Found during adversarial review of PR #1515. Out of scope for that PR.