This repo builds a Lambda layer with intentionally vulnerable packages from a lock file
and auto-deploys a CloudFormation stack on every push to main.
- Create an S3 artifact bucket (same region as the stack, e.g.,
ap-southeast-2). - Create the GitHub OIDC provider in IAM (
token.actions.githubusercontent.com). - Create role
GitHubActionsBadlabDeployertrusted by that provider, attachAdministratorAccess.
AWS_REGION=ap-southeast-2AWS_ROLE_TO_ASSUME=arn:aws:iam::<ACCOUNT_ID>:role/GitHubActionsBadlabDeployerARTIFACT_BUCKET= your artifact bucket nameSTACK_NAME=plerion-badlabPUBLIC_BUCKET_NAME= a globally-unique S3 name you’ll keep stable
Push to main (or run the workflow manually). The workflow:
- Builds the vulnerable layer from
layers/vuln-py39/requirements.lock.txt - Uploads it to
s3://$ARTIFACT_BUCKET/layers/vuln-py39-layer.zip - Deploys
infra/plerion-badlab.yamlwithCAPABILITY_NAMED_IAM
After deploy, check CloudFormation → Stacks → plerion-badlab → Outputs for endpoints and demo creds.
Delete the stack. If the public S3 bucket prevents deletion, empty it first.