diff --git a/oidc-deploy-roles.yaml b/oidc-deploy-roles.yaml index 94154d7..2d43de5 100644 --- a/oidc-deploy-roles.yaml +++ b/oidc-deploy-roles.yaml @@ -56,6 +56,7 @@ Resources: # - DynamoDB CRUD (afterhours-shifts table) # - secretsmanager:GetSecretValue (afterhours-shift-manager/*) # - ses:SendEmail (SES identity) + # - sqs:SendMessage (paychex-checkcomponents in seahaven-prod, WeeklyPost) # - CloudWatch Logs (all functions) # # payments-dashboard @@ -209,6 +210,25 @@ Resources: Resource: - !Sub "arn:aws:sqs:us-east-1:${AWS::AccountId}:*" + # ── SQS cross-account send (afterhours WeeklyPost -> paychex) ───── + # afterhours-shift-manager WeeklyPostFunction enqueues the weekly + # after-hours pay payload onto paychex-integrations' checkcomponents + # queue in seahaven-prod (PLAT-135). Send only. This is a ceiling, + # not a grant: the function's inline policy already allows this ARN + # and the prod queue policy admits only WeeklyPostFunctionRole-*, so + # the boundary was the one missing piece. The PrincipalArn condition + # keeps the ceiling closed for every other role on this boundary even + # if the queue policy is later loosened. + - Sid: SQSPaychexCheckcomponentsSend + Effect: Allow + Action: + - sqs:SendMessage + Resource: + - arn:aws:sqs:us-east-1:011934824531:paychex-checkcomponents + Condition: + ArnLike: + aws:PrincipalArn: !Sub "arn:aws:iam::${AWS::AccountId}:role/afterhours-shift-manager-WeeklyPostFunctionRole-*" + # ── Lambda invocation (payments, meal-order inter-function calls) ── - Sid: LambdaInvoke Effect: Allow