feat(iam): allow afterhours WeeklyPost to send to paychex-checkcomponents (PLAT-135) (#142)
Some checks failed
ci / ci / ci (push) Has been cancelled

This commit is contained in:
Adam Moussa 2026-09-09 23:59:57 +00:00 • committed by GitHub
parent 9781774f04
commit 514552df92
No known key found for this signature in database
GPG key ID: B5690EEEBB952194

View file

@ -56,6 +56,7 @@ Resources:
# - DynamoDB CRUD (afterhours-shifts table)
# - secretsmanager:GetSecretValue (afterhours-shift-manager/*)
# - ses:SendEmail (SES identity)
# - sqs:SendMessage (paychex-checkcomponents in seahaven-prod, WeeklyPost)
# - CloudWatch Logs (all functions)
#
# payments-dashboard
@ -209,6 +210,25 @@ Resources:
Resource:
- !Sub "arn:aws:sqs:us-east-1:${AWS::AccountId}:*"
# ── SQS cross-account send (afterhours WeeklyPost -> paychex) ─────
# afterhours-shift-manager WeeklyPostFunction enqueues the weekly
# after-hours pay payload onto paychex-integrations' checkcomponents
# queue in seahaven-prod (PLAT-135). Send only. This is a ceiling,
# not a grant: the function's inline policy already allows this ARN
# and the prod queue policy admits only WeeklyPostFunctionRole-*, so
# the boundary was the one missing piece. The PrincipalArn condition
# keeps the ceiling closed for every other role on this boundary even
# if the queue policy is later loosened.
- Sid: SQSPaychexCheckcomponentsSend
Effect: Allow
Action:
- sqs:SendMessage
Resource:
- arn:aws:sqs:us-east-1:011934824531:paychex-checkcomponents
Condition:
ArnLike:
aws:PrincipalArn: !Sub "arn:aws:iam::${AWS::AccountId}:role/afterhours-shift-manager-WeeklyPostFunctionRole-*"
# ── Lambda invocation (payments, meal-order inter-function calls) ──
- Sid: LambdaInvoke
Effect: Allow