From 5ba0a9965aa9f345af2b2781e727736db6fe9333 Mon Sep 17 00:00:00 2001 From: Adam Moussa Date: Mon, 10 Aug 2026 11:31:31 -0400 Subject: [PATCH] fix(iam): grant weekly-menu role SSM deploy params --- oidc-deploy-roles.yaml | 20 +++++++++++--------- 1 file changed, 11 insertions(+), 9 deletions(-) diff --git a/oidc-deploy-roles.yaml b/oidc-deploy-roles.yaml index a068911..4ea8b24 100644 --- a/oidc-deploy-roles.yaml +++ b/oidc-deploy-roles.yaml @@ -1355,10 +1355,11 @@ Resources: # Scoped runtime role for the meal-order-manager weekly-menu workflow # (Monday scrape + order-form publish). Deliberately narrower than the - # repo's deploy role: the scheduled job reads stack outputs and app config, - # invokes the IAM-authenticated publication API, writes the published form, - # and invalidates the form's CloudFront path. It deploys nothing, so it gets - # no CloudFormation write actions, no PassRole, and no DynamoDB access. + # repo's deploy role: the scheduled job reads Terraform-written deploy + # parameters and app config, invokes the IAM-authenticated publication API, + # writes the published form, and invalidates the form's CloudFront path. It + # deploys nothing, so it gets no CloudFormation write actions, no PassRole, + # and no DynamoDB access. MealOrderManagerWeeklyMenuRole: Type: AWS::IAM::Role Properties: @@ -1384,11 +1385,6 @@ Resources: PolicyDocument: Version: "2012-10-17" Statement: - - Effect: Allow - Action: - - cloudformation:DescribeStacks - Resource: - - !Sub arn:aws:cloudformation:us-east-1:${AWS::AccountId}:stack/meal-order-manager/* - Effect: Allow Action: - secretsmanager:GetSecretValue @@ -1402,7 +1398,13 @@ Resources: - Effect: Allow Action: - ssm:GetParameter + # Deploy targets are written by Terraform (meal-order-manager + # terraform/ssm.tf). App config params remain named grants only. Resource: + - !Sub arn:aws:ssm:us-east-1:${AWS::AccountId}:parameter/meal-order-manager/deploy/api-url + - !Sub arn:aws:ssm:us-east-1:${AWS::AccountId}:parameter/meal-order-manager/deploy/form-bucket + - !Sub arn:aws:ssm:us-east-1:${AWS::AccountId}:parameter/meal-order-manager/deploy/distribution-id + - !Sub arn:aws:ssm:us-east-1:${AWS::AccountId}:parameter/meal-order-manager/deploy/form-url - !Sub arn:aws:ssm:us-east-1:${AWS::AccountId}:parameter/meal-order-manager/google-client-id - !Sub arn:aws:ssm:us-east-1:${AWS::AccountId}:parameter/meal-order-manager/slack-channel-id # Publication routes on the meal-order-manager HttpApi (API id