mirror of
https://github.com/Sea-Haven-Industries/.github.git
synced 2026-09-30 07:03:11 +00:00
fix(iam): grant weekly-menu role SSM deploy params
This commit is contained in:
parent
9f2adabbea
commit
5ba0a9965a
1 changed files with 11 additions and 9 deletions
|
|
@ -1355,10 +1355,11 @@ Resources:
|
|||
|
||||
# Scoped runtime role for the meal-order-manager weekly-menu workflow
|
||||
# (Monday scrape + order-form publish). Deliberately narrower than the
|
||||
# repo's deploy role: the scheduled job reads stack outputs and app config,
|
||||
# invokes the IAM-authenticated publication API, writes the published form,
|
||||
# and invalidates the form's CloudFront path. It deploys nothing, so it gets
|
||||
# no CloudFormation write actions, no PassRole, and no DynamoDB access.
|
||||
# repo's deploy role: the scheduled job reads Terraform-written deploy
|
||||
# parameters and app config, invokes the IAM-authenticated publication API,
|
||||
# writes the published form, and invalidates the form's CloudFront path. It
|
||||
# deploys nothing, so it gets no CloudFormation write actions, no PassRole,
|
||||
# and no DynamoDB access.
|
||||
MealOrderManagerWeeklyMenuRole:
|
||||
Type: AWS::IAM::Role
|
||||
Properties:
|
||||
|
|
@ -1384,11 +1385,6 @@ Resources:
|
|||
PolicyDocument:
|
||||
Version: "2012-10-17"
|
||||
Statement:
|
||||
- Effect: Allow
|
||||
Action:
|
||||
- cloudformation:DescribeStacks
|
||||
Resource:
|
||||
- !Sub arn:aws:cloudformation:us-east-1:${AWS::AccountId}:stack/meal-order-manager/*
|
||||
- Effect: Allow
|
||||
Action:
|
||||
- secretsmanager:GetSecretValue
|
||||
|
|
@ -1402,7 +1398,13 @@ Resources:
|
|||
- Effect: Allow
|
||||
Action:
|
||||
- ssm:GetParameter
|
||||
# Deploy targets are written by Terraform (meal-order-manager
|
||||
# terraform/ssm.tf). App config params remain named grants only.
|
||||
Resource:
|
||||
- !Sub arn:aws:ssm:us-east-1:${AWS::AccountId}:parameter/meal-order-manager/deploy/api-url
|
||||
- !Sub arn:aws:ssm:us-east-1:${AWS::AccountId}:parameter/meal-order-manager/deploy/form-bucket
|
||||
- !Sub arn:aws:ssm:us-east-1:${AWS::AccountId}:parameter/meal-order-manager/deploy/distribution-id
|
||||
- !Sub arn:aws:ssm:us-east-1:${AWS::AccountId}:parameter/meal-order-manager/deploy/form-url
|
||||
- !Sub arn:aws:ssm:us-east-1:${AWS::AccountId}:parameter/meal-order-manager/google-client-id
|
||||
- !Sub arn:aws:ssm:us-east-1:${AWS::AccountId}:parameter/meal-order-manager/slack-channel-id
|
||||
# Publication routes on the meal-order-manager HttpApi (API id
|
||||
|
|
|
|||
Loading…
Add table
Reference in a new issue