mirror of
https://github.com/Sea-Haven-Industries/.github.git
synced 2026-09-30 07:03:11 +00:00
fix(iam): grant weekly-menu role SSM deploy params (#119)
Some checks are pending
ci / ci / ci (push) Waiting to run
Some checks are pending
ci / ci / ci (push) Waiting to run
This commit is contained in:
parent
9f2adabbea
commit
9a2efffce3
1 changed files with 11 additions and 9 deletions
|
|
@ -1355,10 +1355,11 @@ Resources:
|
||||||
|
|
||||||
# Scoped runtime role for the meal-order-manager weekly-menu workflow
|
# Scoped runtime role for the meal-order-manager weekly-menu workflow
|
||||||
# (Monday scrape + order-form publish). Deliberately narrower than the
|
# (Monday scrape + order-form publish). Deliberately narrower than the
|
||||||
# repo's deploy role: the scheduled job reads stack outputs and app config,
|
# repo's deploy role: the scheduled job reads Terraform-written deploy
|
||||||
# invokes the IAM-authenticated publication API, writes the published form,
|
# parameters and app config, invokes the IAM-authenticated publication API,
|
||||||
# and invalidates the form's CloudFront path. It deploys nothing, so it gets
|
# writes the published form, and invalidates the form's CloudFront path. It
|
||||||
# no CloudFormation write actions, no PassRole, and no DynamoDB access.
|
# deploys nothing, so it gets no CloudFormation write actions, no PassRole,
|
||||||
|
# and no DynamoDB access.
|
||||||
MealOrderManagerWeeklyMenuRole:
|
MealOrderManagerWeeklyMenuRole:
|
||||||
Type: AWS::IAM::Role
|
Type: AWS::IAM::Role
|
||||||
Properties:
|
Properties:
|
||||||
|
|
@ -1384,11 +1385,6 @@ Resources:
|
||||||
PolicyDocument:
|
PolicyDocument:
|
||||||
Version: "2012-10-17"
|
Version: "2012-10-17"
|
||||||
Statement:
|
Statement:
|
||||||
- Effect: Allow
|
|
||||||
Action:
|
|
||||||
- cloudformation:DescribeStacks
|
|
||||||
Resource:
|
|
||||||
- !Sub arn:aws:cloudformation:us-east-1:${AWS::AccountId}:stack/meal-order-manager/*
|
|
||||||
- Effect: Allow
|
- Effect: Allow
|
||||||
Action:
|
Action:
|
||||||
- secretsmanager:GetSecretValue
|
- secretsmanager:GetSecretValue
|
||||||
|
|
@ -1402,7 +1398,13 @@ Resources:
|
||||||
- Effect: Allow
|
- Effect: Allow
|
||||||
Action:
|
Action:
|
||||||
- ssm:GetParameter
|
- ssm:GetParameter
|
||||||
|
# Deploy targets are written by Terraform (meal-order-manager
|
||||||
|
# terraform/ssm.tf). App config params remain named grants only.
|
||||||
Resource:
|
Resource:
|
||||||
|
- !Sub arn:aws:ssm:us-east-1:${AWS::AccountId}:parameter/meal-order-manager/deploy/api-url
|
||||||
|
- !Sub arn:aws:ssm:us-east-1:${AWS::AccountId}:parameter/meal-order-manager/deploy/form-bucket
|
||||||
|
- !Sub arn:aws:ssm:us-east-1:${AWS::AccountId}:parameter/meal-order-manager/deploy/distribution-id
|
||||||
|
- !Sub arn:aws:ssm:us-east-1:${AWS::AccountId}:parameter/meal-order-manager/deploy/form-url
|
||||||
- !Sub arn:aws:ssm:us-east-1:${AWS::AccountId}:parameter/meal-order-manager/google-client-id
|
- !Sub arn:aws:ssm:us-east-1:${AWS::AccountId}:parameter/meal-order-manager/google-client-id
|
||||||
- !Sub arn:aws:ssm:us-east-1:${AWS::AccountId}:parameter/meal-order-manager/slack-channel-id
|
- !Sub arn:aws:ssm:us-east-1:${AWS::AccountId}:parameter/meal-order-manager/slack-channel-id
|
||||||
# Publication routes on the meal-order-manager HttpApi (API id
|
# Publication routes on the meal-order-manager HttpApi (API id
|
||||||
|
|
|
||||||
Loading…
Add table
Reference in a new issue