From b94062bd86018c35c9296632867ba6cf612e0b7d Mon Sep 17 00:00:00 2001 From: Adam Moussa <166072409+amoussa1229@users.noreply.github.com> Date: Mon, 3 Aug 2026 15:32:35 -0400 Subject: [PATCH] fix(iam): grant weekly-menu role execute-api invoke (#114) --- oidc-deploy-roles.yaml | 15 +++++++++------ 1 file changed, 9 insertions(+), 6 deletions(-) diff --git a/oidc-deploy-roles.yaml b/oidc-deploy-roles.yaml index 038a849..e273cf1 100644 --- a/oidc-deploy-roles.yaml +++ b/oidc-deploy-roles.yaml @@ -1383,9 +1383,9 @@ Resources: # Scoped runtime role for the meal-order-manager weekly-menu workflow # (Monday scrape + order-form publish). Deliberately narrower than the # repo's deploy role: the scheduled job reads stack outputs and app config, - # writes menu items and the published form, and invalidates the form's - # CloudFront path. It deploys nothing, so it gets no CloudFormation write - # actions, no PassRole, and no access outside the form bucket. + # invokes the IAM-authenticated publication API, writes the published form, + # and invalidates the form's CloudFront path. It deploys nothing, so it gets + # no CloudFormation write actions, no PassRole, and no DynamoDB access. MealOrderManagerWeeklyMenuRole: Type: AWS::IAM::Role Properties: @@ -1432,12 +1432,15 @@ Resources: Resource: - !Sub arn:aws:ssm:us-east-1:${AWS::AccountId}:parameter/meal-order-manager/google-client-id - !Sub arn:aws:ssm:us-east-1:${AWS::AccountId}:parameter/meal-order-manager/slack-channel-id + # Publication routes on the meal-order-manager HttpApi (API id + # b5mli7qgp3 is stable for the life of the stack). Menu/settings + # writes go through these IAM-authenticated routes, not DynamoDB. - Effect: Allow Action: - - dynamodb:GetItem - - dynamodb:PutItem + - execute-api:Invoke Resource: - - !Sub arn:aws:dynamodb:us-east-1:${AWS::AccountId}:table/meal-order-manager-orders + - !Sub arn:aws:execute-api:us-east-1:${AWS::AccountId}:b5mli7qgp3/*/GET/api/publish/settings + - !Sub arn:aws:execute-api:us-east-1:${AWS::AccountId}:b5mli7qgp3/*/POST/api/publish/menu - Effect: Allow Action: - s3:PutObject