mirror of
https://github.com/Sea-Haven-Industries/.github.git
synced 2026-09-30 04:43:12 +00:00
fix(iam): grant weekly-menu role execute-api invoke (#114)
This commit is contained in:
parent
81cf168170
commit
b94062bd86
1 changed files with 9 additions and 6 deletions
|
|
@ -1383,9 +1383,9 @@ Resources:
|
|||
# Scoped runtime role for the meal-order-manager weekly-menu workflow
|
||||
# (Monday scrape + order-form publish). Deliberately narrower than the
|
||||
# repo's deploy role: the scheduled job reads stack outputs and app config,
|
||||
# writes menu items and the published form, and invalidates the form's
|
||||
# CloudFront path. It deploys nothing, so it gets no CloudFormation write
|
||||
# actions, no PassRole, and no access outside the form bucket.
|
||||
# invokes the IAM-authenticated publication API, writes the published form,
|
||||
# and invalidates the form's CloudFront path. It deploys nothing, so it gets
|
||||
# no CloudFormation write actions, no PassRole, and no DynamoDB access.
|
||||
MealOrderManagerWeeklyMenuRole:
|
||||
Type: AWS::IAM::Role
|
||||
Properties:
|
||||
|
|
@ -1432,12 +1432,15 @@ Resources:
|
|||
Resource:
|
||||
- !Sub arn:aws:ssm:us-east-1:${AWS::AccountId}:parameter/meal-order-manager/google-client-id
|
||||
- !Sub arn:aws:ssm:us-east-1:${AWS::AccountId}:parameter/meal-order-manager/slack-channel-id
|
||||
# Publication routes on the meal-order-manager HttpApi (API id
|
||||
# b5mli7qgp3 is stable for the life of the stack). Menu/settings
|
||||
# writes go through these IAM-authenticated routes, not DynamoDB.
|
||||
- Effect: Allow
|
||||
Action:
|
||||
- dynamodb:GetItem
|
||||
- dynamodb:PutItem
|
||||
- execute-api:Invoke
|
||||
Resource:
|
||||
- !Sub arn:aws:dynamodb:us-east-1:${AWS::AccountId}:table/meal-order-manager-orders
|
||||
- !Sub arn:aws:execute-api:us-east-1:${AWS::AccountId}:b5mli7qgp3/*/GET/api/publish/settings
|
||||
- !Sub arn:aws:execute-api:us-east-1:${AWS::AccountId}:b5mli7qgp3/*/POST/api/publish/menu
|
||||
- Effect: Allow
|
||||
Action:
|
||||
- s3:PutObject
|
||||
|
|
|
|||
Loading…
Add table
Reference in a new issue