fix(iam): grant weekly-menu role execute-api invoke

This commit is contained in:
Adam Moussa 2026-08-03 15:29:07 -04:00
parent 81cf168170
commit eeee7d014c
No known key found for this signature in database

View file

@ -1383,9 +1383,9 @@ Resources:
# Scoped runtime role for the meal-order-manager weekly-menu workflow # Scoped runtime role for the meal-order-manager weekly-menu workflow
# (Monday scrape + order-form publish). Deliberately narrower than the # (Monday scrape + order-form publish). Deliberately narrower than the
# repo's deploy role: the scheduled job reads stack outputs and app config, # repo's deploy role: the scheduled job reads stack outputs and app config,
# writes menu items and the published form, and invalidates the form's # invokes the IAM-authenticated publication API, writes the published form,
# CloudFront path. It deploys nothing, so it gets no CloudFormation write # and invalidates the form's CloudFront path. It deploys nothing, so it gets
# actions, no PassRole, and no access outside the form bucket. # no CloudFormation write actions, no PassRole, and no DynamoDB access.
MealOrderManagerWeeklyMenuRole: MealOrderManagerWeeklyMenuRole:
Type: AWS::IAM::Role Type: AWS::IAM::Role
Properties: Properties:
@ -1432,12 +1432,15 @@ Resources:
Resource: Resource:
- !Sub arn:aws:ssm:us-east-1:${AWS::AccountId}:parameter/meal-order-manager/google-client-id - !Sub arn:aws:ssm:us-east-1:${AWS::AccountId}:parameter/meal-order-manager/google-client-id
- !Sub arn:aws:ssm:us-east-1:${AWS::AccountId}:parameter/meal-order-manager/slack-channel-id - !Sub arn:aws:ssm:us-east-1:${AWS::AccountId}:parameter/meal-order-manager/slack-channel-id
# Publication routes on the meal-order-manager HttpApi (API id
# b5mli7qgp3 is stable for the life of the stack). Menu/settings
# writes go through these IAM-authenticated routes, not DynamoDB.
- Effect: Allow - Effect: Allow
Action: Action:
- dynamodb:GetItem - execute-api:Invoke
- dynamodb:PutItem
Resource: Resource:
- !Sub arn:aws:dynamodb:us-east-1:${AWS::AccountId}:table/meal-order-manager-orders - !Sub arn:aws:execute-api:us-east-1:${AWS::AccountId}:b5mli7qgp3/*/GET/api/publish/settings
- !Sub arn:aws:execute-api:us-east-1:${AWS::AccountId}:b5mli7qgp3/*/POST/api/publish/menu
- Effect: Allow - Effect: Allow
Action: Action:
- s3:PutObject - s3:PutObject