mirror of
https://github.com/Sea-Haven-Industries/.github.git
synced 2026-09-30 09:23:11 +00:00
fix(iam): grant weekly-menu role execute-api invoke
This commit is contained in:
parent
81cf168170
commit
eeee7d014c
1 changed files with 9 additions and 6 deletions
|
|
@ -1383,9 +1383,9 @@ Resources:
|
||||||
# Scoped runtime role for the meal-order-manager weekly-menu workflow
|
# Scoped runtime role for the meal-order-manager weekly-menu workflow
|
||||||
# (Monday scrape + order-form publish). Deliberately narrower than the
|
# (Monday scrape + order-form publish). Deliberately narrower than the
|
||||||
# repo's deploy role: the scheduled job reads stack outputs and app config,
|
# repo's deploy role: the scheduled job reads stack outputs and app config,
|
||||||
# writes menu items and the published form, and invalidates the form's
|
# invokes the IAM-authenticated publication API, writes the published form,
|
||||||
# CloudFront path. It deploys nothing, so it gets no CloudFormation write
|
# and invalidates the form's CloudFront path. It deploys nothing, so it gets
|
||||||
# actions, no PassRole, and no access outside the form bucket.
|
# no CloudFormation write actions, no PassRole, and no DynamoDB access.
|
||||||
MealOrderManagerWeeklyMenuRole:
|
MealOrderManagerWeeklyMenuRole:
|
||||||
Type: AWS::IAM::Role
|
Type: AWS::IAM::Role
|
||||||
Properties:
|
Properties:
|
||||||
|
|
@ -1432,12 +1432,15 @@ Resources:
|
||||||
Resource:
|
Resource:
|
||||||
- !Sub arn:aws:ssm:us-east-1:${AWS::AccountId}:parameter/meal-order-manager/google-client-id
|
- !Sub arn:aws:ssm:us-east-1:${AWS::AccountId}:parameter/meal-order-manager/google-client-id
|
||||||
- !Sub arn:aws:ssm:us-east-1:${AWS::AccountId}:parameter/meal-order-manager/slack-channel-id
|
- !Sub arn:aws:ssm:us-east-1:${AWS::AccountId}:parameter/meal-order-manager/slack-channel-id
|
||||||
|
# Publication routes on the meal-order-manager HttpApi (API id
|
||||||
|
# b5mli7qgp3 is stable for the life of the stack). Menu/settings
|
||||||
|
# writes go through these IAM-authenticated routes, not DynamoDB.
|
||||||
- Effect: Allow
|
- Effect: Allow
|
||||||
Action:
|
Action:
|
||||||
- dynamodb:GetItem
|
- execute-api:Invoke
|
||||||
- dynamodb:PutItem
|
|
||||||
Resource:
|
Resource:
|
||||||
- !Sub arn:aws:dynamodb:us-east-1:${AWS::AccountId}:table/meal-order-manager-orders
|
- !Sub arn:aws:execute-api:us-east-1:${AWS::AccountId}:b5mli7qgp3/*/GET/api/publish/settings
|
||||||
|
- !Sub arn:aws:execute-api:us-east-1:${AWS::AccountId}:b5mli7qgp3/*/POST/api/publish/menu
|
||||||
- Effect: Allow
|
- Effect: Allow
|
||||||
Action:
|
Action:
|
||||||
- s3:PutObject
|
- s3:PutObject
|
||||||
|
|
|
||||||
Loading…
Add table
Reference in a new issue