fix(iam): grant weekly-menu role execute-api invoke

This commit is contained in:
Adam Moussa 2026-08-03 15:29:07 -04:00
parent 81cf168170
commit eeee7d014c
No known key found for this signature in database

View file

@ -1383,9 +1383,9 @@ Resources:
# Scoped runtime role for the meal-order-manager weekly-menu workflow
# (Monday scrape + order-form publish). Deliberately narrower than the
# repo's deploy role: the scheduled job reads stack outputs and app config,
# writes menu items and the published form, and invalidates the form's
# CloudFront path. It deploys nothing, so it gets no CloudFormation write
# actions, no PassRole, and no access outside the form bucket.
# invokes the IAM-authenticated publication API, writes the published form,
# and invalidates the form's CloudFront path. It deploys nothing, so it gets
# no CloudFormation write actions, no PassRole, and no DynamoDB access.
MealOrderManagerWeeklyMenuRole:
Type: AWS::IAM::Role
Properties:
@ -1432,12 +1432,15 @@ Resources:
Resource:
- !Sub arn:aws:ssm:us-east-1:${AWS::AccountId}:parameter/meal-order-manager/google-client-id
- !Sub arn:aws:ssm:us-east-1:${AWS::AccountId}:parameter/meal-order-manager/slack-channel-id
# Publication routes on the meal-order-manager HttpApi (API id
# b5mli7qgp3 is stable for the life of the stack). Menu/settings
# writes go through these IAM-authenticated routes, not DynamoDB.
- Effect: Allow
Action:
- dynamodb:GetItem
- dynamodb:PutItem
- execute-api:Invoke
Resource:
- !Sub arn:aws:dynamodb:us-east-1:${AWS::AccountId}:table/meal-order-manager-orders
- !Sub arn:aws:execute-api:us-east-1:${AWS::AccountId}:b5mli7qgp3/*/GET/api/publish/settings
- !Sub arn:aws:execute-api:us-east-1:${AWS::AccountId}:b5mli7qgp3/*/POST/api/publish/menu
- Effect: Allow
Action:
- s3:PutObject