mirror of
https://github.com/Sea-Haven-Industries/afterhours-shift-manager.git
synced 2026-10-02 19:03:12 +00:00
51 lines
1.5 KiB
Terraform
51 lines
1.5 KiB
Terraform
|
|
# EventBridge Scheduler execution role. slack-bot creates one-off holiday-*
|
||
|
|
# schedules at runtime; Terraform does not create those schedules.
|
||
|
|
|
||
|
|
data "aws_iam_policy_document" "holiday_scheduler_assume" {
|
||
|
|
statement {
|
||
|
|
sid = "SchedulerAssume"
|
||
|
|
effect = "Allow"
|
||
|
|
actions = ["sts:AssumeRole"]
|
||
|
|
|
||
|
|
principals {
|
||
|
|
type = "Service"
|
||
|
|
identifiers = ["scheduler.amazonaws.com"]
|
||
|
|
}
|
||
|
|
|
||
|
|
condition {
|
||
|
|
test = "StringEquals"
|
||
|
|
variable = "aws:SourceAccount"
|
||
|
|
values = [local.account_id]
|
||
|
|
}
|
||
|
|
|
||
|
|
condition {
|
||
|
|
test = "ArnLike"
|
||
|
|
variable = "aws:SourceArn"
|
||
|
|
values = ["arn:aws:scheduler:${var.aws_region}:${local.account_id}:schedule/default/holiday-*"]
|
||
|
|
}
|
||
|
|
}
|
||
|
|
}
|
||
|
|
|
||
|
|
resource "aws_iam_role" "holiday_scheduler" {
|
||
|
|
name = local.holiday_scheduler_role_name
|
||
|
|
path = "/tf-managed/"
|
||
|
|
description = "EventBridge Scheduler assumes this role to invoke afterhours-holiday-router"
|
||
|
|
assume_role_policy = data.aws_iam_policy_document.holiday_scheduler_assume.json
|
||
|
|
permissions_boundary = aws_iam_policy.lambda_boundary.arn
|
||
|
|
}
|
||
|
|
|
||
|
|
data "aws_iam_policy_document" "holiday_scheduler" {
|
||
|
|
statement {
|
||
|
|
sid = "InvokeHolidayRouter"
|
||
|
|
effect = "Allow"
|
||
|
|
actions = ["lambda:InvokeFunction"]
|
||
|
|
resources = [local.holiday_router_arn]
|
||
|
|
}
|
||
|
|
}
|
||
|
|
|
||
|
|
resource "aws_iam_role_policy" "holiday_scheduler" {
|
||
|
|
name = "invoke-holiday-router"
|
||
|
|
role = aws_iam_role.holiday_scheduler.id
|
||
|
|
policy = data.aws_iam_policy_document.holiday_scheduler.json
|
||
|
|
}
|