mirror of
https://github.com/Sea-Haven-Industries/afterhours-shift-manager.git
synced 2026-10-04 00:53:13 +00:00
Scope shift-manager Lambda IAM to least privilege
The nightly sweep flagged four over-broad permissions. Scope each to only what the function actually reads (verified against source): - WeeklyPost: secrets to slack-bot-token-* only (was the whole afterhours-shift-manager/* namespace); SES SendEmail to the single noreply@seahaven.com identity (was identity/*). - RosterSync and RingScheduler: secrets to 3cx-* only (was the whole namespace); both read only the 3cx domain/client-id/client-secret. SlackBotFunction and HolidayRouter wildcards are left unchanged — out of scope for this sweep. Refs: INFRA
This commit is contained in:
parent
43bfbf34c2
commit
03ea8cbdd8
1 changed files with 9 additions and 4 deletions
|
|
@ -156,16 +156,19 @@ Resources:
|
||||||
- DynamoDBCrudPolicy:
|
- DynamoDBCrudPolicy:
|
||||||
TableName: !Ref ShiftTable
|
TableName: !Ref ShiftTable
|
||||||
- Statement:
|
- Statement:
|
||||||
|
# Least privilege: only the Slack bot token, not the whole namespace.
|
||||||
- Effect: Allow
|
- Effect: Allow
|
||||||
Action:
|
Action:
|
||||||
- secretsmanager:GetSecretValue
|
- secretsmanager:GetSecretValue
|
||||||
Resource:
|
Resource:
|
||||||
- !Sub "arn:aws:secretsmanager:${AWS::Region}:${AWS::AccountId}:secret:afterhours-shift-manager/*"
|
- !Sub "arn:aws:secretsmanager:${AWS::Region}:${AWS::AccountId}:secret:afterhours-shift-manager/slack-bot-token-*"
|
||||||
- Effect: Allow
|
- Effect: Allow
|
||||||
Action:
|
Action:
|
||||||
- ses:SendEmail
|
- ses:SendEmail
|
||||||
Resource:
|
Resource:
|
||||||
- !Sub "arn:aws:ses:${AWS::Region}:${AWS::AccountId}:identity/*"
|
# Only the single sending identity (noreply@seahaven.com), not
|
||||||
|
# every identity in the account.
|
||||||
|
- !Sub "arn:aws:ses:${AWS::Region}:${AWS::AccountId}:identity/noreply@seahaven.com"
|
||||||
# The sending identity has a default configuration set
|
# The sending identity has a default configuration set
|
||||||
# (seahaven-email-events); SES authorizes SendEmail against the
|
# (seahaven-email-events); SES authorizes SendEmail against the
|
||||||
# config-set resource too, so it must be granted alongside the
|
# config-set resource too, so it must be granted alongside the
|
||||||
|
|
@ -207,11 +210,12 @@ Resources:
|
||||||
- DynamoDBCrudPolicy:
|
- DynamoDBCrudPolicy:
|
||||||
TableName: !Ref ShiftTable
|
TableName: !Ref ShiftTable
|
||||||
- Statement:
|
- Statement:
|
||||||
|
# Least privilege: only the 3cx-* secrets this function reads.
|
||||||
- Effect: Allow
|
- Effect: Allow
|
||||||
Action:
|
Action:
|
||||||
- secretsmanager:GetSecretValue
|
- secretsmanager:GetSecretValue
|
||||||
Resource:
|
Resource:
|
||||||
- !Sub "arn:aws:secretsmanager:${AWS::Region}:${AWS::AccountId}:secret:afterhours-shift-manager/*"
|
- !Sub "arn:aws:secretsmanager:${AWS::Region}:${AWS::AccountId}:secret:afterhours-shift-manager/3cx-*"
|
||||||
Events:
|
Events:
|
||||||
# Daily at 6am ET (before the 7am schedule post and 8am 3CX scheduler)
|
# Daily at 6am ET (before the 7am schedule post and 8am 3CX scheduler)
|
||||||
# EST: 6am ET = 11:00 UTC (Nov-Mar)
|
# EST: 6am ET = 11:00 UTC (Nov-Mar)
|
||||||
|
|
@ -249,11 +253,12 @@ Resources:
|
||||||
- DynamoDBCrudPolicy:
|
- DynamoDBCrudPolicy:
|
||||||
TableName: !Ref ShiftTable
|
TableName: !Ref ShiftTable
|
||||||
- Statement:
|
- Statement:
|
||||||
|
# Least privilege: only the 3cx-* secrets this function reads.
|
||||||
- Effect: Allow
|
- Effect: Allow
|
||||||
Action:
|
Action:
|
||||||
- secretsmanager:GetSecretValue
|
- secretsmanager:GetSecretValue
|
||||||
Resource:
|
Resource:
|
||||||
- !Sub "arn:aws:secretsmanager:${AWS::Region}:${AWS::AccountId}:secret:afterhours-shift-manager/*"
|
- !Sub "arn:aws:secretsmanager:${AWS::Region}:${AWS::AccountId}:secret:afterhours-shift-manager/3cx-*"
|
||||||
Events:
|
Events:
|
||||||
# Daily at 8am ET — update after-hours routing
|
# Daily at 8am ET — update after-hours routing
|
||||||
DailyScheduleEST:
|
DailyScheduleEST:
|
||||||
|
|
|
||||||
Loading…
Add table
Reference in a new issue