fix(infra): split hcptf apply policy and omit empty queue ARNs (PLAT-216)

The combined services inline policy exceeded 10KB, and an empty
checkcomponents ARN made CreatePolicy reject the Lambda boundary in dev.
This commit is contained in:
Adam Moussa 2026-09-21 15:41:56 -04:00
parent 593cab66ef
commit 35bd989882
No known key found for this signature in database
6 changed files with 59 additions and 35 deletions

View file

@ -562,6 +562,9 @@ data "aws_iam_policy_document" "hcptf_apply_services" {
resources = ["*"]
}
}
data "aws_iam_policy_document" "hcptf_apply_ecs" {
statement {
sid = "EcsWorkload"
effect = "Allow"
@ -1083,6 +1086,12 @@ resource "aws_iam_role_policy" "hcptf_apply_services" {
policy = data.aws_iam_policy_document.hcptf_apply_services.json
}
resource "aws_iam_role_policy" "hcptf_apply_ecs" {
name = "afterhours-shift-manager-ecs"
role = aws_iam_role.hcptf_apply.id
policy = data.aws_iam_policy_document.hcptf_apply_ecs.json
}
resource "aws_iam_role_policy" "hcptf_plan_refresh" {
name = "afterhours-shift-manager-plan-refresh"
role = aws_iam_role.hcptf_plan.id

View file

@ -96,11 +96,14 @@ data "aws_iam_policy_document" "ecs_task_boundary" {
resources = [aws_sqs_queue.jobs.arn]
}
statement {
sid = "CheckcomponentsSend"
effect = "Allow"
actions = ["sqs:SendMessage"]
resources = compact([var.checkcomponents_queue_arn])
dynamic "statement" {
for_each = var.checkcomponents_queue_arn == "" ? [] : [1]
content {
sid = "CheckcomponentsSend"
effect = "Allow"
actions = ["sqs:SendMessage"]
resources = [var.checkcomponents_queue_arn]
}
}
statement {

View file

@ -57,26 +57,30 @@ locals {
condition = null
},
]
weekly_post = [
{
sid = "DdbCrud"
actions = ["dynamodb:GetItem", "dynamodb:PutItem", "dynamodb:UpdateItem", "dynamodb:DeleteItem", "dynamodb:Query", "dynamodb:Scan", "dynamodb:BatchGetItem", "dynamodb:BatchWriteItem", "dynamodb:DescribeTable", "dynamodb:ConditionCheckItem"]
resources = [local.table_arn, "${local.table_arn}/*"]
condition = null
},
{
sid = "Secrets"
actions = ["secretsmanager:GetSecretValue"]
resources = ["arn:aws:secretsmanager:${var.aws_region}:${local.account_id}:secret:afterhours-shift-manager/slack-bot-token-*"]
condition = null
},
{
sid = "CheckcomponentsSend"
actions = ["sqs:SendMessage"]
resources = [var.checkcomponents_queue_arn]
condition = null
},
]
weekly_post = concat(
[
{
sid = "DdbCrud"
actions = ["dynamodb:GetItem", "dynamodb:PutItem", "dynamodb:UpdateItem", "dynamodb:DeleteItem", "dynamodb:Query", "dynamodb:Scan", "dynamodb:BatchGetItem", "dynamodb:BatchWriteItem", "dynamodb:DescribeTable", "dynamodb:ConditionCheckItem"]
resources = [local.table_arn, "${local.table_arn}/*"]
condition = null
},
{
sid = "Secrets"
actions = ["secretsmanager:GetSecretValue"]
resources = ["arn:aws:secretsmanager:${var.aws_region}:${local.account_id}:secret:afterhours-shift-manager/slack-bot-token-*"]
condition = null
},
],
var.checkcomponents_queue_arn == "" ? [] : [
{
sid = "CheckcomponentsSend"
actions = ["sqs:SendMessage"]
resources = [var.checkcomponents_queue_arn]
condition = null
},
],
),
roster_sync = [
{
sid = "DdbCrud"

View file

@ -121,15 +121,18 @@ data "aws_iam_policy_document" "lambda_boundary" {
]
}
statement {
sid = "AfterhoursCheckcomponentsSend"
effect = "Allow"
actions = [
"sqs:SendMessage",
]
resources = [
var.checkcomponents_queue_arn,
]
dynamic "statement" {
for_each = var.checkcomponents_queue_arn == "" ? [] : [1]
content {
sid = "AfterhoursCheckcomponentsSend"
effect = "Allow"
actions = [
"sqs:SendMessage",
]
resources = [
var.checkcomponents_queue_arn,
]
}
}
}

View file

@ -12,7 +12,10 @@ resource "aws_vpc" "this" {
}
# First apply updates the live hcptf apply role before CreateVpc.
depends_on = [aws_iam_role_policy.hcptf_apply_services]
depends_on = [
aws_iam_role_policy.hcptf_apply_services,
aws_iam_role_policy.hcptf_apply_ecs,
]
}
resource "aws_internet_gateway" "this" {

View file

@ -81,6 +81,8 @@ def test_stack_owns_a_vpc_instead_of_looking_up_default():
assert "aws_subnet.public[*].id" in ecs
assert "ec2:CreateVpc" in HCP_IAM
assert "sid = \"RefreshVpc\"" in HCP_IAM
assert "afterhours-shift-manager-ecs" in HCP_IAM
assert "hcptf_apply_ecs" in HCP_IAM
def test_deploy_api_workflow_exists():