mirror of
https://github.com/Sea-Haven-Industries/afterhours-shift-manager.git
synced 2026-09-30 09:03:11 +00:00
fix(infra): split hcptf apply policy and omit empty queue ARNs (PLAT-216) (#261)
The combined services inline policy exceeded 10KB, and an empty checkcomponents ARN made CreatePolicy reject the Lambda boundary in dev.
This commit is contained in:
parent
593cab66ef
commit
d49c4bb4f2
6 changed files with 59 additions and 35 deletions
|
|
@ -562,6 +562,9 @@ data "aws_iam_policy_document" "hcptf_apply_services" {
|
|||
resources = ["*"]
|
||||
}
|
||||
|
||||
}
|
||||
|
||||
data "aws_iam_policy_document" "hcptf_apply_ecs" {
|
||||
statement {
|
||||
sid = "EcsWorkload"
|
||||
effect = "Allow"
|
||||
|
|
@ -1083,6 +1086,12 @@ resource "aws_iam_role_policy" "hcptf_apply_services" {
|
|||
policy = data.aws_iam_policy_document.hcptf_apply_services.json
|
||||
}
|
||||
|
||||
resource "aws_iam_role_policy" "hcptf_apply_ecs" {
|
||||
name = "afterhours-shift-manager-ecs"
|
||||
role = aws_iam_role.hcptf_apply.id
|
||||
policy = data.aws_iam_policy_document.hcptf_apply_ecs.json
|
||||
}
|
||||
|
||||
resource "aws_iam_role_policy" "hcptf_plan_refresh" {
|
||||
name = "afterhours-shift-manager-plan-refresh"
|
||||
role = aws_iam_role.hcptf_plan.id
|
||||
|
|
|
|||
|
|
@ -96,11 +96,14 @@ data "aws_iam_policy_document" "ecs_task_boundary" {
|
|||
resources = [aws_sqs_queue.jobs.arn]
|
||||
}
|
||||
|
||||
statement {
|
||||
sid = "CheckcomponentsSend"
|
||||
effect = "Allow"
|
||||
actions = ["sqs:SendMessage"]
|
||||
resources = compact([var.checkcomponents_queue_arn])
|
||||
dynamic "statement" {
|
||||
for_each = var.checkcomponents_queue_arn == "" ? [] : [1]
|
||||
content {
|
||||
sid = "CheckcomponentsSend"
|
||||
effect = "Allow"
|
||||
actions = ["sqs:SendMessage"]
|
||||
resources = [var.checkcomponents_queue_arn]
|
||||
}
|
||||
}
|
||||
|
||||
statement {
|
||||
|
|
|
|||
|
|
@ -57,26 +57,30 @@ locals {
|
|||
condition = null
|
||||
},
|
||||
]
|
||||
weekly_post = [
|
||||
{
|
||||
sid = "DdbCrud"
|
||||
actions = ["dynamodb:GetItem", "dynamodb:PutItem", "dynamodb:UpdateItem", "dynamodb:DeleteItem", "dynamodb:Query", "dynamodb:Scan", "dynamodb:BatchGetItem", "dynamodb:BatchWriteItem", "dynamodb:DescribeTable", "dynamodb:ConditionCheckItem"]
|
||||
resources = [local.table_arn, "${local.table_arn}/*"]
|
||||
condition = null
|
||||
},
|
||||
{
|
||||
sid = "Secrets"
|
||||
actions = ["secretsmanager:GetSecretValue"]
|
||||
resources = ["arn:aws:secretsmanager:${var.aws_region}:${local.account_id}:secret:afterhours-shift-manager/slack-bot-token-*"]
|
||||
condition = null
|
||||
},
|
||||
{
|
||||
sid = "CheckcomponentsSend"
|
||||
actions = ["sqs:SendMessage"]
|
||||
resources = [var.checkcomponents_queue_arn]
|
||||
condition = null
|
||||
},
|
||||
]
|
||||
weekly_post = concat(
|
||||
[
|
||||
{
|
||||
sid = "DdbCrud"
|
||||
actions = ["dynamodb:GetItem", "dynamodb:PutItem", "dynamodb:UpdateItem", "dynamodb:DeleteItem", "dynamodb:Query", "dynamodb:Scan", "dynamodb:BatchGetItem", "dynamodb:BatchWriteItem", "dynamodb:DescribeTable", "dynamodb:ConditionCheckItem"]
|
||||
resources = [local.table_arn, "${local.table_arn}/*"]
|
||||
condition = null
|
||||
},
|
||||
{
|
||||
sid = "Secrets"
|
||||
actions = ["secretsmanager:GetSecretValue"]
|
||||
resources = ["arn:aws:secretsmanager:${var.aws_region}:${local.account_id}:secret:afterhours-shift-manager/slack-bot-token-*"]
|
||||
condition = null
|
||||
},
|
||||
],
|
||||
var.checkcomponents_queue_arn == "" ? [] : [
|
||||
{
|
||||
sid = "CheckcomponentsSend"
|
||||
actions = ["sqs:SendMessage"]
|
||||
resources = [var.checkcomponents_queue_arn]
|
||||
condition = null
|
||||
},
|
||||
],
|
||||
),
|
||||
roster_sync = [
|
||||
{
|
||||
sid = "DdbCrud"
|
||||
|
|
|
|||
|
|
@ -121,15 +121,18 @@ data "aws_iam_policy_document" "lambda_boundary" {
|
|||
]
|
||||
}
|
||||
|
||||
statement {
|
||||
sid = "AfterhoursCheckcomponentsSend"
|
||||
effect = "Allow"
|
||||
actions = [
|
||||
"sqs:SendMessage",
|
||||
]
|
||||
resources = [
|
||||
var.checkcomponents_queue_arn,
|
||||
]
|
||||
dynamic "statement" {
|
||||
for_each = var.checkcomponents_queue_arn == "" ? [] : [1]
|
||||
content {
|
||||
sid = "AfterhoursCheckcomponentsSend"
|
||||
effect = "Allow"
|
||||
actions = [
|
||||
"sqs:SendMessage",
|
||||
]
|
||||
resources = [
|
||||
var.checkcomponents_queue_arn,
|
||||
]
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
|
|
|
|||
|
|
@ -12,7 +12,10 @@ resource "aws_vpc" "this" {
|
|||
}
|
||||
|
||||
# First apply updates the live hcptf apply role before CreateVpc.
|
||||
depends_on = [aws_iam_role_policy.hcptf_apply_services]
|
||||
depends_on = [
|
||||
aws_iam_role_policy.hcptf_apply_services,
|
||||
aws_iam_role_policy.hcptf_apply_ecs,
|
||||
]
|
||||
}
|
||||
|
||||
resource "aws_internet_gateway" "this" {
|
||||
|
|
|
|||
|
|
@ -81,6 +81,8 @@ def test_stack_owns_a_vpc_instead_of_looking_up_default():
|
|||
assert "aws_subnet.public[*].id" in ecs
|
||||
assert "ec2:CreateVpc" in HCP_IAM
|
||||
assert "sid = \"RefreshVpc\"" in HCP_IAM
|
||||
assert "afterhours-shift-manager-ecs" in HCP_IAM
|
||||
assert "hcptf_apply_ecs" in HCP_IAM
|
||||
|
||||
|
||||
def test_deploy_api_workflow_exists():
|
||||
|
|
|
|||
Loading…
Add table
Reference in a new issue