fix: complete IAM least-privilege sweep (sh-security-review)

HolidayRouter secrets scope afterhours-shift-manager/* -> /3cx-* (reads
only 3cx secrets); RingScheduler DynamoDBCrudPolicy -> DynamoDBReadPolicy
(read-only at runtime). SlackBot wildcard left as-is (reads across all
sub-prefixes; verified defensible).
This commit is contained in:
Adam Moussa 2026-06-17 12:17:43 -04:00
parent 401a561ae2
commit f6a1451216

View file

@ -250,7 +250,7 @@ Resources:
QUEUE_NUMBER: !Ref QueueNumber
TZ: !Ref Timezone
Policies:
- DynamoDBCrudPolicy:
- DynamoDBReadPolicy:
TableName: !Ref ShiftTable
- Statement:
# Least privilege: only the 3cx-* secrets this function reads.
@ -333,11 +333,12 @@ Resources:
- DynamoDBCrudPolicy:
TableName: !Ref ShiftTable
- Statement:
# Least privilege: only the 3cx-* secrets this function reads.
- Effect: Allow
Action:
- secretsmanager:GetSecretValue
Resource:
- !Sub "arn:aws:secretsmanager:${AWS::Region}:${AWS::AccountId}:secret:afterhours-shift-manager/*"
- !Sub "arn:aws:secretsmanager:${AWS::Region}:${AWS::AccountId}:secret:afterhours-shift-manager/3cx-*"
# Lambda error alarm for the holiday router. Mirrors the account-wide
# operational convention (Lambda-Errors-<fn>, threshold 1 over one 5-min