From f6a1451216db39bc55da22ec68c6a26b6623862f Mon Sep 17 00:00:00 2001 From: Adam Moussa Date: Wed, 17 Jun 2026 12:17:43 -0400 Subject: [PATCH] fix: complete IAM least-privilege sweep (sh-security-review) HolidayRouter secrets scope afterhours-shift-manager/* -> /3cx-* (reads only 3cx secrets); RingScheduler DynamoDBCrudPolicy -> DynamoDBReadPolicy (read-only at runtime). SlackBot wildcard left as-is (reads across all sub-prefixes; verified defensible). --- template.yaml | 5 +++-- 1 file changed, 3 insertions(+), 2 deletions(-) diff --git a/template.yaml b/template.yaml index 639c65e..e2532d4 100644 --- a/template.yaml +++ b/template.yaml @@ -250,7 +250,7 @@ Resources: QUEUE_NUMBER: !Ref QueueNumber TZ: !Ref Timezone Policies: - - DynamoDBCrudPolicy: + - DynamoDBReadPolicy: TableName: !Ref ShiftTable - Statement: # Least privilege: only the 3cx-* secrets this function reads. @@ -333,11 +333,12 @@ Resources: - DynamoDBCrudPolicy: TableName: !Ref ShiftTable - Statement: + # Least privilege: only the 3cx-* secrets this function reads. - Effect: Allow Action: - secretsmanager:GetSecretValue Resource: - - !Sub "arn:aws:secretsmanager:${AWS::Region}:${AWS::AccountId}:secret:afterhours-shift-manager/*" + - !Sub "arn:aws:secretsmanager:${AWS::Region}:${AWS::AccountId}:secret:afterhours-shift-manager/3cx-*" # Lambda error alarm for the holiday router. Mirrors the account-wide # operational convention (Lambda-Errors-, threshold 1 over one 5-min