fix: complete IAM least-privilege sweep (sh-security-review)

HolidayRouter secrets scope afterhours-shift-manager/* -> /3cx-* (reads
only 3cx secrets); RingScheduler DynamoDBCrudPolicy -> DynamoDBReadPolicy
(read-only at runtime). SlackBot wildcard left as-is (reads across all
sub-prefixes; verified defensible).
This commit is contained in:
Adam Moussa 2026-06-17 12:17:43 -04:00
parent 401a561ae2
commit f6a1451216

View file

@ -250,7 +250,7 @@ Resources:
QUEUE_NUMBER: !Ref QueueNumber QUEUE_NUMBER: !Ref QueueNumber
TZ: !Ref Timezone TZ: !Ref Timezone
Policies: Policies:
- DynamoDBCrudPolicy: - DynamoDBReadPolicy:
TableName: !Ref ShiftTable TableName: !Ref ShiftTable
- Statement: - Statement:
# Least privilege: only the 3cx-* secrets this function reads. # Least privilege: only the 3cx-* secrets this function reads.
@ -333,11 +333,12 @@ Resources:
- DynamoDBCrudPolicy: - DynamoDBCrudPolicy:
TableName: !Ref ShiftTable TableName: !Ref ShiftTable
- Statement: - Statement:
# Least privilege: only the 3cx-* secrets this function reads.
- Effect: Allow - Effect: Allow
Action: Action:
- secretsmanager:GetSecretValue - secretsmanager:GetSecretValue
Resource: Resource:
- !Sub "arn:aws:secretsmanager:${AWS::Region}:${AWS::AccountId}:secret:afterhours-shift-manager/*" - !Sub "arn:aws:secretsmanager:${AWS::Region}:${AWS::AccountId}:secret:afterhours-shift-manager/3cx-*"
# Lambda error alarm for the holiday router. Mirrors the account-wide # Lambda error alarm for the holiday router. Mirrors the account-wide
# operational convention (Lambda-Errors-<fn>, threshold 1 over one 5-min # operational convention (Lambda-Errors-<fn>, threshold 1 over one 5-min