# Per-workload Lambda permissions boundary. Created on the first (bootstrap) # apply. The scoped apply role denies iam:CreatePolicy / CreatePolicyVersion, # so later edits to this document need the hcptf-bootstrap window. data "aws_iam_policy_document" "lambda_boundary" { statement { sid = "CloudWatchLogsWrite" effect = "Allow" actions = [ "logs:CreateLogGroup", "logs:CreateLogStream", "logs:PutLogEvents", "logs:DescribeLogStreams", ] resources = [ "arn:aws:logs:${var.aws_region}:${local.account_id}:log-group:/aws/lambda*", ] } statement { sid = "CloudWatchLogsDescribe" effect = "Allow" actions = ["logs:DescribeLogGroups"] resources = ["*"] } statement { sid = "XRay" effect = "Allow" actions = [ "xray:PutTraceSegments", "xray:PutTelemetryRecords", ] resources = ["*"] } statement { sid = "Ec2Eni" effect = "Allow" actions = [ "ec2:CreateNetworkInterface", "ec2:DescribeNetworkInterfaces", "ec2:DeleteNetworkInterface", "ec2:DescribeSubnets", "ec2:DescribeSecurityGroups", "ec2:DescribeVpcs", ] resources = ["*"] } statement { sid = "AfterhoursSecrets" effect = "Allow" actions = [ "secretsmanager:GetSecretValue", ] resources = [ "arn:aws:secretsmanager:${var.aws_region}:${local.account_id}:secret:afterhours-shift-manager/*", ] } statement { sid = "AfterhoursDynamoDB" effect = "Allow" actions = [ "dynamodb:GetItem", "dynamodb:PutItem", "dynamodb:UpdateItem", "dynamodb:DeleteItem", "dynamodb:Query", "dynamodb:Scan", "dynamodb:BatchGetItem", "dynamodb:BatchWriteItem", "dynamodb:DescribeTable", "dynamodb:ConditionCheckItem", ] resources = [ "arn:aws:dynamodb:${var.aws_region}:${local.account_id}:table/${local.table_name}", "arn:aws:dynamodb:${var.aws_region}:${local.account_id}:table/${local.table_name}/*", ] } statement { sid = "AfterhoursScheduler" effect = "Allow" actions = [ "scheduler:CreateSchedule", "scheduler:DeleteSchedule", "scheduler:GetSchedule", ] resources = [ "arn:aws:scheduler:${var.aws_region}:${local.account_id}:schedule/default/holiday-*", ] } statement { sid = "AfterhoursPassRoleScheduler" effect = "Allow" actions = [ "iam:PassRole", ] resources = [ "arn:aws:iam::${local.account_id}:role/tf-managed/afterhours-shift-manager-holiday-scheduler", ] condition { test = "StringEquals" variable = "iam:PassedToService" values = ["scheduler.amazonaws.com"] } } statement { sid = "AfterhoursInvokeHolidayRouter" effect = "Allow" actions = [ "lambda:InvokeFunction", ] resources = [ "arn:aws:lambda:${var.aws_region}:${local.account_id}:function:afterhours-holiday-router", ] } statement { sid = "AfterhoursCheckcomponentsSend" effect = "Allow" actions = [ "sqs:SendMessage", ] resources = [ var.checkcomponents_queue_arn, ] } } resource "aws_iam_policy" "lambda_boundary" { name = "afterhours-shift-manager-lambda-boundary" path = "/tf-managed/" description = "Per-workload Lambda permissions boundary for afterhours-shift-manager (PLAT-74)." policy = data.aws_iam_policy_document.lambda_boundary.json }