mirror of
https://github.com/Sea-Haven-Industries/afterhours-shift-manager.git
synced 2026-10-02 06:13:13 +00:00
Replace the mgmt SAM stack with a prod-only HCP workspace, in-repo hcptf IAM, stub Lambdas, and zip CD on push to main.
50 lines
1.5 KiB
HCL
50 lines
1.5 KiB
HCL
# EventBridge Scheduler execution role. slack-bot creates one-off holiday-*
|
|
# schedules at runtime; Terraform does not create those schedules.
|
|
|
|
data "aws_iam_policy_document" "holiday_scheduler_assume" {
|
|
statement {
|
|
sid = "SchedulerAssume"
|
|
effect = "Allow"
|
|
actions = ["sts:AssumeRole"]
|
|
|
|
principals {
|
|
type = "Service"
|
|
identifiers = ["scheduler.amazonaws.com"]
|
|
}
|
|
|
|
condition {
|
|
test = "StringEquals"
|
|
variable = "aws:SourceAccount"
|
|
values = [local.account_id]
|
|
}
|
|
|
|
condition {
|
|
test = "ArnLike"
|
|
variable = "aws:SourceArn"
|
|
values = ["arn:aws:scheduler:${var.aws_region}:${local.account_id}:schedule/default/holiday-*"]
|
|
}
|
|
}
|
|
}
|
|
|
|
resource "aws_iam_role" "holiday_scheduler" {
|
|
name = local.holiday_scheduler_role_name
|
|
path = "/tf-managed/"
|
|
description = "EventBridge Scheduler assumes this role to invoke afterhours-holiday-router"
|
|
assume_role_policy = data.aws_iam_policy_document.holiday_scheduler_assume.json
|
|
permissions_boundary = aws_iam_policy.lambda_boundary.arn
|
|
}
|
|
|
|
data "aws_iam_policy_document" "holiday_scheduler" {
|
|
statement {
|
|
sid = "InvokeHolidayRouter"
|
|
effect = "Allow"
|
|
actions = ["lambda:InvokeFunction"]
|
|
resources = [local.holiday_router_arn]
|
|
}
|
|
}
|
|
|
|
resource "aws_iam_role_policy" "holiday_scheduler" {
|
|
name = "invoke-holiday-router"
|
|
role = aws_iam_role.holiday_scheduler.id
|
|
policy = data.aws_iam_policy_document.holiday_scheduler.json
|
|
}
|