mirror of
https://github.com/Sea-Haven-Industries/afterhours-shift-manager.git
synced 2026-09-30 11:23:12 +00:00
Some checks are pending
Deploy / Deploy to prod (push) Waiting to run
* fix(cutover): write Slack secrets into empty Terraform shells DescribeSecret succeeds on HCP-created shells with no version, so skip-if-exists left roster and Slack tokens unset. * feat(infra): migrate afterhours to HCP Terraform (PLAT-74) Replace the mgmt SAM stack with a prod-only HCP workspace, in-repo hcptf IAM, stub Lambdas, and zip CD on push to main. * fix(cutover): retry DDB unprocessed items and skip past at() holidays Unprocessed BatchWriteItem rows and leftover past at() schedules would drop roster data or abort holiday recreation during prod cutover.
141 lines
3.5 KiB
HCL
141 lines
3.5 KiB
HCL
# Per-workload Lambda permissions boundary. Created on the first (bootstrap)
|
|
# apply. The scoped apply role denies iam:CreatePolicy / CreatePolicyVersion,
|
|
# so later edits to this document need the hcptf-bootstrap window.
|
|
|
|
data "aws_iam_policy_document" "lambda_boundary" {
|
|
statement {
|
|
sid = "CloudWatchLogsWrite"
|
|
effect = "Allow"
|
|
actions = [
|
|
"logs:CreateLogGroup",
|
|
"logs:CreateLogStream",
|
|
"logs:PutLogEvents",
|
|
"logs:DescribeLogStreams",
|
|
]
|
|
resources = [
|
|
"arn:aws:logs:${var.aws_region}:${local.account_id}:log-group:/aws/lambda*",
|
|
]
|
|
}
|
|
|
|
statement {
|
|
sid = "CloudWatchLogsDescribe"
|
|
effect = "Allow"
|
|
actions = ["logs:DescribeLogGroups"]
|
|
resources = ["*"]
|
|
}
|
|
|
|
statement {
|
|
sid = "XRay"
|
|
effect = "Allow"
|
|
actions = [
|
|
"xray:PutTraceSegments",
|
|
"xray:PutTelemetryRecords",
|
|
]
|
|
resources = ["*"]
|
|
}
|
|
|
|
statement {
|
|
sid = "Ec2Eni"
|
|
effect = "Allow"
|
|
actions = [
|
|
"ec2:CreateNetworkInterface",
|
|
"ec2:DescribeNetworkInterfaces",
|
|
"ec2:DeleteNetworkInterface",
|
|
"ec2:DescribeSubnets",
|
|
"ec2:DescribeSecurityGroups",
|
|
"ec2:DescribeVpcs",
|
|
]
|
|
resources = ["*"]
|
|
}
|
|
|
|
statement {
|
|
sid = "AfterhoursSecrets"
|
|
effect = "Allow"
|
|
actions = [
|
|
"secretsmanager:GetSecretValue",
|
|
]
|
|
resources = [
|
|
"arn:aws:secretsmanager:${var.aws_region}:${local.account_id}:secret:afterhours-shift-manager/*",
|
|
]
|
|
}
|
|
|
|
statement {
|
|
sid = "AfterhoursDynamoDB"
|
|
effect = "Allow"
|
|
actions = [
|
|
"dynamodb:GetItem",
|
|
"dynamodb:PutItem",
|
|
"dynamodb:UpdateItem",
|
|
"dynamodb:DeleteItem",
|
|
"dynamodb:Query",
|
|
"dynamodb:Scan",
|
|
"dynamodb:BatchGetItem",
|
|
"dynamodb:BatchWriteItem",
|
|
"dynamodb:DescribeTable",
|
|
"dynamodb:ConditionCheckItem",
|
|
]
|
|
resources = [
|
|
"arn:aws:dynamodb:${var.aws_region}:${local.account_id}:table/${local.table_name}",
|
|
"arn:aws:dynamodb:${var.aws_region}:${local.account_id}:table/${local.table_name}/*",
|
|
]
|
|
}
|
|
|
|
statement {
|
|
sid = "AfterhoursScheduler"
|
|
effect = "Allow"
|
|
actions = [
|
|
"scheduler:CreateSchedule",
|
|
"scheduler:DeleteSchedule",
|
|
"scheduler:GetSchedule",
|
|
]
|
|
resources = [
|
|
"arn:aws:scheduler:${var.aws_region}:${local.account_id}:schedule/default/holiday-*",
|
|
]
|
|
}
|
|
|
|
statement {
|
|
sid = "AfterhoursPassRoleScheduler"
|
|
effect = "Allow"
|
|
actions = [
|
|
"iam:PassRole",
|
|
]
|
|
resources = [
|
|
"arn:aws:iam::${local.account_id}:role/tf-managed/afterhours-shift-manager-holiday-scheduler",
|
|
]
|
|
|
|
condition {
|
|
test = "StringEquals"
|
|
variable = "iam:PassedToService"
|
|
values = ["scheduler.amazonaws.com"]
|
|
}
|
|
}
|
|
|
|
statement {
|
|
sid = "AfterhoursInvokeHolidayRouter"
|
|
effect = "Allow"
|
|
actions = [
|
|
"lambda:InvokeFunction",
|
|
]
|
|
resources = [
|
|
"arn:aws:lambda:${var.aws_region}:${local.account_id}:function:afterhours-holiday-router",
|
|
]
|
|
}
|
|
|
|
statement {
|
|
sid = "AfterhoursCheckcomponentsSend"
|
|
effect = "Allow"
|
|
actions = [
|
|
"sqs:SendMessage",
|
|
]
|
|
resources = [
|
|
var.checkcomponents_queue_arn,
|
|
]
|
|
}
|
|
}
|
|
|
|
resource "aws_iam_policy" "lambda_boundary" {
|
|
name = "afterhours-shift-manager-lambda-boundary"
|
|
path = "/tf-managed/"
|
|
description = "Per-workload Lambda permissions boundary for afterhours-shift-manager (PLAT-74)."
|
|
policy = data.aws_iam_policy_document.lambda_boundary.json
|
|
}
|