fix(iam): scope SES SendRawEmail to verified identities

Constrain the email-report role to the sender and domain identity ARNs so the policy is not unconstrained write.
This commit is contained in:
Adam Moussa 2026-08-07 19:21:45 -04:00
parent 40ea4ed898
commit 1728f6e408
No known key found for this signature in database

View file

@ -388,14 +388,16 @@ data "aws_iam_policy_document" "email_report" {
resources = [aws_s3_bucket.reports.arn]
}
# SES does not support resource-level permissions for SendRawEmail; the
# sender identity is enforced by SES verification, not IAM. Matches
# template.yaml.
# Scope SendRawEmail to the verified sender domain/identity rather than "*".
# SES still enforces verification; IAM pins the From identity ARNs.
statement {
sid = "SendPayrollReport"
effect = "Allow"
actions = ["ses:SendRawEmail"]
resources = ["*"]
sid = "SendPayrollReport"
effect = "Allow"
actions = ["ses:SendRawEmail"]
resources = [
"arn:aws:ses:${var.aws_region}:${local.account_id}:identity/${var.sender_email}",
"arn:aws:ses:${var.aws_region}:${local.account_id}:identity/seahavenind.com",
]
}
}