From 697deb94fd2a16e6e306064ef0f809877548ec40 Mon Sep 17 00:00:00 2001 From: Adam Moussa <166072409+amoussa1229@users.noreply.github.com> Date: Mon, 21 Sep 2026 16:26:17 -0400 Subject: [PATCH] fix(iam): omit checkcomponents from the ECS boundary in non-prod (#202) --- terraform/iam.tf | 13 ++++++++----- tests/test_terraform_iam.py | 12 ++++++++++++ 2 files changed, 20 insertions(+), 5 deletions(-) create mode 100644 tests/test_terraform_iam.py diff --git a/terraform/iam.tf b/terraform/iam.tf index dbb9ac6..d8112cc 100644 --- a/terraform/iam.tf +++ b/terraform/iam.tf @@ -45,11 +45,14 @@ data "aws_iam_policy_document" "ecs_task_boundary" { resources = [aws_sqs_queue.jobs.arn] } - statement { - sid = "CheckcomponentsSend" - effect = "Allow" - actions = ["sqs:SendMessage"] - resources = compact([var.checkcomponents_queue_arn]) + dynamic "statement" { + for_each = var.checkcomponents_queue_arn == "" ? [] : [1] + content { + sid = "CheckcomponentsSend" + effect = "Allow" + actions = ["sqs:SendMessage"] + resources = [var.checkcomponents_queue_arn] + } } statement { diff --git a/tests/test_terraform_iam.py b/tests/test_terraform_iam.py new file mode 100644 index 0000000..de69433 --- /dev/null +++ b/tests/test_terraform_iam.py @@ -0,0 +1,12 @@ +"""ECS task boundary stays a valid IAM document when Paychex is unset.""" + +from pathlib import Path + +IAM = Path(__file__).resolve().parents[1] / "terraform" / "iam.tf" + + +def test_checkcomponents_send_omitted_when_queue_arn_empty(): + text = IAM.read_text() + assert "compact([var.checkcomponents_queue_arn])" not in text + assert 'for_each = var.checkcomponents_queue_arn == "" ? [] : [1]' in text + assert 'sid = "CheckcomponentsSend"' in text