From 8a0fc0b9a3ede69b0f4c91955f9c555e5541b21b Mon Sep 17 00:00:00 2001 From: Adam Moussa Date: Fri, 18 Sep 2026 13:27:07 -0400 Subject: [PATCH] fix(infra): drop prod-only authorizer import so dev can create it (PLAT-210) The PLAT-102 import is already in meal-order-manager-prod state. A shared import block fails in seahaven-dev because the permission does not exist there. --- terraform/apigateway.tf | 10 +++------- 1 file changed, 3 insertions(+), 7 deletions(-) diff --git a/terraform/apigateway.tf b/terraform/apigateway.tf index 007ed4a..05a8cbd 100644 --- a/terraform/apigateway.tf +++ b/terraform/apigateway.tf @@ -114,13 +114,9 @@ resource "aws_lambda_permission" "api_route" { # Grant API Gateway permission to invoke the admin authorizer Lambda. Source ARN # is the authorizer itself (not a route), matching the AWS HTTP API docs. -# Import adopts the PLAT-102 live hotfix statement so the first apply does not -# attempt a duplicate AddPermission. -import { - to = aws_lambda_permission.admin_authorizer - id = "meal-order-manager-admin-authorizer/AllowApiGatewayInvokeAuthorizer" -} - +# The PLAT-102 live hotfix was imported into meal-order-manager-prod state; do +# not keep a workspace-global import block or seahaven-dev cannot create this +# permission. resource "aws_lambda_permission" "admin_authorizer" { statement_id = "AllowApiGatewayInvokeAuthorizer" action = "lambda:InvokeFunction"