diff --git a/terraform/iam.tf b/terraform/iam.tf index 94139f5..3bb8f16 100644 --- a/terraform/iam.tf +++ b/terraform/iam.tf @@ -1,10 +1,10 @@ # Execution roles for the seven Lambda functions plus the API Gateway role that # invokes the admin authorizer. # -# Every role is created under the /tf-managed/ path and carries the account's -# seahaven-lambda-execution-boundary permissions boundary. The path is what -# distinguishes Terraform-owned roles from the /cfn-managed/ roles the retired -# SAM stack created. +# Every Lambda execution role is created under the /tf-managed/ path and +# carries seahaven-lambda-execution-boundary-meal-order-manager (PLAT-52). +# The path distinguishes Terraform-owned roles from the retired SAM +# /cfn-managed/ roles. # # The inline policies below are hand-expanded from the SAM policy templates in # template.yaml (DynamoDBCrudPolicy, DynamoDBReadPolicy, S3CrudPolicy, diff --git a/terraform/iam_github_weekly_menu.tf b/terraform/iam_github_weekly_menu.tf index 21001f2..4596b22 100644 --- a/terraform/iam_github_weekly_menu.tf +++ b/terraform/iam_github_weekly_menu.tf @@ -47,8 +47,18 @@ resource "aws_iam_role" "weekly_menu" { path = "/tf-managed/" description = "GitHub Actions weekly-menu scrape/publish for meal-order-manager" assume_role_policy = data.aws_iam_policy_document.weekly_menu_assume.json - permissions_boundary = local.boundary_arn max_session_duration = 3600 + + # Not a Lambda execution role. Config omits permissions_boundary so a later + # apply will not PutRolePermissionsBoundary the Lambda ceiling back. Live still + # has seahaven-lambda-execution-boundary; omitting without ignore_changes would + # plan DeleteRolePermissionsBoundary, which hcptf-meal-order-manager is denied + # (DenyBoundaryTampering). Ignore the attribute so this apply does not touch + # the ceiling. An administrator deletes the live attachment, then a follow-up + # drops this lifecycle after refresh-only updates state to null. + lifecycle { + ignore_changes = [permissions_boundary] + } } data "aws_iam_policy_document" "weekly_menu" { diff --git a/terraform/locals.tf b/terraform/locals.tf index a8d48c1..bfa22f1 100644 --- a/terraform/locals.tf +++ b/terraform/locals.tf @@ -2,9 +2,9 @@ locals { project = "meal-order-manager" account_id = "011934824531" - # Every execution role in this configuration is created under /tf-managed/ and - # carries the account's Lambda execution boundary. - boundary_arn = "arn:aws:iam::${local.account_id}:policy/seahaven-lambda-execution-boundary" + # Lambda execution roles under /tf-managed/ carry the per-workload ceiling + # (PLAT-52). githubdeploy-meal-order-manager-weekly-menu must not. + boundary_arn = "arn:aws:iam::${local.account_id}:policy/seahaven-lambda-execution-boundary-meal-order-manager" form_bucket_name = "${local.project}-form-${local.account_id}" reports_bucket_name = "${local.project}-reports-${local.account_id}"