mirror of
https://github.com/Sea-Haven-Industries/meal-order-manager.git
synced 2026-10-07 16:18:54 +00:00
fix(iam): attach per-workload lambda permissions boundary (PLAT-52) (#148)
* fix(iam): attach per-workload lambda permissions boundary (PLAT-52) * fix(iam): skip boundary delete on weekly-menu role (PLAT-52)
This commit is contained in:
parent
a247f2f45a
commit
c5c29b2bef
3 changed files with 18 additions and 8 deletions
|
|
@ -1,10 +1,10 @@
|
||||||
# Execution roles for the seven Lambda functions plus the API Gateway role that
|
# Execution roles for the seven Lambda functions plus the API Gateway role that
|
||||||
# invokes the admin authorizer.
|
# invokes the admin authorizer.
|
||||||
#
|
#
|
||||||
# Every role is created under the /tf-managed/ path and carries the account's
|
# Every Lambda execution role is created under the /tf-managed/ path and
|
||||||
# seahaven-lambda-execution-boundary permissions boundary. The path is what
|
# carries seahaven-lambda-execution-boundary-meal-order-manager (PLAT-52).
|
||||||
# distinguishes Terraform-owned roles from the /cfn-managed/ roles the retired
|
# The path distinguishes Terraform-owned roles from the retired SAM
|
||||||
# SAM stack created.
|
# /cfn-managed/ roles.
|
||||||
#
|
#
|
||||||
# The inline policies below are hand-expanded from the SAM policy templates in
|
# The inline policies below are hand-expanded from the SAM policy templates in
|
||||||
# template.yaml (DynamoDBCrudPolicy, DynamoDBReadPolicy, S3CrudPolicy,
|
# template.yaml (DynamoDBCrudPolicy, DynamoDBReadPolicy, S3CrudPolicy,
|
||||||
|
|
|
||||||
|
|
@ -47,8 +47,18 @@ resource "aws_iam_role" "weekly_menu" {
|
||||||
path = "/tf-managed/"
|
path = "/tf-managed/"
|
||||||
description = "GitHub Actions weekly-menu scrape/publish for meal-order-manager"
|
description = "GitHub Actions weekly-menu scrape/publish for meal-order-manager"
|
||||||
assume_role_policy = data.aws_iam_policy_document.weekly_menu_assume.json
|
assume_role_policy = data.aws_iam_policy_document.weekly_menu_assume.json
|
||||||
permissions_boundary = local.boundary_arn
|
|
||||||
max_session_duration = 3600
|
max_session_duration = 3600
|
||||||
|
|
||||||
|
# Not a Lambda execution role. Config omits permissions_boundary so a later
|
||||||
|
# apply will not PutRolePermissionsBoundary the Lambda ceiling back. Live still
|
||||||
|
# has seahaven-lambda-execution-boundary; omitting without ignore_changes would
|
||||||
|
# plan DeleteRolePermissionsBoundary, which hcptf-meal-order-manager is denied
|
||||||
|
# (DenyBoundaryTampering). Ignore the attribute so this apply does not touch
|
||||||
|
# the ceiling. An administrator deletes the live attachment, then a follow-up
|
||||||
|
# drops this lifecycle after refresh-only updates state to null.
|
||||||
|
lifecycle {
|
||||||
|
ignore_changes = [permissions_boundary]
|
||||||
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
data "aws_iam_policy_document" "weekly_menu" {
|
data "aws_iam_policy_document" "weekly_menu" {
|
||||||
|
|
|
||||||
|
|
@ -2,9 +2,9 @@ locals {
|
||||||
project = "meal-order-manager"
|
project = "meal-order-manager"
|
||||||
account_id = "011934824531"
|
account_id = "011934824531"
|
||||||
|
|
||||||
# Every execution role in this configuration is created under /tf-managed/ and
|
# Lambda execution roles under /tf-managed/ carry the per-workload ceiling
|
||||||
# carries the account's Lambda execution boundary.
|
# (PLAT-52). githubdeploy-meal-order-manager-weekly-menu must not.
|
||||||
boundary_arn = "arn:aws:iam::${local.account_id}:policy/seahaven-lambda-execution-boundary"
|
boundary_arn = "arn:aws:iam::${local.account_id}:policy/seahaven-lambda-execution-boundary-meal-order-manager"
|
||||||
|
|
||||||
form_bucket_name = "${local.project}-form-${local.account_id}"
|
form_bucket_name = "${local.project}-form-${local.account_id}"
|
||||||
reports_bucket_name = "${local.project}-reports-${local.account_id}"
|
reports_bucket_name = "${local.project}-reports-${local.account_id}"
|
||||||
|
|
|
||||||
Loading…
Add table
Reference in a new issue