fix(iam): move hcptf apply grants off the 10KB inline quota

This commit is contained in:
Adam Moussa 2026-09-21 15:54:44 -04:00
parent 424b1ce1ac
commit cf9867adf7
No known key found for this signature in database
2 changed files with 41 additions and 33 deletions

View file

@ -24,11 +24,6 @@ import {
id = "hcptf-meal-order-manager-plan" id = "hcptf-meal-order-manager-plan"
} }
import {
to = aws_iam_role_policy.hcptf_apply_services
id = "hcptf-meal-order-manager:meal-order-manager-services"
}
import { import {
to = aws_iam_role_policy.hcptf_plan_refresh to = aws_iam_role_policy.hcptf_plan_refresh
id = "hcptf-meal-order-manager-plan:meal-order-manager-plan-refresh" id = "hcptf-meal-order-manager-plan:meal-order-manager-plan-refresh"
@ -319,33 +314,12 @@ data "aws_iam_policy_document" "hcptf_scoped_iam" {
} }
} }
resource "aws_iam_role_policy" "hcptf_apply_services" { resource "aws_iam_policy" "hcptf_apply_compute" {
name = "meal-order-manager-services" name = "meal-order-manager-apply-compute"
role = aws_iam_role.hcptf_apply.id path = "/tf-managed/"
policy = jsonencode({ policy = jsonencode({
Version = "2012-10-17" Version = "2012-10-17"
Statement = [ Statement = [
{
Action = [
"lambda:*",
]
Resource = [
"arn:aws:lambda:us-east-1:${local.account_id}:function:meal-order-manager-*",
"arn:aws:lambda:us-east-1:${local.account_id}:layer:meal-order-manager-*",
]
Effect = "Allow"
Sid = "LambdaAll"
},
{
Action = [
"lambda:ListFunctions",
"lambda:ListLayers",
"lambda:GetAccountSettings",
]
Resource = "*"
Effect = "Allow"
Sid = "LambdaList"
},
{ {
Action = [ Action = [
"ecs:*", "ecs:*",
@ -462,6 +436,37 @@ resource "aws_iam_role_policy" "hcptf_apply_services" {
Effect = "Allow" Effect = "Allow"
Sid = "SchedulerAccount" Sid = "SchedulerAccount"
}, },
]
})
}
resource "aws_iam_policy" "hcptf_apply_services" {
name = "meal-order-manager-apply-services"
path = "/tf-managed/"
policy = jsonencode({
Version = "2012-10-17"
Statement = [
{
Action = [
"lambda:*",
]
Resource = [
"arn:aws:lambda:us-east-1:${local.account_id}:function:meal-order-manager-*",
"arn:aws:lambda:us-east-1:${local.account_id}:layer:meal-order-manager-*",
]
Effect = "Allow"
Sid = "LambdaAll"
},
{
Action = [
"lambda:ListFunctions",
"lambda:ListLayers",
"lambda:GetAccountSettings",
]
Resource = "*"
Effect = "Allow"
Sid = "LambdaList"
},
{ {
Action = [ Action = [
"events:*", "events:*",
@ -1037,10 +1042,13 @@ resource "aws_iam_role" "hcptf_apply" {
} }
} }
# Empty exclusive set keeps seahaven-hcptf-iam-management detached. # Exclusive set keeps seahaven-hcptf-iam-management detached.
resource "aws_iam_role_policy_attachments_exclusive" "hcptf_apply" { resource "aws_iam_role_policy_attachments_exclusive" "hcptf_apply" {
role_name = aws_iam_role.hcptf_apply.name role_name = aws_iam_role.hcptf_apply.name
policy_arns = [] policy_arns = [
aws_iam_policy.hcptf_apply_services.arn,
aws_iam_policy.hcptf_apply_compute.arn,
]
} }
resource "aws_iam_role" "hcptf_plan" { resource "aws_iam_role" "hcptf_plan" {

View file

@ -13,7 +13,7 @@ resource "aws_vpc" "this" {
# First apply updates the live hcptf apply role before CreateVpc. # First apply updates the live hcptf apply role before CreateVpc.
depends_on = [ depends_on = [
aws_iam_role_policy.hcptf_apply_services, aws_iam_role_policy_attachments_exclusive.hcptf_apply,
aws_iam_role_policy.hcptf_apply_ec2, aws_iam_role_policy.hcptf_apply_ec2,
] ]
} }