Commit graph

5 commits

Author SHA1 Message Date
b91d7f3745
fix(iam): attach per-workload lambda permissions boundary (PLAT-52) 2026-08-20 14:31:28 -04:00
Adam Moussa
60abc9fb50
fix(apigateway): grant admin authorizer invoke via resource policy (#136)
Drop the broken AuthorizerCredentialsArn invoke role path that returned
500 without calling the authorizer, and adopt the live Lambda permission.
2026-08-10 17:17:51 -04:00
1f67543f16
fix(ci): satisfy PR policy and authorizer trust constraints
Move weekly-menu step expressions into env blocks, terraform-fmt SES
alignment, and pin API Gateway authorizer invoke role assume conditions.
2026-08-07 19:33:49 -04:00
1728f6e408
fix(iam): scope SES SendRawEmail to verified identities
Constrain the email-report role to the sender and domain identity ARNs so the policy is not unconstrained write.
2026-08-07 19:21:45 -04:00
40ea4ed898
feat(infra): migrate meal-order-manager to HCP Terraform
Freeze SAM CD and add greenfield Terraform for seahaven-prod so HCP is the sole stack deploy path.
2026-08-07 19:19:51 -04:00