Adam Moussa
|
c5c29b2bef
|
fix(iam): attach per-workload lambda permissions boundary (PLAT-52) (#148)
* fix(iam): attach per-workload lambda permissions boundary (PLAT-52)
* fix(iam): skip boundary delete on weekly-menu role (PLAT-52)
|
2026-08-20 16:02:46 -04:00 |
|
Adam Moussa
|
10c86f2de6
|
fix(apigateway): drop orphaned authorizer invoke role from state (#137)
Apply destroyed the inline policy then failed deleting the role on
iam:ListInstanceProfilesForRole; the role was removed out of band.
|
2026-08-10 17:48:05 -04:00 |
|
Adam Moussa
|
60abc9fb50
|
fix(apigateway): grant admin authorizer invoke via resource policy (#136)
Drop the broken AuthorizerCredentialsArn invoke role path that returned
500 without calling the authorizer, and adopt the live Lambda permission.
|
2026-08-10 17:17:51 -04:00 |
|
|
|
1519264da1
|
fix(iam): use literal GitHub OIDC provider ARN for weekly-menu role
|
2026-08-10 16:12:40 -04:00 |
|
|
|
3b9b9fb936
|
feat(iam): add prod weekly-menu GitHub OIDC role
|
2026-08-10 15:42:12 -04:00 |
|
|
|
5a00cc33fa
|
fix(cloudfront): defer custom domain alias until DNS cutover
|
2026-08-10 13:46:04 -04:00 |
|
|
|
1f67543f16
|
fix(ci): satisfy PR policy and authorizer trust constraints
Move weekly-menu step expressions into env blocks, terraform-fmt SES
alignment, and pin API Gateway authorizer invoke role assume conditions.
|
2026-08-07 19:33:49 -04:00 |
|
|
|
3906ad1885
|
fix(infra): assert google-client-id SSM exists at plan time
Wire the google_client_id data source into a check so apply fails closed when the OOB parameter is missing.
|
2026-08-07 19:28:25 -04:00 |
|
|
|
1728f6e408
|
fix(iam): scope SES SendRawEmail to verified identities
Constrain the email-report role to the sender and domain identity ARNs so the policy is not unconstrained write.
|
2026-08-07 19:21:45 -04:00 |
|
|
|
40ea4ed898
|
feat(infra): migrate meal-order-manager to HCP Terraform
Freeze SAM CD and add greenfield Terraform for seahaven-prod so HCP is the sole stack deploy path.
|
2026-08-07 19:19:51 -04:00 |
|