Fix module import, IAM permissions, and add manual test support

- Fix three_cx_client import path for Lambda packaging
- Expand SSM policy to include parent path and KMS decrypt for SecureString
- Add force flag to bypass 8am schedule check for manual invocations
- Add override_extension payload option for ad-hoc testing
- Update .gitignore for output.json and .DS_Store

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
This commit is contained in:
Adam Moussa 2026-04-03 17:40:58 -04:00
parent dc1d0bfe75
commit cb5817ce95
3 changed files with 22 additions and 5 deletions

2
.gitignore vendored
View file

@ -3,3 +3,5 @@ __pycache__/
.aws-sam/ .aws-sam/
.env .env
packaged.yaml packaged.yaml
output.json
.DS_Store

View file

@ -6,7 +6,7 @@ from datetime import datetime, timezone, timedelta
import boto3 import boto3
import yaml import yaml
from three_cx_client import ThreeCXClient from src.three_cx_client import ThreeCXClient
logger = logging.getLogger() logger = logging.getLogger()
logger.setLevel(logging.INFO) logger.setLevel(logging.INFO)
@ -67,12 +67,13 @@ def handler(event, context):
current_hour = now.hour current_hour = now.hour
logger.info("Running 3CX ring group scheduler at %s", now.isoformat()) logger.info("Running 3CX ring group scheduler at %s", now.isoformat())
if current_hour != 8: force = event.get("force", False)
if not force and current_hour != 8:
logger.info("Current ET hour is %d, not 8am — skipping (wrong DST rule fired)", current_hour) logger.info("Current ET hour is %d, not 8am — skipping (wrong DST rule fired)", current_hour)
return {"skipped": True, "reason": f"ET hour is {current_hour}, not 8"} return {"skipped": True, "reason": f"ET hour is {current_hour}, not 8"}
schedule = load_schedule() schedule = load_schedule()
extension = resolve_extension(schedule, now) extension = event.get("override_extension") or resolve_extension(schedule, now)
creds = get_3cx_credentials() creds = get_3cx_credentials()
client = ThreeCXClient( client = ThreeCXClient(

View file

@ -25,8 +25,22 @@ Resources:
SSM_PREFIX: /3cx-scheduler SSM_PREFIX: /3cx-scheduler
TZ: !Ref Timezone TZ: !Ref Timezone
Policies: Policies:
- SSMParameterWithSlashPrefixReadPolicy: - Statement:
ParameterName: 3cx-scheduler - Effect: Allow
Action:
- ssm:GetParametersByPath
- ssm:GetParameter
- ssm:GetParameters
Resource:
- !Sub "arn:aws:ssm:${AWS::Region}:${AWS::AccountId}:parameter/3cx-scheduler"
- !Sub "arn:aws:ssm:${AWS::Region}:${AWS::AccountId}:parameter/3cx-scheduler/*"
- Effect: Allow
Action:
- kms:Decrypt
Resource: "*"
Condition:
StringEquals:
"kms:ViaService": !Sub "ssm.${AWS::Region}.amazonaws.com"
Events: Events:
# EST: 8am ET = 13:00 UTC (Nov-Mar) # EST: 8am ET = 13:00 UTC (Nov-Mar)
DailyScheduleEST: DailyScheduleEST: