docs(iam): qualify mgmt-only verification claims per cross-review round 2

This commit is contained in:
Adam Moussa 2026-07-31 13:46:29 -04:00
parent 08a1d41b05
commit 16a82c2a36
No known key found for this signature in database

View file

@ -284,8 +284,13 @@ Resources:
# each stack's own template (WIDENING PATH step 1). No Resource pattern in
# the floor above derives from this block.
#
# Permission sources per stack (verified live 2026-07-30; starting point
# only — verify every entry against the owning repo before use):
# Permission sources per stack (verified live 2026-07-30 IN MGMT — these
# stacks and resources do not exist in prod/dev yet, so nothing below is a
# prod/dev observation; starting point only — verify every entry against
# the owning repo before use. PARAMETERIZED resources (ARNs passed as
# deploy parameters) must be re-derived from the live stack configuration
# at migration time, as exact ARNs — never inferred from these names into
# broad patterns like secret:afi-*):
#
# afterhours-shift-manager (functions: afterhours-*, 6 live)
# - DynamoDB CRUD (afterhours-shifts table)
@ -307,7 +312,9 @@ Resources:
# ONLY this action)
# - CloudWatch Logs (all functions)
# - UNRESOLVED: /3cx-scheduler/* ownership (this stack vs. the retired
# standalone 3CX scheduler). Deliberately NOT granted. Resolve at migration.
# standalone 3CX scheduler). Deliberately NOT granted. Resolve at
# migration in that stack's own repo — do NOT add any 3cx-scheduler
# resource here until ownership is resolved.
#
# payments-dashboard (functions: payments-*)
# - DynamoDB CRUD / Read (PaymentsDashboard table — legacy PascalCase)
@ -338,7 +345,8 @@ Resources:
# - DynamoDB CRUD (front-sla-alerts table)
# - secretsmanager:GetSecretValue (front-integrations/*)
# - CloudWatch Logs
# - no S3 / SQS / SSM / SES / KMS / VPC
# - no IAM permissions for S3 / SQS / SSM / SES / KMS / VPC in this
# stack's template as of 2026-07-30
#
# afi-backup-monitor (functions: afi-*)
# - secretsmanager:GetSecretValue on TWO bare, unprefixed secrets: