mirror of
https://github.com/Sea-Haven-Industries/seahaven-org-baseline.git
synced 2026-09-30 08:03:19 +00:00
docs(iam): qualify mgmt-only verification claims per cross-review round 2
This commit is contained in:
parent
08a1d41b05
commit
16a82c2a36
1 changed files with 12 additions and 4 deletions
|
|
@ -284,8 +284,13 @@ Resources:
|
|||
# each stack's own template (WIDENING PATH step 1). No Resource pattern in
|
||||
# the floor above derives from this block.
|
||||
#
|
||||
# Permission sources per stack (verified live 2026-07-30; starting point
|
||||
# only — verify every entry against the owning repo before use):
|
||||
# Permission sources per stack (verified live 2026-07-30 IN MGMT — these
|
||||
# stacks and resources do not exist in prod/dev yet, so nothing below is a
|
||||
# prod/dev observation; starting point only — verify every entry against
|
||||
# the owning repo before use. PARAMETERIZED resources (ARNs passed as
|
||||
# deploy parameters) must be re-derived from the live stack configuration
|
||||
# at migration time, as exact ARNs — never inferred from these names into
|
||||
# broad patterns like secret:afi-*):
|
||||
#
|
||||
# afterhours-shift-manager (functions: afterhours-*, 6 live)
|
||||
# - DynamoDB CRUD (afterhours-shifts table)
|
||||
|
|
@ -307,7 +312,9 @@ Resources:
|
|||
# ONLY this action)
|
||||
# - CloudWatch Logs (all functions)
|
||||
# - UNRESOLVED: /3cx-scheduler/* ownership (this stack vs. the retired
|
||||
# standalone 3CX scheduler). Deliberately NOT granted. Resolve at migration.
|
||||
# standalone 3CX scheduler). Deliberately NOT granted. Resolve at
|
||||
# migration in that stack's own repo — do NOT add any 3cx-scheduler
|
||||
# resource here until ownership is resolved.
|
||||
#
|
||||
# payments-dashboard (functions: payments-*)
|
||||
# - DynamoDB CRUD / Read (PaymentsDashboard table — legacy PascalCase)
|
||||
|
|
@ -338,7 +345,8 @@ Resources:
|
|||
# - DynamoDB CRUD (front-sla-alerts table)
|
||||
# - secretsmanager:GetSecretValue (front-integrations/*)
|
||||
# - CloudWatch Logs
|
||||
# - no S3 / SQS / SSM / SES / KMS / VPC
|
||||
# - no IAM permissions for S3 / SQS / SSM / SES / KMS / VPC in this
|
||||
# stack's template as of 2026-07-30
|
||||
#
|
||||
# afi-backup-monitor (functions: afi-*)
|
||||
# - secretsmanager:GetSecretValue on TWO bare, unprefixed secrets:
|
||||
|
|
|
|||
Loading…
Add table
Reference in a new issue