From 16a82c2a360f94224290ff0fa6ecbce2f4c91cbd Mon Sep 17 00:00:00 2001 From: Adam Moussa Date: Fri, 31 Jul 2026 13:46:29 -0400 Subject: [PATCH] docs(iam): qualify mgmt-only verification claims per cross-review round 2 --- .../deploy-substrate.template.yaml | 16 ++++++++++++---- 1 file changed, 12 insertions(+), 4 deletions(-) diff --git a/lib/deploy-substrate/deploy-substrate.template.yaml b/lib/deploy-substrate/deploy-substrate.template.yaml index f966b9d..301af15 100644 --- a/lib/deploy-substrate/deploy-substrate.template.yaml +++ b/lib/deploy-substrate/deploy-substrate.template.yaml @@ -284,8 +284,13 @@ Resources: # each stack's own template (WIDENING PATH step 1). No Resource pattern in # the floor above derives from this block. # - # Permission sources per stack (verified live 2026-07-30; starting point - # only — verify every entry against the owning repo before use): + # Permission sources per stack (verified live 2026-07-30 IN MGMT — these + # stacks and resources do not exist in prod/dev yet, so nothing below is a + # prod/dev observation; starting point only — verify every entry against + # the owning repo before use. PARAMETERIZED resources (ARNs passed as + # deploy parameters) must be re-derived from the live stack configuration + # at migration time, as exact ARNs — never inferred from these names into + # broad patterns like secret:afi-*): # # afterhours-shift-manager (functions: afterhours-*, 6 live) # - DynamoDB CRUD (afterhours-shifts table) @@ -307,7 +312,9 @@ Resources: # ONLY this action) # - CloudWatch Logs (all functions) # - UNRESOLVED: /3cx-scheduler/* ownership (this stack vs. the retired - # standalone 3CX scheduler). Deliberately NOT granted. Resolve at migration. + # standalone 3CX scheduler). Deliberately NOT granted. Resolve at + # migration in that stack's own repo — do NOT add any 3cx-scheduler + # resource here until ownership is resolved. # # payments-dashboard (functions: payments-*) # - DynamoDB CRUD / Read (PaymentsDashboard table — legacy PascalCase) @@ -338,7 +345,8 @@ Resources: # - DynamoDB CRUD (front-sla-alerts table) # - secretsmanager:GetSecretValue (front-integrations/*) # - CloudWatch Logs - # - no S3 / SQS / SSM / SES / KMS / VPC + # - no IAM permissions for S3 / SQS / SSM / SES / KMS / VPC in this + # stack's template as of 2026-07-30 # # afi-backup-monitor (functions: afi-*) # - secretsmanager:GetSecretValue on TWO bare, unprefixed secrets: