mirror of
https://github.com/Sea-Haven-Industries/seahaven-org-baseline.git
synced 2026-10-05 14:01:57 +00:00
docs(iam): qualify mgmt-only verification claims per cross-review round 2
This commit is contained in:
parent
08a1d41b05
commit
16a82c2a36
1 changed files with 12 additions and 4 deletions
|
|
@ -284,8 +284,13 @@ Resources:
|
||||||
# each stack's own template (WIDENING PATH step 1). No Resource pattern in
|
# each stack's own template (WIDENING PATH step 1). No Resource pattern in
|
||||||
# the floor above derives from this block.
|
# the floor above derives from this block.
|
||||||
#
|
#
|
||||||
# Permission sources per stack (verified live 2026-07-30; starting point
|
# Permission sources per stack (verified live 2026-07-30 IN MGMT — these
|
||||||
# only — verify every entry against the owning repo before use):
|
# stacks and resources do not exist in prod/dev yet, so nothing below is a
|
||||||
|
# prod/dev observation; starting point only — verify every entry against
|
||||||
|
# the owning repo before use. PARAMETERIZED resources (ARNs passed as
|
||||||
|
# deploy parameters) must be re-derived from the live stack configuration
|
||||||
|
# at migration time, as exact ARNs — never inferred from these names into
|
||||||
|
# broad patterns like secret:afi-*):
|
||||||
#
|
#
|
||||||
# afterhours-shift-manager (functions: afterhours-*, 6 live)
|
# afterhours-shift-manager (functions: afterhours-*, 6 live)
|
||||||
# - DynamoDB CRUD (afterhours-shifts table)
|
# - DynamoDB CRUD (afterhours-shifts table)
|
||||||
|
|
@ -307,7 +312,9 @@ Resources:
|
||||||
# ONLY this action)
|
# ONLY this action)
|
||||||
# - CloudWatch Logs (all functions)
|
# - CloudWatch Logs (all functions)
|
||||||
# - UNRESOLVED: /3cx-scheduler/* ownership (this stack vs. the retired
|
# - UNRESOLVED: /3cx-scheduler/* ownership (this stack vs. the retired
|
||||||
# standalone 3CX scheduler). Deliberately NOT granted. Resolve at migration.
|
# standalone 3CX scheduler). Deliberately NOT granted. Resolve at
|
||||||
|
# migration in that stack's own repo — do NOT add any 3cx-scheduler
|
||||||
|
# resource here until ownership is resolved.
|
||||||
#
|
#
|
||||||
# payments-dashboard (functions: payments-*)
|
# payments-dashboard (functions: payments-*)
|
||||||
# - DynamoDB CRUD / Read (PaymentsDashboard table — legacy PascalCase)
|
# - DynamoDB CRUD / Read (PaymentsDashboard table — legacy PascalCase)
|
||||||
|
|
@ -338,7 +345,8 @@ Resources:
|
||||||
# - DynamoDB CRUD (front-sla-alerts table)
|
# - DynamoDB CRUD (front-sla-alerts table)
|
||||||
# - secretsmanager:GetSecretValue (front-integrations/*)
|
# - secretsmanager:GetSecretValue (front-integrations/*)
|
||||||
# - CloudWatch Logs
|
# - CloudWatch Logs
|
||||||
# - no S3 / SQS / SSM / SES / KMS / VPC
|
# - no IAM permissions for S3 / SQS / SSM / SES / KMS / VPC in this
|
||||||
|
# stack's template as of 2026-07-30
|
||||||
#
|
#
|
||||||
# afi-backup-monitor (functions: afi-*)
|
# afi-backup-monitor (functions: afi-*)
|
||||||
# - secretsmanager:GetSecretValue on TWO bare, unprefixed secrets:
|
# - secretsmanager:GetSecretValue on TWO bare, unprefixed secrets:
|
||||||
|
|
|
||||||
Loading…
Add table
Reference in a new issue