docs(iam): qualify mgmt-only verification claims per cross-review round 2

This commit is contained in:
Adam Moussa 2026-07-31 13:46:29 -04:00
parent 08a1d41b05
commit 16a82c2a36
No known key found for this signature in database

View file

@ -284,8 +284,13 @@ Resources:
# each stack's own template (WIDENING PATH step 1). No Resource pattern in # each stack's own template (WIDENING PATH step 1). No Resource pattern in
# the floor above derives from this block. # the floor above derives from this block.
# #
# Permission sources per stack (verified live 2026-07-30; starting point # Permission sources per stack (verified live 2026-07-30 IN MGMT — these
# only — verify every entry against the owning repo before use): # stacks and resources do not exist in prod/dev yet, so nothing below is a
# prod/dev observation; starting point only — verify every entry against
# the owning repo before use. PARAMETERIZED resources (ARNs passed as
# deploy parameters) must be re-derived from the live stack configuration
# at migration time, as exact ARNs — never inferred from these names into
# broad patterns like secret:afi-*):
# #
# afterhours-shift-manager (functions: afterhours-*, 6 live) # afterhours-shift-manager (functions: afterhours-*, 6 live)
# - DynamoDB CRUD (afterhours-shifts table) # - DynamoDB CRUD (afterhours-shifts table)
@ -307,7 +312,9 @@ Resources:
# ONLY this action) # ONLY this action)
# - CloudWatch Logs (all functions) # - CloudWatch Logs (all functions)
# - UNRESOLVED: /3cx-scheduler/* ownership (this stack vs. the retired # - UNRESOLVED: /3cx-scheduler/* ownership (this stack vs. the retired
# standalone 3CX scheduler). Deliberately NOT granted. Resolve at migration. # standalone 3CX scheduler). Deliberately NOT granted. Resolve at
# migration in that stack's own repo — do NOT add any 3cx-scheduler
# resource here until ownership is resolved.
# #
# payments-dashboard (functions: payments-*) # payments-dashboard (functions: payments-*)
# - DynamoDB CRUD / Read (PaymentsDashboard table — legacy PascalCase) # - DynamoDB CRUD / Read (PaymentsDashboard table — legacy PascalCase)
@ -338,7 +345,8 @@ Resources:
# - DynamoDB CRUD (front-sla-alerts table) # - DynamoDB CRUD (front-sla-alerts table)
# - secretsmanager:GetSecretValue (front-integrations/*) # - secretsmanager:GetSecretValue (front-integrations/*)
# - CloudWatch Logs # - CloudWatch Logs
# - no S3 / SQS / SSM / SES / KMS / VPC # - no IAM permissions for S3 / SQS / SSM / SES / KMS / VPC in this
# stack's template as of 2026-07-30
# #
# afi-backup-monitor (functions: afi-*) # afi-backup-monitor (functions: afi-*)
# - secretsmanager:GetSecretValue on TWO bare, unprefixed secrets: # - secretsmanager:GetSecretValue on TWO bare, unprefixed secrets: