From 2f5e5e6e663c566ca70b8c90d547dfcb2fd9ca81 Mon Sep 17 00:00:00 2001 From: Adam Moussa <166072409+amoussa1229@users.noreply.github.com> Date: Thu, 27 Aug 2026 23:03:35 +0000 Subject: [PATCH] fix(iam): drop unscoped door-unlock domain create (#127) CreateDomainName cannot be hostname-pinned, and mgmt still holds doorunlock.seahaven.com. Attach the domain at cutover instead of granting collection POST. --- .../terraform-substrate.template.yaml | 11 +++-------- 1 file changed, 3 insertions(+), 8 deletions(-) diff --git a/lib/terraform-substrate/terraform-substrate.template.yaml b/lib/terraform-substrate/terraform-substrate.template.yaml index c57747e..449cd94 100644 --- a/lib/terraform-substrate/terraform-substrate.template.yaml +++ b/lib/terraform-substrate/terraform-substrate.template.yaml @@ -2379,6 +2379,9 @@ Resources: - !Sub "arn:aws:s3:::door-unlock-api-artifacts-${AWS::AccountId}/*" # HTTP API ids are allocated at create (same as meal-order). # Custom domain is hostname-pinned like procurement-api. + # CreateDomainName POSTs to /domainnames and cannot be hostname-pinned; + # mgmt still holds doorunlock.seahaven.com, so the domain is attached + # at DNS cutover rather than granted as an unscoped collection POST. - Sid: HttpApiManage Effect: Allow Action: @@ -2387,14 +2390,6 @@ Resources: - !Sub "arn:aws:apigateway:us-east-1::/apis" - !Sub "arn:aws:apigateway:us-east-1::/apis/*" - !Sub "arn:aws:apigateway:us-east-1::/tags/*" - # CreateDomainName POSTs to the collection ARN. Hostname ARNs - # cover Get/Update/Delete and apiMappings after create. - - Sid: HttpApiDomainCreate - Effect: Allow - Action: - - apigateway:POST - Resource: - - arn:aws:apigateway:us-east-1::/domainnames - Sid: HttpApiDomain Effect: Allow Action: