fix(iam): drop unscoped door-unlock domain create (#127)

CreateDomainName cannot be hostname-pinned, and mgmt still holds doorunlock.seahaven.com. Attach the domain at cutover instead of granting collection POST.
This commit is contained in:
Adam Moussa 2026-08-27 23:03:35 +00:00 • committed by GitHub
parent 23d954369d
commit 2f5e5e6e66
No known key found for this signature in database
GPG key ID: B5690EEEBB952194

View file

@ -2379,6 +2379,9 @@ Resources:
- !Sub "arn:aws:s3:::door-unlock-api-artifacts-${AWS::AccountId}/*" - !Sub "arn:aws:s3:::door-unlock-api-artifacts-${AWS::AccountId}/*"
# HTTP API ids are allocated at create (same as meal-order). # HTTP API ids are allocated at create (same as meal-order).
# Custom domain is hostname-pinned like procurement-api. # Custom domain is hostname-pinned like procurement-api.
# CreateDomainName POSTs to /domainnames and cannot be hostname-pinned;
# mgmt still holds doorunlock.seahaven.com, so the domain is attached
# at DNS cutover rather than granted as an unscoped collection POST.
- Sid: HttpApiManage - Sid: HttpApiManage
Effect: Allow Effect: Allow
Action: Action:
@ -2387,14 +2390,6 @@ Resources:
- !Sub "arn:aws:apigateway:us-east-1::/apis" - !Sub "arn:aws:apigateway:us-east-1::/apis"
- !Sub "arn:aws:apigateway:us-east-1::/apis/*" - !Sub "arn:aws:apigateway:us-east-1::/apis/*"
- !Sub "arn:aws:apigateway:us-east-1::/tags/*" - !Sub "arn:aws:apigateway:us-east-1::/tags/*"
# CreateDomainName POSTs to the collection ARN. Hostname ARNs
# cover Get/Update/Delete and apiMappings after create.
- Sid: HttpApiDomainCreate
Effect: Allow
Action:
- apigateway:POST
Resource:
- arn:aws:apigateway:us-east-1::/domainnames
- Sid: HttpApiDomain - Sid: HttpApiDomain
Effect: Allow Effect: Allow
Action: Action: