mirror of
https://github.com/Sea-Haven-Industries/seahaven-org-baseline.git
synced 2026-09-30 06:53:17 +00:00
fix(iam): drop unscoped door-unlock domain create (#127)
CreateDomainName cannot be hostname-pinned, and mgmt still holds doorunlock.seahaven.com. Attach the domain at cutover instead of granting collection POST.
This commit is contained in:
parent
23d954369d
commit
2f5e5e6e66
1 changed files with 3 additions and 8 deletions
|
|
@ -2379,6 +2379,9 @@ Resources:
|
|||
- !Sub "arn:aws:s3:::door-unlock-api-artifacts-${AWS::AccountId}/*"
|
||||
# HTTP API ids are allocated at create (same as meal-order).
|
||||
# Custom domain is hostname-pinned like procurement-api.
|
||||
# CreateDomainName POSTs to /domainnames and cannot be hostname-pinned;
|
||||
# mgmt still holds doorunlock.seahaven.com, so the domain is attached
|
||||
# at DNS cutover rather than granted as an unscoped collection POST.
|
||||
- Sid: HttpApiManage
|
||||
Effect: Allow
|
||||
Action:
|
||||
|
|
@ -2387,14 +2390,6 @@ Resources:
|
|||
- !Sub "arn:aws:apigateway:us-east-1::/apis"
|
||||
- !Sub "arn:aws:apigateway:us-east-1::/apis/*"
|
||||
- !Sub "arn:aws:apigateway:us-east-1::/tags/*"
|
||||
# CreateDomainName POSTs to the collection ARN. Hostname ARNs
|
||||
# cover Get/Update/Delete and apiMappings after create.
|
||||
- Sid: HttpApiDomainCreate
|
||||
Effect: Allow
|
||||
Action:
|
||||
- apigateway:POST
|
||||
Resource:
|
||||
- arn:aws:apigateway:us-east-1::/domainnames
|
||||
- Sid: HttpApiDomain
|
||||
Effect: Allow
|
||||
Action:
|
||||
|
|
|
|||
Loading…
Add table
Reference in a new issue