diff --git a/lib/deploy-substrate/deploy-substrate.template.yaml b/lib/deploy-substrate/deploy-substrate.template.yaml index 4bd811d..28d4a93 100644 --- a/lib/deploy-substrate/deploy-substrate.template.yaml +++ b/lib/deploy-substrate/deploy-substrate.template.yaml @@ -147,7 +147,9 @@ Description: >- # seahaven-lambda-execution-boundary-seahaven-site: 1159 / 6 statements # seahaven-lambda-execution-boundary-seahaven-door-unlock-api: measure after deploy (PLAT-76) # seahaven-lambda-execution-boundary-paychex-integrations: GetSecretValue on six minted ARNs (PLAT-122) -# Dev copies are floor-only (691 / 4) via IsProdAccount. +# Dev copies are floor-only (691 / 4) via IsProdAccount, except +# meal-order-manager (PLAT-210): DynamoDB/S3/SSM/invoke plus the +# seahaven-dev slack-bot-token ARN. SNS, SQS (Paychex), and SES stay prod. # # Guardrail PolicyDocuments also cap at 6,144. Each extra allow-list ARN # is copied into four Sids in EACH of SamCfnIamManagementPolicy and @@ -1055,9 +1057,10 @@ Resources: ManagedPolicyName: seahaven-lambda-execution-boundary-meal-order-manager Description: >- Per-workload permissions boundary for meal-order-manager (PLAT-52). - Floor plus secrets, orders table, form/reports buckets, site-alerts, - SSM/invoke/execute-api, and SES. Shared policy remains the live-role - ceiling until app retarget. + Floor plus secrets, orders table, form/reports buckets, SSM/invoke/ + execute-api in both prod and seahaven-dev (PLAT-210). site-alerts, + Paychex SQS, and SES stay prod-only. Shared policy remains the + live-role ceiling until app retarget. PolicyDocument: Version: "2012-10-17" Statement: @@ -1075,43 +1078,42 @@ Resources: - secretsmanager:GetSecretValue Resource: - arn:aws:secretsmanager:us-east-1:011934824531:secret:meal-order-manager/slack-bot-token-ZGmSGw - - !Ref AWS::NoValue - - !If - - IsProdAccount - - Sid: MealOrderManagerDynamoDB + - Sid: MealOrderManagerSecrets Effect: Allow Action: - - dynamodb:GetItem - - dynamodb:PutItem - - dynamodb:UpdateItem - - dynamodb:DeleteItem - - dynamodb:Query - - dynamodb:Scan - - dynamodb:BatchGetItem - - dynamodb:BatchWriteItem - - dynamodb:DescribeTable - - dynamodb:ConditionCheckItem + - secretsmanager:GetSecretValue Resource: - - !Sub "arn:aws:dynamodb:us-east-1:${AWS::AccountId}:table/meal-order-manager-orders" - - !Sub "arn:aws:dynamodb:us-east-1:${AWS::AccountId}:table/meal-order-manager-orders/index/*" - - !Ref AWS::NoValue - - !If - - IsProdAccount - - Sid: MealOrderManagerS3 - Effect: Allow - Action: - - s3:GetObject* - - s3:GetBucket* - - s3:List* - - s3:PutObject* - - s3:DeleteObject* - - s3:AbortMultipartUpload - Resource: - - !Sub "arn:aws:s3:::meal-order-manager-form-${AWS::AccountId}" - - !Sub "arn:aws:s3:::meal-order-manager-form-${AWS::AccountId}/*" - - !Sub "arn:aws:s3:::meal-order-manager-reports-${AWS::AccountId}" - - !Sub "arn:aws:s3:::meal-order-manager-reports-${AWS::AccountId}/*" - - !Ref AWS::NoValue + - arn:aws:secretsmanager:us-east-1:710827005802:secret:meal-order-manager/slack-bot-token-y37snU + - Sid: MealOrderManagerDynamoDB + Effect: Allow + Action: + - dynamodb:GetItem + - dynamodb:PutItem + - dynamodb:UpdateItem + - dynamodb:DeleteItem + - dynamodb:Query + - dynamodb:Scan + - dynamodb:BatchGetItem + - dynamodb:BatchWriteItem + - dynamodb:DescribeTable + - dynamodb:ConditionCheckItem + Resource: + - !Sub "arn:aws:dynamodb:us-east-1:${AWS::AccountId}:table/meal-order-manager-orders" + - !Sub "arn:aws:dynamodb:us-east-1:${AWS::AccountId}:table/meal-order-manager-orders/index/*" + - Sid: MealOrderManagerS3 + Effect: Allow + Action: + - s3:GetObject* + - s3:GetBucket* + - s3:List* + - s3:PutObject* + - s3:DeleteObject* + - s3:AbortMultipartUpload + Resource: + - !Sub "arn:aws:s3:::meal-order-manager-form-${AWS::AccountId}" + - !Sub "arn:aws:s3:::meal-order-manager-form-${AWS::AccountId}/*" + - !Sub "arn:aws:s3:::meal-order-manager-reports-${AWS::AccountId}" + - !Sub "arn:aws:s3:::meal-order-manager-reports-${AWS::AccountId}/*" - !If - IsProdAccount - Sid: MealOrderManagerSns @@ -1123,7 +1125,8 @@ Resources: - !Ref AWS::NoValue # aggregate-orders enqueues the weekly meal-deduction payload onto # paychex-integrations' checkcomponents queue (PLAT-135). Send only; - # the paychex processor owns receive/delete. + # the paychex processor owns receive/delete. Not in seahaven-dev + # (PLAT-210: Paychex queue URLs stay empty). - !If - IsProdAccount - Sid: MealOrderManagerSqs @@ -1133,20 +1136,17 @@ Resources: Resource: - !Sub "arn:aws:sqs:us-east-1:${AWS::AccountId}:paychex-checkcomponents" - !Ref AWS::NoValue - - !If - - IsProdAccount - - Sid: MealOrderManager - Effect: Allow - Action: - - ssm:GetParameter - - lambda:InvokeFunction - - execute-api:Invoke - Resource: - - !Sub "arn:aws:ssm:us-east-1:${AWS::AccountId}:parameter/meal-order-manager/*" - - !Sub "arn:aws:lambda:us-east-1:${AWS::AccountId}:function:meal-order-manager-*" - - !Sub "arn:aws:execute-api:us-east-1:${AWS::AccountId}:*/*/GET/api/publish/settings" - - !Sub "arn:aws:execute-api:us-east-1:${AWS::AccountId}:*/*/POST/api/publish/menu" - - !Ref AWS::NoValue + - Sid: MealOrderManager + Effect: Allow + Action: + - ssm:GetParameter + - lambda:InvokeFunction + - execute-api:Invoke + Resource: + - !Sub "arn:aws:ssm:us-east-1:${AWS::AccountId}:parameter/meal-order-manager/*" + - !Sub "arn:aws:lambda:us-east-1:${AWS::AccountId}:function:meal-order-manager-*" + - !Sub "arn:aws:execute-api:us-east-1:${AWS::AccountId}:*/*/GET/api/publish/settings" + - !Sub "arn:aws:execute-api:us-east-1:${AWS::AccountId}:*/*/POST/api/publish/menu" - !If - IsProdAccount - Sid: MealOrderManagerSes