diff --git a/lib/deploy-substrate/deploy-substrate.template.yaml b/lib/deploy-substrate/deploy-substrate.template.yaml index 085786b..e6e6d18 100644 --- a/lib/deploy-substrate/deploy-substrate.template.yaml +++ b/lib/deploy-substrate/deploy-substrate.template.yaml @@ -146,7 +146,7 @@ Description: >- # seahaven-lambda-execution-boundary-meal-order-manager: 2530 / 11 statements (PLAT-135) # seahaven-lambda-execution-boundary-seahaven-site: 1159 / 6 statements # seahaven-lambda-execution-boundary-seahaven-door-unlock-api: measure after deploy (PLAT-76) -# seahaven-lambda-execution-boundary-paychex-integrations: GetSecretValue on six minted ARNs (PLAT-122) +# seahaven-lambda-execution-boundary-paychex-integrations: 3250 / 10 statements (PLAT-228) # Dev copies are floor-only (691 / 4) via IsProdAccount, except # meal-order-manager (PLAT-210): DynamoDB/S3/SSM/invoke plus the # seahaven-dev slack-bot-token ARN. SNS, SQS (Paychex), and SES stay prod. @@ -370,13 +370,17 @@ Resources: # - no IAM permissions for S3 / SQS / SSM / SES / KMS / VPC in this # stack's template as of 2026-07-30 # - # paychex-integrations (functions: paychex-*, PLAT-122) - # - Authority: Sea-Haven-Industries/paychex-integrations terraform/ - # (placeholder Lambda). GetSecretValue on six exact prod secret ARNs - # minted by first HCP apply on 2026-08-27. No name-prefix wildcards. - # - CloudWatch Logs (floor) - # - no DynamoDB / EventBridge / S3 data plane / SES / KMS / VPC in the - # scaffold Terraform +# paychex-integrations (functions: paychex-*, PLAT-122) +# - Authority: Sea-Haven-Industries/paychex-integrations terraform/ +# (placeholder Lambda). GetSecretValue on six exact prod secret ARNs +# minted by first HCP apply on 2026-08-27. No name-prefix wildcards. +# - CloudWatch Logs (floor) +# - no DynamoDB / EventBridge / S3 data plane / SES / KMS / VPC in the +# scaffold Terraform +# - lambda:InvokeFunction on function:paychex-payroll-schedule only +# (PLAT-228). No other function ARN. +# - sqs:SendMessage on paychex-checkcomponents so the schedule role can +# enqueue the Monday flush. Identity policies still name the queue. # # afi-backup-monitor (functions: afi-*) # - secretsmanager:GetSecretValue on TWO exact prod secret ARNs @@ -917,12 +921,21 @@ Resources: Resource: - !Sub "arn:aws:sqs:us-east-1:${AWS::AccountId}:paychex-webhook-events" - !Sub "arn:aws:sqs:us-east-1:${AWS::AccountId}:paychex-login-delay" + - !Sub "arn:aws:sqs:us-east-1:${AWS::AccountId}:paychex-checkcomponents" - Sid: PaychexIntegrationsSns Effect: Allow Action: - sns:Publish Resource: - !Sub "arn:aws:sns:us-east-1:${AWS::AccountId}:site-alerts" + # Scheduler invoke role only. The identity policy names this one + # function; the boundary must not open any other function ARN. + - Sid: PaychexIntegrationsInvokeSchedule + Effect: Allow + Action: + - lambda:InvokeFunction + Resource: + - !Sub "arn:aws:lambda:us-east-1:${AWS::AccountId}:function:paychex-payroll-schedule" ProcurementIngestBoundary: Type: AWS::IAM::ManagedPolicy