mirror of
https://github.com/Sea-Haven-Industries/seahaven-org-baseline.git
synced 2026-09-30 06:53:17 +00:00
fix(iam): allow payroll schedule invoke under the paychex boundary (PLAT-228) (#155)
The live boundary denies lambda:InvokeFunction, so the Monday and Thursday schedules would be created and would not fire. Allow that action only on paychex-payroll-schedule, and allow SendMessage on paychex-checkcomponents so the schedule role can enqueue the flush.
This commit is contained in:
parent
2f2858f885
commit
617987c4a8
1 changed files with 21 additions and 8 deletions
|
|
@ -146,7 +146,7 @@ Description: >-
|
||||||
# seahaven-lambda-execution-boundary-meal-order-manager: 2530 / 11 statements (PLAT-135)
|
# seahaven-lambda-execution-boundary-meal-order-manager: 2530 / 11 statements (PLAT-135)
|
||||||
# seahaven-lambda-execution-boundary-seahaven-site: 1159 / 6 statements
|
# seahaven-lambda-execution-boundary-seahaven-site: 1159 / 6 statements
|
||||||
# seahaven-lambda-execution-boundary-seahaven-door-unlock-api: measure after deploy (PLAT-76)
|
# seahaven-lambda-execution-boundary-seahaven-door-unlock-api: measure after deploy (PLAT-76)
|
||||||
# seahaven-lambda-execution-boundary-paychex-integrations: GetSecretValue on six minted ARNs (PLAT-122)
|
# seahaven-lambda-execution-boundary-paychex-integrations: 3250 / 10 statements (PLAT-228)
|
||||||
# Dev copies are floor-only (691 / 4) via IsProdAccount, except
|
# Dev copies are floor-only (691 / 4) via IsProdAccount, except
|
||||||
# meal-order-manager (PLAT-210): DynamoDB/S3/SSM/invoke plus the
|
# meal-order-manager (PLAT-210): DynamoDB/S3/SSM/invoke plus the
|
||||||
# seahaven-dev slack-bot-token ARN. SNS, SQS (Paychex), and SES stay prod.
|
# seahaven-dev slack-bot-token ARN. SNS, SQS (Paychex), and SES stay prod.
|
||||||
|
|
@ -370,13 +370,17 @@ Resources:
|
||||||
# - no IAM permissions for S3 / SQS / SSM / SES / KMS / VPC in this
|
# - no IAM permissions for S3 / SQS / SSM / SES / KMS / VPC in this
|
||||||
# stack's template as of 2026-07-30
|
# stack's template as of 2026-07-30
|
||||||
#
|
#
|
||||||
# paychex-integrations (functions: paychex-*, PLAT-122)
|
# paychex-integrations (functions: paychex-*, PLAT-122)
|
||||||
# - Authority: Sea-Haven-Industries/paychex-integrations terraform/
|
# - Authority: Sea-Haven-Industries/paychex-integrations terraform/
|
||||||
# (placeholder Lambda). GetSecretValue on six exact prod secret ARNs
|
# (placeholder Lambda). GetSecretValue on six exact prod secret ARNs
|
||||||
# minted by first HCP apply on 2026-08-27. No name-prefix wildcards.
|
# minted by first HCP apply on 2026-08-27. No name-prefix wildcards.
|
||||||
# - CloudWatch Logs (floor)
|
# - CloudWatch Logs (floor)
|
||||||
# - no DynamoDB / EventBridge / S3 data plane / SES / KMS / VPC in the
|
# - no DynamoDB / EventBridge / S3 data plane / SES / KMS / VPC in the
|
||||||
# scaffold Terraform
|
# scaffold Terraform
|
||||||
|
# - lambda:InvokeFunction on function:paychex-payroll-schedule only
|
||||||
|
# (PLAT-228). No other function ARN.
|
||||||
|
# - sqs:SendMessage on paychex-checkcomponents so the schedule role can
|
||||||
|
# enqueue the Monday flush. Identity policies still name the queue.
|
||||||
#
|
#
|
||||||
# afi-backup-monitor (functions: afi-*)
|
# afi-backup-monitor (functions: afi-*)
|
||||||
# - secretsmanager:GetSecretValue on TWO exact prod secret ARNs
|
# - secretsmanager:GetSecretValue on TWO exact prod secret ARNs
|
||||||
|
|
@ -917,12 +921,21 @@ Resources:
|
||||||
Resource:
|
Resource:
|
||||||
- !Sub "arn:aws:sqs:us-east-1:${AWS::AccountId}:paychex-webhook-events"
|
- !Sub "arn:aws:sqs:us-east-1:${AWS::AccountId}:paychex-webhook-events"
|
||||||
- !Sub "arn:aws:sqs:us-east-1:${AWS::AccountId}:paychex-login-delay"
|
- !Sub "arn:aws:sqs:us-east-1:${AWS::AccountId}:paychex-login-delay"
|
||||||
|
- !Sub "arn:aws:sqs:us-east-1:${AWS::AccountId}:paychex-checkcomponents"
|
||||||
- Sid: PaychexIntegrationsSns
|
- Sid: PaychexIntegrationsSns
|
||||||
Effect: Allow
|
Effect: Allow
|
||||||
Action:
|
Action:
|
||||||
- sns:Publish
|
- sns:Publish
|
||||||
Resource:
|
Resource:
|
||||||
- !Sub "arn:aws:sns:us-east-1:${AWS::AccountId}:site-alerts"
|
- !Sub "arn:aws:sns:us-east-1:${AWS::AccountId}:site-alerts"
|
||||||
|
# Scheduler invoke role only. The identity policy names this one
|
||||||
|
# function; the boundary must not open any other function ARN.
|
||||||
|
- Sid: PaychexIntegrationsInvokeSchedule
|
||||||
|
Effect: Allow
|
||||||
|
Action:
|
||||||
|
- lambda:InvokeFunction
|
||||||
|
Resource:
|
||||||
|
- !Sub "arn:aws:lambda:us-east-1:${AWS::AccountId}:function:paychex-payroll-schedule"
|
||||||
|
|
||||||
ProcurementIngestBoundary:
|
ProcurementIngestBoundary:
|
||||||
Type: AWS::IAM::ManagedPolicy
|
Type: AWS::IAM::ManagedPolicy
|
||||||
|
|
|
||||||
Loading…
Add table
Reference in a new issue