feat(iam): allow meal-order-manager to send to paychex-checkcomponents (PLAT-135)

This commit is contained in:
Adam Moussa 2026-09-09 19:43:56 -04:00
parent 6bc4f6e095
commit 6c6fe0f664
No known key found for this signature in database

View file

@ -143,7 +143,7 @@ Description: >-
# seahaven-lambda-execution-boundary-afi-backup-monitor: 952 / 5 statements
# seahaven-lambda-execution-boundary-front-integrations: 1532 / 6 statements
# seahaven-lambda-execution-boundary-procurement-ingest: 3977 / 11 statements
# seahaven-lambda-execution-boundary-meal-order-manager: 2380 / 10 statements
# seahaven-lambda-execution-boundary-meal-order-manager: 2530 / 11 statements (PLAT-135)
# seahaven-lambda-execution-boundary-seahaven-site: 1159 / 6 statements
# seahaven-lambda-execution-boundary-seahaven-door-unlock-api: measure after deploy (PLAT-76)
# seahaven-lambda-execution-boundary-paychex-integrations: GetSecretValue on six minted ARNs (PLAT-122)
@ -1089,6 +1089,18 @@ Resources:
Resource:
- !Sub "arn:aws:sns:us-east-1:${AWS::AccountId}:site-alerts"
- !Ref AWS::NoValue
# aggregate-orders enqueues the weekly meal-deduction payload onto
# paychex-integrations' checkcomponents queue (PLAT-135). Send only;
# the paychex processor owns receive/delete.
- !If
- IsProdAccount
- Sid: MealOrderManagerSqs
Effect: Allow
Action:
- sqs:SendMessage
Resource:
- !Sub "arn:aws:sqs:us-east-1:${AWS::AccountId}:paychex-checkcomponents"
- !Ref AWS::NoValue
- !If
- IsProdAccount
- Sid: MealOrderManager