fix(iam): allow paychex period table and optional secrets (PLAT-195) (#147)
Some checks failed
Deploy / deploy-management (push) Has been cancelled
Deploy / deploy-external-dev (push) Has been cancelled
Deploy / deploy-security (push) Has been cancelled
Deploy / deploy-dev (push) Has been cancelled
Deploy / deploy-prod (push) Has been cancelled

* fix(iam): allow paychex period table and optional secrets (PLAT-195)

The processor role already allows these ARNs. The live boundary denied
them, so GetSecretValue and period PutItem returned HTTP 400. Sync the
template to the live ceiling and add the missing period table plus
slack-admin and afterhours secret suffixes.

* fix(iam): keep paychex boundary description unchanged (PLAT-195)

IAM managed-policy Description is immutable. Changing it on a named
policy forces replacement and 409s against the live ManagedPolicyName.
Widen PolicyDocument only.
This commit is contained in:
Adam Moussa 2026-09-14 18:31:08 +00:00 • committed by GitHub
parent a492a45e07
commit 7a1623e8d4
No known key found for this signature in database
GPG key ID: B5690EEEBB952194

View file

@ -876,8 +876,10 @@ Resources:
- arn:aws:secretsmanager:us-east-1:011934824531:secret:paychex-integrations/webhook-api-key-44b0jB
- arn:aws:secretsmanager:us-east-1:011934824531:secret:paychex-integrations/google-service-account-PcUeJD
- arn:aws:secretsmanager:us-east-1:011934824531:secret:paychex-integrations/slack-bot-token-L8DntD
- arn:aws:secretsmanager:us-east-1:011934824531:secret:paychex-integrations/slack-admin-token-LHr2VD
- arn:aws:secretsmanager:us-east-1:011934824531:secret:paychex-integrations/front-inboxes-write-v6niDC
- arn:aws:secretsmanager:us-east-1:011934824531:secret:paychex-integrations/3cx-system-admin-PcUeJD
- arn:aws:secretsmanager:us-east-1:011934824531:secret:paychex-integrations/afterhours-roster-token-j3yCh7
- Sid: PaychexIntegrationsDynamoDB
Effect: Allow
Action:
@ -887,8 +889,38 @@ Resources:
- dynamodb:DeleteItem
- dynamodb:ConditionCheckItem
- dynamodb:DescribeTable
- dynamodb:Query
Resource:
- !Sub "arn:aws:dynamodb:us-east-1:${AWS::AccountId}:table/paychex-worker-ledger"
- !Sub "arn:aws:dynamodb:us-east-1:${AWS::AccountId}:table/paychex-worker-ledger/index/*"
- !Sub "arn:aws:dynamodb:us-east-1:${AWS::AccountId}:table/paychex-webhook-notifications"
- !Sub "arn:aws:dynamodb:us-east-1:${AWS::AccountId}:table/paychex-payroll-notices"
- !Sub "arn:aws:dynamodb:us-east-1:${AWS::AccountId}:table/paychex-checkcomponents-posted"
- !Sub "arn:aws:dynamodb:us-east-1:${AWS::AccountId}:table/paychex-checkcomponents-period"
- Sid: PaychexIntegrationsSqsConsume
Effect: Allow
Action:
- sqs:ReceiveMessage
- sqs:DeleteMessage
- sqs:GetQueueAttributes
- sqs:ChangeMessageVisibility
Resource:
- !Sub "arn:aws:sqs:us-east-1:${AWS::AccountId}:paychex-webhook-events"
- !Sub "arn:aws:sqs:us-east-1:${AWS::AccountId}:paychex-login-delay"
- !Sub "arn:aws:sqs:us-east-1:${AWS::AccountId}:paychex-checkcomponents"
- Sid: PaychexIntegrationsSqsSend
Effect: Allow
Action:
- sqs:SendMessage
Resource:
- !Sub "arn:aws:sqs:us-east-1:${AWS::AccountId}:paychex-webhook-events"
- !Sub "arn:aws:sqs:us-east-1:${AWS::AccountId}:paychex-login-delay"
- Sid: PaychexIntegrationsSns
Effect: Allow
Action:
- sns:Publish
Resource:
- !Sub "arn:aws:sns:us-east-1:${AWS::AccountId}:site-alerts"
ProcurementIngestBoundary:
Type: AWS::IAM::ManagedPolicy