From 7a1623e8d40aff7b67f5886dcfb8f9105a8612bc Mon Sep 17 00:00:00 2001 From: Adam Moussa <166072409+amoussa1229@users.noreply.github.com> Date: Mon, 14 Sep 2026 18:31:08 +0000 Subject: [PATCH] fix(iam): allow paychex period table and optional secrets (PLAT-195) (#147) * fix(iam): allow paychex period table and optional secrets (PLAT-195) The processor role already allows these ARNs. The live boundary denied them, so GetSecretValue and period PutItem returned HTTP 400. Sync the template to the live ceiling and add the missing period table plus slack-admin and afterhours secret suffixes. * fix(iam): keep paychex boundary description unchanged (PLAT-195) IAM managed-policy Description is immutable. Changing it on a named policy forces replacement and 409s against the live ManagedPolicyName. Widen PolicyDocument only. --- .../deploy-substrate.template.yaml | 32 +++++++++++++++++++ 1 file changed, 32 insertions(+) diff --git a/lib/deploy-substrate/deploy-substrate.template.yaml b/lib/deploy-substrate/deploy-substrate.template.yaml index 0b787f0..4bd811d 100644 --- a/lib/deploy-substrate/deploy-substrate.template.yaml +++ b/lib/deploy-substrate/deploy-substrate.template.yaml @@ -876,8 +876,10 @@ Resources: - arn:aws:secretsmanager:us-east-1:011934824531:secret:paychex-integrations/webhook-api-key-44b0jB - arn:aws:secretsmanager:us-east-1:011934824531:secret:paychex-integrations/google-service-account-PcUeJD - arn:aws:secretsmanager:us-east-1:011934824531:secret:paychex-integrations/slack-bot-token-L8DntD + - arn:aws:secretsmanager:us-east-1:011934824531:secret:paychex-integrations/slack-admin-token-LHr2VD - arn:aws:secretsmanager:us-east-1:011934824531:secret:paychex-integrations/front-inboxes-write-v6niDC - arn:aws:secretsmanager:us-east-1:011934824531:secret:paychex-integrations/3cx-system-admin-PcUeJD + - arn:aws:secretsmanager:us-east-1:011934824531:secret:paychex-integrations/afterhours-roster-token-j3yCh7 - Sid: PaychexIntegrationsDynamoDB Effect: Allow Action: @@ -887,8 +889,38 @@ Resources: - dynamodb:DeleteItem - dynamodb:ConditionCheckItem - dynamodb:DescribeTable + - dynamodb:Query Resource: - !Sub "arn:aws:dynamodb:us-east-1:${AWS::AccountId}:table/paychex-worker-ledger" + - !Sub "arn:aws:dynamodb:us-east-1:${AWS::AccountId}:table/paychex-worker-ledger/index/*" + - !Sub "arn:aws:dynamodb:us-east-1:${AWS::AccountId}:table/paychex-webhook-notifications" + - !Sub "arn:aws:dynamodb:us-east-1:${AWS::AccountId}:table/paychex-payroll-notices" + - !Sub "arn:aws:dynamodb:us-east-1:${AWS::AccountId}:table/paychex-checkcomponents-posted" + - !Sub "arn:aws:dynamodb:us-east-1:${AWS::AccountId}:table/paychex-checkcomponents-period" + - Sid: PaychexIntegrationsSqsConsume + Effect: Allow + Action: + - sqs:ReceiveMessage + - sqs:DeleteMessage + - sqs:GetQueueAttributes + - sqs:ChangeMessageVisibility + Resource: + - !Sub "arn:aws:sqs:us-east-1:${AWS::AccountId}:paychex-webhook-events" + - !Sub "arn:aws:sqs:us-east-1:${AWS::AccountId}:paychex-login-delay" + - !Sub "arn:aws:sqs:us-east-1:${AWS::AccountId}:paychex-checkcomponents" + - Sid: PaychexIntegrationsSqsSend + Effect: Allow + Action: + - sqs:SendMessage + Resource: + - !Sub "arn:aws:sqs:us-east-1:${AWS::AccountId}:paychex-webhook-events" + - !Sub "arn:aws:sqs:us-east-1:${AWS::AccountId}:paychex-login-delay" + - Sid: PaychexIntegrationsSns + Effect: Allow + Action: + - sns:Publish + Resource: + - !Sub "arn:aws:sns:us-east-1:${AWS::AccountId}:site-alerts" ProcurementIngestBoundary: Type: AWS::IAM::ManagedPolicy