Merge pull request #102 from Sea-Haven-Industries/fix/meal-order-log-delivery
Some checks are pending
Deploy / deploy-management (push) Waiting to run
Deploy / deploy-external-dev (push) Waiting to run
Deploy / deploy-security (push) Waiting to run
Deploy / deploy-dev (push) Waiting to run
Deploy / deploy-prod (push) Waiting to run

fix(iam): allow API GW Log Delivery on meal-order apply role (PLAT-99)
This commit is contained in:
Adam Moussa 2026-08-10 15:27:34 -04:00 • committed by GitHub
commit 7ad46d9528
No known key found for this signature in database
GPG key ID: B5690EEEBB952194

View file

@ -1791,6 +1791,21 @@ Resources:
Action:
- logs:DescribeLogGroups
Resource: "*"
# HTTP API stage access_log_settings uses Log Delivery APIs
# (account-level Resource "*"). PutResourcePolicy is intentionally
# omitted: MealOrderApiAccessLogResourcePolicy below pre-grants
# delivery.logs.amazonaws.com on the meal-order API log group so
# the apply role cannot mutate account-wide log resource policies.
- Sid: MealOrderApiGwAccessLogDelivery
Effect: Allow
Action:
- logs:CreateLogDelivery
- logs:GetLogDelivery
- logs:UpdateLogDelivery
- logs:DeleteLogDelivery
- logs:ListLogDeliveries
- logs:DescribeResourcePolicies
Resource: "*"
- Sid: StackBuckets
Effect: Allow
Action:
@ -1926,3 +1941,36 @@ Resources:
- ses:GetIdentityVerificationAttributes
- ses:GetSendQuota
Resource: "*"
# Pre-grant delivery.logs write to the meal-order API access log group so
# hcptf-meal-order-manager does not need logs:PutResourcePolicy (account-wide).
# Deployed by CDK CFN exec on substrate update (PLAT-99).
MealOrderApiAccessLogResourcePolicy:
Type: AWS::Logs::ResourcePolicy
Condition: IsProdAccount
Properties:
PolicyName: MealOrderManagerApiAccessLogDelivery
PolicyDocument: !Sub |
{
"Version": "2012-10-17",
"Statement": [
{
"Sid": "AWSLogDeliveryWrite",
"Effect": "Allow",
"Principal": { "Service": "delivery.logs.amazonaws.com" },
"Action": [
"logs:CreateLogStream",
"logs:PutLogEvents"
],
"Resource": [
"arn:aws:logs:us-east-1:${AWS::AccountId}:log-group:/aws/apigateway/meal-order-manager",
"arn:aws:logs:us-east-1:${AWS::AccountId}:log-group:/aws/apigateway/meal-order-manager:*"
],
"Condition": {
"StringEquals": {
"aws:SourceAccount": "${AWS::AccountId}"
}
}
}
]
}