fix(iam): allow execute-api Invoke for meal-order weekly-menu boundary

This commit is contained in:
Adam Moussa 2026-08-10 15:42:12 -04:00
parent 7ad46d9528
commit 7c43c867e3
No known key found for this signature in database

View file

@ -682,6 +682,19 @@ Resources:
Resource:
- !Sub "arn:aws:ssm:us-east-1:${AWS::AccountId}:parameter/meal-order-manager/*"
- !Ref AWS::NoValue
# Weekly-menu OIDC role (githubdeploy-meal-order-manager-weekly-menu)
# invokes IAM-authenticated HttpApi publish routes. Identity policy
# pins the API id; boundary uses method/path only (PLAT-100).
- !If
- IsProdAccount
- Sid: MealOrderManagerExecuteApi
Effect: Allow
Action:
- execute-api:Invoke
Resource:
- !Sub "arn:aws:execute-api:us-east-1:${AWS::AccountId}:*/*/GET/api/publish/settings"
- !Sub "arn:aws:execute-api:us-east-1:${AWS::AccountId}:*/*/POST/api/publish/menu"
- !Ref AWS::NoValue
- !If
- IsProdAccount
- Sid: MealOrderManagerLambdaInvoke