From 7c43c867e3b794c013a9f863b959face9901c5c6 Mon Sep 17 00:00:00 2001 From: Adam Moussa Date: Mon, 10 Aug 2026 15:42:12 -0400 Subject: [PATCH] fix(iam): allow execute-api Invoke for meal-order weekly-menu boundary --- lib/deploy-substrate/deploy-substrate.template.yaml | 13 +++++++++++++ 1 file changed, 13 insertions(+) diff --git a/lib/deploy-substrate/deploy-substrate.template.yaml b/lib/deploy-substrate/deploy-substrate.template.yaml index fa9712e..fb02518 100644 --- a/lib/deploy-substrate/deploy-substrate.template.yaml +++ b/lib/deploy-substrate/deploy-substrate.template.yaml @@ -682,6 +682,19 @@ Resources: Resource: - !Sub "arn:aws:ssm:us-east-1:${AWS::AccountId}:parameter/meal-order-manager/*" - !Ref AWS::NoValue + # Weekly-menu OIDC role (githubdeploy-meal-order-manager-weekly-menu) + # invokes IAM-authenticated HttpApi publish routes. Identity policy + # pins the API id; boundary uses method/path only (PLAT-100). + - !If + - IsProdAccount + - Sid: MealOrderManagerExecuteApi + Effect: Allow + Action: + - execute-api:Invoke + Resource: + - !Sub "arn:aws:execute-api:us-east-1:${AWS::AccountId}:*/*/GET/api/publish/settings" + - !Sub "arn:aws:execute-api:us-east-1:${AWS::AccountId}:*/*/POST/api/publish/menu" + - !Ref AWS::NoValue - !If - IsProdAccount - Sid: MealOrderManagerLambdaInvoke