fix(iam): consolidate meal-order boundary Sid under PolicySize cap

This commit is contained in:
Adam Moussa 2026-08-10 15:57:08 -04:00
parent 7c43c867e3
commit 81cc8eb4f9
No known key found for this signature in database

View file

@ -121,13 +121,15 @@ Description: >-
# correctly left untouched.
#
# SIZE BUDGET: an attached managed policy document is capped at 6,144 characters
# (whitespace excluded). LambdaExecutionBoundary measures 5903 characters across
# 16 statements as of 2026-08-07 (PLAT-93 consolidation after the meal-order
# PolicySize rollback). Measure before widening — len(json.dumps(doc,
# separators=(',',':'))) on the synthesized PolicyDocument with
# ${AWS::AccountId} resolved, and UPDATE THESE TWO NUMBERS in the same edit.
# (whitespace excluded). LambdaExecutionBoundary measures 5986 characters across
# 15 statements as of 2026-08-10 (PLAT-100: MealOrderManagerSsm+LambdaInvoke
# consolidated with execute-api:Invoke; SES kept separate because Resource:"*"
# must not share a statement with execute-api:Invoke. Was 5903/16 after PLAT-93).
# Measure before widening — len(json.dumps(doc, separators=(',',':'))) on the
# synthesized PolicyDocument with ${AWS::AccountId} resolved, and UPDATE THESE
# TWO NUMBERS in the same edit.
#
# Headroom is 241 characters. Statement consolidation (shared WorkloadSecrets /
# Headroom is 158 characters. Statement consolidation (shared WorkloadSecrets /
# WorkloadDynamoDB / extended WorkloadS3 Resource lists; no new action wildcards)
# is the only remaining lever short of per-workload boundaries. If the budget
# tightens again, the end-state fix is per-workload boundaries
@ -670,40 +672,30 @@ Resources:
- !Sub "arn:aws:cloudfront::${AWS::AccountId}:distribution/*"
- !Ref AWS::NoValue
# ── meal-order-manager (PLAT-70) — statements not covered above ─────
# ── meal-order-manager (PLAT-70 / PLAT-100) — not covered above ─────
# Secrets → WorkloadSecrets; DynamoDB → WorkloadDynamoDB; S3 → WorkloadS3;
# SNS → ProcurementIngestSns. Trimmed to identity-policy needs.
# SNS → ProcurementIngestSns. SSM + Lambda Invoke + execute-api share
# one Sid (scoped Resources only) so PolicySize stays under 6,144 —
# a standalone execute-api Sid is ~243 chars against 241 headroom and
# would fail UPDATE with LimitExceeded. SES stays in its own Sid:
# Resource:"*" must not share a statement with execute-api:Invoke
# (that would allow Invoke on every API in the account).
# Weekly-menu OIDC identity policy pins the API id; boundary pins
# method/path only.
- !If
- IsProdAccount
- Sid: MealOrderManagerSsm
- Sid: MealOrderManager
Effect: Allow
Action:
- ssm:GetParameter
Resource:
- !Sub "arn:aws:ssm:us-east-1:${AWS::AccountId}:parameter/meal-order-manager/*"
- !Ref AWS::NoValue
# Weekly-menu OIDC role (githubdeploy-meal-order-manager-weekly-menu)
# invokes IAM-authenticated HttpApi publish routes. Identity policy
# pins the API id; boundary uses method/path only (PLAT-100).
- !If
- IsProdAccount
- Sid: MealOrderManagerExecuteApi
Effect: Allow
Action:
- lambda:InvokeFunction
- execute-api:Invoke
Resource:
- !Sub "arn:aws:ssm:us-east-1:${AWS::AccountId}:parameter/meal-order-manager/*"
- !Sub "arn:aws:lambda:us-east-1:${AWS::AccountId}:function:meal-order-manager-*"
- !Sub "arn:aws:execute-api:us-east-1:${AWS::AccountId}:*/*/GET/api/publish/settings"
- !Sub "arn:aws:execute-api:us-east-1:${AWS::AccountId}:*/*/POST/api/publish/menu"
- !Ref AWS::NoValue
- !If
- IsProdAccount
- Sid: MealOrderManagerLambdaInvoke
Effect: Allow
Action:
- lambda:InvokeFunction
Resource:
- !Sub "arn:aws:lambda:us-east-1:${AWS::AccountId}:function:meal-order-manager-*"
- !Ref AWS::NoValue
- !If
- IsProdAccount
- Sid: MealOrderManagerSes