mirror of
https://github.com/Sea-Haven-Industries/seahaven-org-baseline.git
synced 2026-10-06 06:21:58 +00:00
fix(iam): widen procurement-ingest plan refresh for import
Add GetEventSourceMapping, SSM GetParameter pins, and Resource "*" for kms:ListAliases so the first HCP import plan can refresh.
This commit is contained in:
parent
a5fa0b16a3
commit
a5997f878b
1 changed files with 38 additions and 5 deletions
|
|
@ -999,11 +999,15 @@ Resources:
|
||||||
- !Sub "arn:aws:lambda:us-east-1:${AWS::AccountId}:function:workorder-*"
|
- !Sub "arn:aws:lambda:us-east-1:${AWS::AccountId}:function:workorder-*"
|
||||||
- !Sub "arn:aws:lambda:us-east-1:${AWS::AccountId}:function:procurement-api"
|
- !Sub "arn:aws:lambda:us-east-1:${AWS::AccountId}:function:procurement-api"
|
||||||
# Collection/list APIs authorize only against Resource "*".
|
# Collection/list APIs authorize only against Resource "*".
|
||||||
|
# GetEventSourceMapping is authorized on the UUID mapping ARN
|
||||||
|
# (no FunctionArn in the request context), so it cannot share
|
||||||
|
# the apply-role FunctionArn condition.
|
||||||
- Sid: RefreshLambdaList
|
- Sid: RefreshLambdaList
|
||||||
Effect: Allow
|
Effect: Allow
|
||||||
Action:
|
Action:
|
||||||
- lambda:ListFunctions
|
- lambda:ListFunctions
|
||||||
- lambda:ListEventSourceMappings
|
- lambda:ListEventSourceMappings
|
||||||
|
- lambda:GetEventSourceMapping
|
||||||
- lambda:GetAccountSettings
|
- lambda:GetAccountSettings
|
||||||
Resource: "*"
|
Resource: "*"
|
||||||
- Sid: RefreshArtifactsBucket
|
- Sid: RefreshArtifactsBucket
|
||||||
|
|
@ -1093,10 +1097,16 @@ Resources:
|
||||||
- kms:GetKeyPolicy
|
- kms:GetKeyPolicy
|
||||||
- kms:GetKeyRotationStatus
|
- kms:GetKeyRotationStatus
|
||||||
- kms:ListResourceTags
|
- kms:ListResourceTags
|
||||||
- kms:ListAliases
|
|
||||||
Resource:
|
Resource:
|
||||||
- !Sub "arn:aws:kms:us-east-1:${AWS::AccountId}:key/*"
|
- !Sub "arn:aws:kms:us-east-1:${AWS::AccountId}:key/*"
|
||||||
- !Sub "arn:aws:kms:us-east-1:${AWS::AccountId}:alias/workorder-ingest-shoc-webhook-kms"
|
- !Sub "arn:aws:kms:us-east-1:${AWS::AccountId}:alias/workorder-ingest-shoc-webhook-kms"
|
||||||
|
# ListAliases/ListKeys are collection APIs (Resource "*").
|
||||||
|
- Sid: RefreshKmsList
|
||||||
|
Effect: Allow
|
||||||
|
Action:
|
||||||
|
- kms:ListAliases
|
||||||
|
- kms:ListKeys
|
||||||
|
Resource: "*"
|
||||||
- Sid: RefreshSecrets
|
- Sid: RefreshSecrets
|
||||||
Effect: Allow
|
Effect: Allow
|
||||||
Action:
|
Action:
|
||||||
|
|
@ -1106,6 +1116,15 @@ Resources:
|
||||||
Resource:
|
Resource:
|
||||||
- !Sub "arn:aws:secretsmanager:us-east-1:${AWS::AccountId}:secret:workorder-ingest/shoc-webhook-hmac-*"
|
- !Sub "arn:aws:secretsmanager:us-east-1:${AWS::AccountId}:secret:workorder-ingest/shoc-webhook-hmac-*"
|
||||||
- !Sub "arn:aws:secretsmanager:us-east-1:${AWS::AccountId}:secret:procurement-ingest/web-ui-auth-token-*"
|
- !Sub "arn:aws:secretsmanager:us-east-1:${AWS::AccountId}:secret:procurement-ingest/web-ui-auth-token-*"
|
||||||
|
# OOB SSM pins used by data.aws_ssm_parameter (not in ViewOnlyAccess).
|
||||||
|
- Sid: RefreshSsm
|
||||||
|
Effect: Allow
|
||||||
|
Action:
|
||||||
|
- ssm:GetParameter
|
||||||
|
- ssm:GetParameters
|
||||||
|
Resource:
|
||||||
|
- !Sub "arn:aws:ssm:us-east-1:${AWS::AccountId}:parameter/seahaven/dynamodb/cmk-arn"
|
||||||
|
- !Sub "arn:aws:ssm:us-east-1:${AWS::AccountId}:parameter/procurement-api/custom-domain/certificate-arn"
|
||||||
- Sid: RefreshSes
|
- Sid: RefreshSes
|
||||||
Effect: Allow
|
Effect: Allow
|
||||||
Action:
|
Action:
|
||||||
|
|
@ -1152,16 +1171,22 @@ Resources:
|
||||||
- !Sub "arn:aws:lambda:us-east-1:${AWS::AccountId}:function:workorder-*"
|
- !Sub "arn:aws:lambda:us-east-1:${AWS::AccountId}:function:workorder-*"
|
||||||
- !Sub "arn:aws:lambda:us-east-1:${AWS::AccountId}:function:procurement-api"
|
- !Sub "arn:aws:lambda:us-east-1:${AWS::AccountId}:function:procurement-api"
|
||||||
# Event source mapping ARNs are UUID-keyed; AWS authorises Create against
|
# Event source mapping ARNs are UUID-keyed; AWS authorises Create against
|
||||||
# FunctionArn. Get/Update/Delete also take the mapping ARN, so Resource
|
# FunctionArn. Mutating Get/Update/Delete also take the mapping ARN.
|
||||||
# stays "*" but FunctionArn is constrained to this stack's functions.
|
# GetEventSourceMapping by UUID does not carry FunctionArn in the
|
||||||
|
# request context, so read is unconditioned on "*"; mutate stays
|
||||||
|
# FunctionArn-constrained.
|
||||||
|
- Sid: LambdaEventSourceMappingRead
|
||||||
|
Effect: Allow
|
||||||
|
Action:
|
||||||
|
- lambda:GetEventSourceMapping
|
||||||
|
- lambda:ListTags
|
||||||
|
Resource: "*"
|
||||||
- Sid: LambdaEventSourceMappings
|
- Sid: LambdaEventSourceMappings
|
||||||
Effect: Allow
|
Effect: Allow
|
||||||
Action:
|
Action:
|
||||||
- lambda:CreateEventSourceMapping
|
- lambda:CreateEventSourceMapping
|
||||||
- lambda:DeleteEventSourceMapping
|
- lambda:DeleteEventSourceMapping
|
||||||
- lambda:UpdateEventSourceMapping
|
- lambda:UpdateEventSourceMapping
|
||||||
- lambda:GetEventSourceMapping
|
|
||||||
- lambda:ListTags
|
|
||||||
- lambda:TagResource
|
- lambda:TagResource
|
||||||
- lambda:UntagResource
|
- lambda:UntagResource
|
||||||
Resource: "*"
|
Resource: "*"
|
||||||
|
|
@ -1178,6 +1203,14 @@ Resources:
|
||||||
- lambda:ListEventSourceMappings
|
- lambda:ListEventSourceMappings
|
||||||
- lambda:GetAccountSettings
|
- lambda:GetAccountSettings
|
||||||
Resource: "*"
|
Resource: "*"
|
||||||
|
- Sid: SsmRead
|
||||||
|
Effect: Allow
|
||||||
|
Action:
|
||||||
|
- ssm:GetParameter
|
||||||
|
- ssm:GetParameters
|
||||||
|
Resource:
|
||||||
|
- !Sub "arn:aws:ssm:us-east-1:${AWS::AccountId}:parameter/seahaven/dynamodb/cmk-arn"
|
||||||
|
- !Sub "arn:aws:ssm:us-east-1:${AWS::AccountId}:parameter/procurement-api/custom-domain/certificate-arn"
|
||||||
- Sid: CloudWatchLogs
|
- Sid: CloudWatchLogs
|
||||||
Effect: Allow
|
Effect: Allow
|
||||||
Action:
|
Action:
|
||||||
|
|
|
||||||
Loading…
Add table
Reference in a new issue