mirror of
https://github.com/Sea-Haven-Industries/seahaven-org-baseline.git
synced 2026-10-01 10:53:16 +00:00
fix(iam): allow paychex period table and optional secrets (PLAT-195)
The processor role already allows these ARNs. The live boundary denied them, so GetSecretValue and period PutItem returned HTTP 400. Sync the template to the live ceiling and add the missing period table plus slack-admin and afterhours secret suffixes.
This commit is contained in:
parent
a492a45e07
commit
af47bf6455
1 changed files with 34 additions and 2 deletions
|
|
@ -853,8 +853,8 @@ Resources:
|
|||
Properties:
|
||||
ManagedPolicyName: seahaven-lambda-execution-boundary-paychex-integrations
|
||||
Description: >-
|
||||
Per-workload permissions boundary for paychex-integrations (PLAT-120).
|
||||
Floor only until first HCP apply mints secret suffixes.
|
||||
Per-workload permissions boundary for paychex-integrations (PLAT-120,
|
||||
PLAT-195). Floor plus minted secret ARNs and processor data plane.
|
||||
PolicyDocument:
|
||||
Version: "2012-10-17"
|
||||
Statement:
|
||||
|
|
@ -876,8 +876,10 @@ Resources:
|
|||
- arn:aws:secretsmanager:us-east-1:011934824531:secret:paychex-integrations/webhook-api-key-44b0jB
|
||||
- arn:aws:secretsmanager:us-east-1:011934824531:secret:paychex-integrations/google-service-account-PcUeJD
|
||||
- arn:aws:secretsmanager:us-east-1:011934824531:secret:paychex-integrations/slack-bot-token-L8DntD
|
||||
- arn:aws:secretsmanager:us-east-1:011934824531:secret:paychex-integrations/slack-admin-token-LHr2VD
|
||||
- arn:aws:secretsmanager:us-east-1:011934824531:secret:paychex-integrations/front-inboxes-write-v6niDC
|
||||
- arn:aws:secretsmanager:us-east-1:011934824531:secret:paychex-integrations/3cx-system-admin-PcUeJD
|
||||
- arn:aws:secretsmanager:us-east-1:011934824531:secret:paychex-integrations/afterhours-roster-token-j3yCh7
|
||||
- Sid: PaychexIntegrationsDynamoDB
|
||||
Effect: Allow
|
||||
Action:
|
||||
|
|
@ -887,8 +889,38 @@ Resources:
|
|||
- dynamodb:DeleteItem
|
||||
- dynamodb:ConditionCheckItem
|
||||
- dynamodb:DescribeTable
|
||||
- dynamodb:Query
|
||||
Resource:
|
||||
- !Sub "arn:aws:dynamodb:us-east-1:${AWS::AccountId}:table/paychex-worker-ledger"
|
||||
- !Sub "arn:aws:dynamodb:us-east-1:${AWS::AccountId}:table/paychex-worker-ledger/index/*"
|
||||
- !Sub "arn:aws:dynamodb:us-east-1:${AWS::AccountId}:table/paychex-webhook-notifications"
|
||||
- !Sub "arn:aws:dynamodb:us-east-1:${AWS::AccountId}:table/paychex-payroll-notices"
|
||||
- !Sub "arn:aws:dynamodb:us-east-1:${AWS::AccountId}:table/paychex-checkcomponents-posted"
|
||||
- !Sub "arn:aws:dynamodb:us-east-1:${AWS::AccountId}:table/paychex-checkcomponents-period"
|
||||
- Sid: PaychexIntegrationsSqsConsume
|
||||
Effect: Allow
|
||||
Action:
|
||||
- sqs:ReceiveMessage
|
||||
- sqs:DeleteMessage
|
||||
- sqs:GetQueueAttributes
|
||||
- sqs:ChangeMessageVisibility
|
||||
Resource:
|
||||
- !Sub "arn:aws:sqs:us-east-1:${AWS::AccountId}:paychex-webhook-events"
|
||||
- !Sub "arn:aws:sqs:us-east-1:${AWS::AccountId}:paychex-login-delay"
|
||||
- !Sub "arn:aws:sqs:us-east-1:${AWS::AccountId}:paychex-checkcomponents"
|
||||
- Sid: PaychexIntegrationsSqsSend
|
||||
Effect: Allow
|
||||
Action:
|
||||
- sqs:SendMessage
|
||||
Resource:
|
||||
- !Sub "arn:aws:sqs:us-east-1:${AWS::AccountId}:paychex-webhook-events"
|
||||
- !Sub "arn:aws:sqs:us-east-1:${AWS::AccountId}:paychex-login-delay"
|
||||
- Sid: PaychexIntegrationsSns
|
||||
Effect: Allow
|
||||
Action:
|
||||
- sns:Publish
|
||||
Resource:
|
||||
- !Sub "arn:aws:sns:us-east-1:${AWS::AccountId}:site-alerts"
|
||||
|
||||
ProcurementIngestBoundary:
|
||||
Type: AWS::IAM::ManagedPolicy
|
||||
|
|
|
|||
Loading…
Add table
Reference in a new issue