fix(iam): allow paychex period table and optional secrets (PLAT-195)

The processor role already allows these ARNs. The live boundary denied
them, so GetSecretValue and period PutItem returned HTTP 400. Sync the
template to the live ceiling and add the missing period table plus
slack-admin and afterhours secret suffixes.
This commit is contained in:
Adam Moussa 2026-09-14 14:10:47 -04:00
parent a492a45e07
commit af47bf6455
No known key found for this signature in database

View file

@ -853,8 +853,8 @@ Resources:
Properties:
ManagedPolicyName: seahaven-lambda-execution-boundary-paychex-integrations
Description: >-
Per-workload permissions boundary for paychex-integrations (PLAT-120).
Floor only until first HCP apply mints secret suffixes.
Per-workload permissions boundary for paychex-integrations (PLAT-120,
PLAT-195). Floor plus minted secret ARNs and processor data plane.
PolicyDocument:
Version: "2012-10-17"
Statement:
@ -876,8 +876,10 @@ Resources:
- arn:aws:secretsmanager:us-east-1:011934824531:secret:paychex-integrations/webhook-api-key-44b0jB
- arn:aws:secretsmanager:us-east-1:011934824531:secret:paychex-integrations/google-service-account-PcUeJD
- arn:aws:secretsmanager:us-east-1:011934824531:secret:paychex-integrations/slack-bot-token-L8DntD
- arn:aws:secretsmanager:us-east-1:011934824531:secret:paychex-integrations/slack-admin-token-LHr2VD
- arn:aws:secretsmanager:us-east-1:011934824531:secret:paychex-integrations/front-inboxes-write-v6niDC
- arn:aws:secretsmanager:us-east-1:011934824531:secret:paychex-integrations/3cx-system-admin-PcUeJD
- arn:aws:secretsmanager:us-east-1:011934824531:secret:paychex-integrations/afterhours-roster-token-j3yCh7
- Sid: PaychexIntegrationsDynamoDB
Effect: Allow
Action:
@ -887,8 +889,38 @@ Resources:
- dynamodb:DeleteItem
- dynamodb:ConditionCheckItem
- dynamodb:DescribeTable
- dynamodb:Query
Resource:
- !Sub "arn:aws:dynamodb:us-east-1:${AWS::AccountId}:table/paychex-worker-ledger"
- !Sub "arn:aws:dynamodb:us-east-1:${AWS::AccountId}:table/paychex-worker-ledger/index/*"
- !Sub "arn:aws:dynamodb:us-east-1:${AWS::AccountId}:table/paychex-webhook-notifications"
- !Sub "arn:aws:dynamodb:us-east-1:${AWS::AccountId}:table/paychex-payroll-notices"
- !Sub "arn:aws:dynamodb:us-east-1:${AWS::AccountId}:table/paychex-checkcomponents-posted"
- !Sub "arn:aws:dynamodb:us-east-1:${AWS::AccountId}:table/paychex-checkcomponents-period"
- Sid: PaychexIntegrationsSqsConsume
Effect: Allow
Action:
- sqs:ReceiveMessage
- sqs:DeleteMessage
- sqs:GetQueueAttributes
- sqs:ChangeMessageVisibility
Resource:
- !Sub "arn:aws:sqs:us-east-1:${AWS::AccountId}:paychex-webhook-events"
- !Sub "arn:aws:sqs:us-east-1:${AWS::AccountId}:paychex-login-delay"
- !Sub "arn:aws:sqs:us-east-1:${AWS::AccountId}:paychex-checkcomponents"
- Sid: PaychexIntegrationsSqsSend
Effect: Allow
Action:
- sqs:SendMessage
Resource:
- !Sub "arn:aws:sqs:us-east-1:${AWS::AccountId}:paychex-webhook-events"
- !Sub "arn:aws:sqs:us-east-1:${AWS::AccountId}:paychex-login-delay"
- Sid: PaychexIntegrationsSns
Effect: Allow
Action:
- sns:Publish
Resource:
- !Sub "arn:aws:sns:us-east-1:${AWS::AccountId}:site-alerts"
ProcurementIngestBoundary:
Type: AWS::IAM::ManagedPolicy