From af47bf645542eefd308bcb52990c16ec804f012e Mon Sep 17 00:00:00 2001 From: Adam Moussa Date: Mon, 14 Sep 2026 14:10:47 -0400 Subject: [PATCH] fix(iam): allow paychex period table and optional secrets (PLAT-195) The processor role already allows these ARNs. The live boundary denied them, so GetSecretValue and period PutItem returned HTTP 400. Sync the template to the live ceiling and add the missing period table plus slack-admin and afterhours secret suffixes. --- .../deploy-substrate.template.yaml | 36 +++++++++++++++++-- 1 file changed, 34 insertions(+), 2 deletions(-) diff --git a/lib/deploy-substrate/deploy-substrate.template.yaml b/lib/deploy-substrate/deploy-substrate.template.yaml index 0b787f0..56f095b 100644 --- a/lib/deploy-substrate/deploy-substrate.template.yaml +++ b/lib/deploy-substrate/deploy-substrate.template.yaml @@ -853,8 +853,8 @@ Resources: Properties: ManagedPolicyName: seahaven-lambda-execution-boundary-paychex-integrations Description: >- - Per-workload permissions boundary for paychex-integrations (PLAT-120). - Floor only until first HCP apply mints secret suffixes. + Per-workload permissions boundary for paychex-integrations (PLAT-120, + PLAT-195). Floor plus minted secret ARNs and processor data plane. PolicyDocument: Version: "2012-10-17" Statement: @@ -876,8 +876,10 @@ Resources: - arn:aws:secretsmanager:us-east-1:011934824531:secret:paychex-integrations/webhook-api-key-44b0jB - arn:aws:secretsmanager:us-east-1:011934824531:secret:paychex-integrations/google-service-account-PcUeJD - arn:aws:secretsmanager:us-east-1:011934824531:secret:paychex-integrations/slack-bot-token-L8DntD + - arn:aws:secretsmanager:us-east-1:011934824531:secret:paychex-integrations/slack-admin-token-LHr2VD - arn:aws:secretsmanager:us-east-1:011934824531:secret:paychex-integrations/front-inboxes-write-v6niDC - arn:aws:secretsmanager:us-east-1:011934824531:secret:paychex-integrations/3cx-system-admin-PcUeJD + - arn:aws:secretsmanager:us-east-1:011934824531:secret:paychex-integrations/afterhours-roster-token-j3yCh7 - Sid: PaychexIntegrationsDynamoDB Effect: Allow Action: @@ -887,8 +889,38 @@ Resources: - dynamodb:DeleteItem - dynamodb:ConditionCheckItem - dynamodb:DescribeTable + - dynamodb:Query Resource: - !Sub "arn:aws:dynamodb:us-east-1:${AWS::AccountId}:table/paychex-worker-ledger" + - !Sub "arn:aws:dynamodb:us-east-1:${AWS::AccountId}:table/paychex-worker-ledger/index/*" + - !Sub "arn:aws:dynamodb:us-east-1:${AWS::AccountId}:table/paychex-webhook-notifications" + - !Sub "arn:aws:dynamodb:us-east-1:${AWS::AccountId}:table/paychex-payroll-notices" + - !Sub "arn:aws:dynamodb:us-east-1:${AWS::AccountId}:table/paychex-checkcomponents-posted" + - !Sub "arn:aws:dynamodb:us-east-1:${AWS::AccountId}:table/paychex-checkcomponents-period" + - Sid: PaychexIntegrationsSqsConsume + Effect: Allow + Action: + - sqs:ReceiveMessage + - sqs:DeleteMessage + - sqs:GetQueueAttributes + - sqs:ChangeMessageVisibility + Resource: + - !Sub "arn:aws:sqs:us-east-1:${AWS::AccountId}:paychex-webhook-events" + - !Sub "arn:aws:sqs:us-east-1:${AWS::AccountId}:paychex-login-delay" + - !Sub "arn:aws:sqs:us-east-1:${AWS::AccountId}:paychex-checkcomponents" + - Sid: PaychexIntegrationsSqsSend + Effect: Allow + Action: + - sqs:SendMessage + Resource: + - !Sub "arn:aws:sqs:us-east-1:${AWS::AccountId}:paychex-webhook-events" + - !Sub "arn:aws:sqs:us-east-1:${AWS::AccountId}:paychex-login-delay" + - Sid: PaychexIntegrationsSns + Effect: Allow + Action: + - sns:Publish + Resource: + - !Sub "arn:aws:sns:us-east-1:${AWS::AccountId}:site-alerts" ProcurementIngestBoundary: Type: AWS::IAM::ManagedPolicy