fix(iam): keep meal-order-manager boundary Description unchanged (PLAT-210)

Named IAM managed-policy Description is immutable. Changing it replaces the
resource and 409s on ManagedPolicyName. PolicyDocument still widens in place.
This commit is contained in:
Adam Moussa 2026-09-18 14:30:33 -04:00
parent 496a702339
commit c1db5ae089
No known key found for this signature in database

View file

@ -1057,10 +1057,9 @@ Resources:
ManagedPolicyName: seahaven-lambda-execution-boundary-meal-order-manager
Description: >-
Per-workload permissions boundary for meal-order-manager (PLAT-52).
Floor plus secrets, orders table, form/reports buckets, SSM/invoke/
execute-api in both prod and seahaven-dev (PLAT-210). site-alerts,
Paychex SQS, and SES stay prod-only. Shared policy remains the
live-role ceiling until app retarget.
Floor plus secrets, orders table, form/reports buckets, site-alerts,
SSM/invoke/execute-api, and SES. Shared policy remains the live-role
ceiling until app retarget.
PolicyDocument:
Version: "2012-10-17"
Statement: