From c1db5ae0895c70dacffe368431cb1702247b5b78 Mon Sep 17 00:00:00 2001 From: Adam Moussa Date: Fri, 18 Sep 2026 14:30:33 -0400 Subject: [PATCH] fix(iam): keep meal-order-manager boundary Description unchanged (PLAT-210) Named IAM managed-policy Description is immutable. Changing it replaces the resource and 409s on ManagedPolicyName. PolicyDocument still widens in place. --- lib/deploy-substrate/deploy-substrate.template.yaml | 7 +++---- 1 file changed, 3 insertions(+), 4 deletions(-) diff --git a/lib/deploy-substrate/deploy-substrate.template.yaml b/lib/deploy-substrate/deploy-substrate.template.yaml index 28d4a93..085786b 100644 --- a/lib/deploy-substrate/deploy-substrate.template.yaml +++ b/lib/deploy-substrate/deploy-substrate.template.yaml @@ -1057,10 +1057,9 @@ Resources: ManagedPolicyName: seahaven-lambda-execution-boundary-meal-order-manager Description: >- Per-workload permissions boundary for meal-order-manager (PLAT-52). - Floor plus secrets, orders table, form/reports buckets, SSM/invoke/ - execute-api in both prod and seahaven-dev (PLAT-210). site-alerts, - Paychex SQS, and SES stay prod-only. Shared policy remains the - live-role ceiling until app retarget. + Floor plus secrets, orders table, form/reports buckets, site-alerts, + SSM/invoke/execute-api, and SES. Shared policy remains the live-role + ceiling until app retarget. PolicyDocument: Version: "2012-10-17" Statement: