diff --git a/lib/deploy-substrate/deploy-substrate.template.yaml b/lib/deploy-substrate/deploy-substrate.template.yaml index 4bd811d..085786b 100644 --- a/lib/deploy-substrate/deploy-substrate.template.yaml +++ b/lib/deploy-substrate/deploy-substrate.template.yaml @@ -147,7 +147,9 @@ Description: >- # seahaven-lambda-execution-boundary-seahaven-site: 1159 / 6 statements # seahaven-lambda-execution-boundary-seahaven-door-unlock-api: measure after deploy (PLAT-76) # seahaven-lambda-execution-boundary-paychex-integrations: GetSecretValue on six minted ARNs (PLAT-122) -# Dev copies are floor-only (691 / 4) via IsProdAccount. +# Dev copies are floor-only (691 / 4) via IsProdAccount, except +# meal-order-manager (PLAT-210): DynamoDB/S3/SSM/invoke plus the +# seahaven-dev slack-bot-token ARN. SNS, SQS (Paychex), and SES stay prod. # # Guardrail PolicyDocuments also cap at 6,144. Each extra allow-list ARN # is copied into four Sids in EACH of SamCfnIamManagementPolicy and @@ -1075,43 +1077,42 @@ Resources: - secretsmanager:GetSecretValue Resource: - arn:aws:secretsmanager:us-east-1:011934824531:secret:meal-order-manager/slack-bot-token-ZGmSGw - - !Ref AWS::NoValue - - !If - - IsProdAccount - - Sid: MealOrderManagerDynamoDB + - Sid: MealOrderManagerSecrets Effect: Allow Action: - - dynamodb:GetItem - - dynamodb:PutItem - - dynamodb:UpdateItem - - dynamodb:DeleteItem - - dynamodb:Query - - dynamodb:Scan - - dynamodb:BatchGetItem - - dynamodb:BatchWriteItem - - dynamodb:DescribeTable - - dynamodb:ConditionCheckItem + - secretsmanager:GetSecretValue Resource: - - !Sub "arn:aws:dynamodb:us-east-1:${AWS::AccountId}:table/meal-order-manager-orders" - - !Sub "arn:aws:dynamodb:us-east-1:${AWS::AccountId}:table/meal-order-manager-orders/index/*" - - !Ref AWS::NoValue - - !If - - IsProdAccount - - Sid: MealOrderManagerS3 - Effect: Allow - Action: - - s3:GetObject* - - s3:GetBucket* - - s3:List* - - s3:PutObject* - - s3:DeleteObject* - - s3:AbortMultipartUpload - Resource: - - !Sub "arn:aws:s3:::meal-order-manager-form-${AWS::AccountId}" - - !Sub "arn:aws:s3:::meal-order-manager-form-${AWS::AccountId}/*" - - !Sub "arn:aws:s3:::meal-order-manager-reports-${AWS::AccountId}" - - !Sub "arn:aws:s3:::meal-order-manager-reports-${AWS::AccountId}/*" - - !Ref AWS::NoValue + - arn:aws:secretsmanager:us-east-1:710827005802:secret:meal-order-manager/slack-bot-token-y37snU + - Sid: MealOrderManagerDynamoDB + Effect: Allow + Action: + - dynamodb:GetItem + - dynamodb:PutItem + - dynamodb:UpdateItem + - dynamodb:DeleteItem + - dynamodb:Query + - dynamodb:Scan + - dynamodb:BatchGetItem + - dynamodb:BatchWriteItem + - dynamodb:DescribeTable + - dynamodb:ConditionCheckItem + Resource: + - !Sub "arn:aws:dynamodb:us-east-1:${AWS::AccountId}:table/meal-order-manager-orders" + - !Sub "arn:aws:dynamodb:us-east-1:${AWS::AccountId}:table/meal-order-manager-orders/index/*" + - Sid: MealOrderManagerS3 + Effect: Allow + Action: + - s3:GetObject* + - s3:GetBucket* + - s3:List* + - s3:PutObject* + - s3:DeleteObject* + - s3:AbortMultipartUpload + Resource: + - !Sub "arn:aws:s3:::meal-order-manager-form-${AWS::AccountId}" + - !Sub "arn:aws:s3:::meal-order-manager-form-${AWS::AccountId}/*" + - !Sub "arn:aws:s3:::meal-order-manager-reports-${AWS::AccountId}" + - !Sub "arn:aws:s3:::meal-order-manager-reports-${AWS::AccountId}/*" - !If - IsProdAccount - Sid: MealOrderManagerSns @@ -1123,7 +1124,8 @@ Resources: - !Ref AWS::NoValue # aggregate-orders enqueues the weekly meal-deduction payload onto # paychex-integrations' checkcomponents queue (PLAT-135). Send only; - # the paychex processor owns receive/delete. + # the paychex processor owns receive/delete. Not in seahaven-dev + # (PLAT-210: Paychex queue URLs stay empty). - !If - IsProdAccount - Sid: MealOrderManagerSqs @@ -1133,20 +1135,17 @@ Resources: Resource: - !Sub "arn:aws:sqs:us-east-1:${AWS::AccountId}:paychex-checkcomponents" - !Ref AWS::NoValue - - !If - - IsProdAccount - - Sid: MealOrderManager - Effect: Allow - Action: - - ssm:GetParameter - - lambda:InvokeFunction - - execute-api:Invoke - Resource: - - !Sub "arn:aws:ssm:us-east-1:${AWS::AccountId}:parameter/meal-order-manager/*" - - !Sub "arn:aws:lambda:us-east-1:${AWS::AccountId}:function:meal-order-manager-*" - - !Sub "arn:aws:execute-api:us-east-1:${AWS::AccountId}:*/*/GET/api/publish/settings" - - !Sub "arn:aws:execute-api:us-east-1:${AWS::AccountId}:*/*/POST/api/publish/menu" - - !Ref AWS::NoValue + - Sid: MealOrderManager + Effect: Allow + Action: + - ssm:GetParameter + - lambda:InvokeFunction + - execute-api:Invoke + Resource: + - !Sub "arn:aws:ssm:us-east-1:${AWS::AccountId}:parameter/meal-order-manager/*" + - !Sub "arn:aws:lambda:us-east-1:${AWS::AccountId}:function:meal-order-manager-*" + - !Sub "arn:aws:execute-api:us-east-1:${AWS::AccountId}:*/*/GET/api/publish/settings" + - !Sub "arn:aws:execute-api:us-east-1:${AWS::AccountId}:*/*/POST/api/publish/menu" - !If - IsProdAccount - Sid: MealOrderManagerSes