mirror of
https://github.com/Sea-Haven-Industries/seahaven-org-baseline.git
synced 2026-09-30 05:43:17 +00:00
fix(iam): enable meal-order-manager Lambda boundary in seahaven-dev (PLAT-210) (#149)
* fix(iam): enable meal-order-manager Lambda boundary in seahaven-dev (PLAT-210) The per-workload boundary was floor-only outside prod, so meals-dev Lambdas were denied DynamoDB. Keep Paychex SQS, SNS, and SES prod-only. * fix(iam): keep meal-order-manager boundary Description unchanged (PLAT-210) Named IAM managed-policy Description is immutable. Changing it replaces the resource and 409s on ManagedPolicyName. PolicyDocument still widens in place.
This commit is contained in:
parent
db9465deda
commit
c63b5e9779
1 changed files with 49 additions and 50 deletions
|
|
@ -147,7 +147,9 @@ Description: >-
|
||||||
# seahaven-lambda-execution-boundary-seahaven-site: 1159 / 6 statements
|
# seahaven-lambda-execution-boundary-seahaven-site: 1159 / 6 statements
|
||||||
# seahaven-lambda-execution-boundary-seahaven-door-unlock-api: measure after deploy (PLAT-76)
|
# seahaven-lambda-execution-boundary-seahaven-door-unlock-api: measure after deploy (PLAT-76)
|
||||||
# seahaven-lambda-execution-boundary-paychex-integrations: GetSecretValue on six minted ARNs (PLAT-122)
|
# seahaven-lambda-execution-boundary-paychex-integrations: GetSecretValue on six minted ARNs (PLAT-122)
|
||||||
# Dev copies are floor-only (691 / 4) via IsProdAccount.
|
# Dev copies are floor-only (691 / 4) via IsProdAccount, except
|
||||||
|
# meal-order-manager (PLAT-210): DynamoDB/S3/SSM/invoke plus the
|
||||||
|
# seahaven-dev slack-bot-token ARN. SNS, SQS (Paychex), and SES stay prod.
|
||||||
#
|
#
|
||||||
# Guardrail PolicyDocuments also cap at 6,144. Each extra allow-list ARN
|
# Guardrail PolicyDocuments also cap at 6,144. Each extra allow-list ARN
|
||||||
# is copied into four Sids in EACH of SamCfnIamManagementPolicy and
|
# is copied into four Sids in EACH of SamCfnIamManagementPolicy and
|
||||||
|
|
@ -1075,43 +1077,42 @@ Resources:
|
||||||
- secretsmanager:GetSecretValue
|
- secretsmanager:GetSecretValue
|
||||||
Resource:
|
Resource:
|
||||||
- arn:aws:secretsmanager:us-east-1:011934824531:secret:meal-order-manager/slack-bot-token-ZGmSGw
|
- arn:aws:secretsmanager:us-east-1:011934824531:secret:meal-order-manager/slack-bot-token-ZGmSGw
|
||||||
- !Ref AWS::NoValue
|
- Sid: MealOrderManagerSecrets
|
||||||
- !If
|
|
||||||
- IsProdAccount
|
|
||||||
- Sid: MealOrderManagerDynamoDB
|
|
||||||
Effect: Allow
|
Effect: Allow
|
||||||
Action:
|
Action:
|
||||||
- dynamodb:GetItem
|
- secretsmanager:GetSecretValue
|
||||||
- dynamodb:PutItem
|
|
||||||
- dynamodb:UpdateItem
|
|
||||||
- dynamodb:DeleteItem
|
|
||||||
- dynamodb:Query
|
|
||||||
- dynamodb:Scan
|
|
||||||
- dynamodb:BatchGetItem
|
|
||||||
- dynamodb:BatchWriteItem
|
|
||||||
- dynamodb:DescribeTable
|
|
||||||
- dynamodb:ConditionCheckItem
|
|
||||||
Resource:
|
Resource:
|
||||||
- !Sub "arn:aws:dynamodb:us-east-1:${AWS::AccountId}:table/meal-order-manager-orders"
|
- arn:aws:secretsmanager:us-east-1:710827005802:secret:meal-order-manager/slack-bot-token-y37snU
|
||||||
- !Sub "arn:aws:dynamodb:us-east-1:${AWS::AccountId}:table/meal-order-manager-orders/index/*"
|
- Sid: MealOrderManagerDynamoDB
|
||||||
- !Ref AWS::NoValue
|
Effect: Allow
|
||||||
- !If
|
Action:
|
||||||
- IsProdAccount
|
- dynamodb:GetItem
|
||||||
- Sid: MealOrderManagerS3
|
- dynamodb:PutItem
|
||||||
Effect: Allow
|
- dynamodb:UpdateItem
|
||||||
Action:
|
- dynamodb:DeleteItem
|
||||||
- s3:GetObject*
|
- dynamodb:Query
|
||||||
- s3:GetBucket*
|
- dynamodb:Scan
|
||||||
- s3:List*
|
- dynamodb:BatchGetItem
|
||||||
- s3:PutObject*
|
- dynamodb:BatchWriteItem
|
||||||
- s3:DeleteObject*
|
- dynamodb:DescribeTable
|
||||||
- s3:AbortMultipartUpload
|
- dynamodb:ConditionCheckItem
|
||||||
Resource:
|
Resource:
|
||||||
- !Sub "arn:aws:s3:::meal-order-manager-form-${AWS::AccountId}"
|
- !Sub "arn:aws:dynamodb:us-east-1:${AWS::AccountId}:table/meal-order-manager-orders"
|
||||||
- !Sub "arn:aws:s3:::meal-order-manager-form-${AWS::AccountId}/*"
|
- !Sub "arn:aws:dynamodb:us-east-1:${AWS::AccountId}:table/meal-order-manager-orders/index/*"
|
||||||
- !Sub "arn:aws:s3:::meal-order-manager-reports-${AWS::AccountId}"
|
- Sid: MealOrderManagerS3
|
||||||
- !Sub "arn:aws:s3:::meal-order-manager-reports-${AWS::AccountId}/*"
|
Effect: Allow
|
||||||
- !Ref AWS::NoValue
|
Action:
|
||||||
|
- s3:GetObject*
|
||||||
|
- s3:GetBucket*
|
||||||
|
- s3:List*
|
||||||
|
- s3:PutObject*
|
||||||
|
- s3:DeleteObject*
|
||||||
|
- s3:AbortMultipartUpload
|
||||||
|
Resource:
|
||||||
|
- !Sub "arn:aws:s3:::meal-order-manager-form-${AWS::AccountId}"
|
||||||
|
- !Sub "arn:aws:s3:::meal-order-manager-form-${AWS::AccountId}/*"
|
||||||
|
- !Sub "arn:aws:s3:::meal-order-manager-reports-${AWS::AccountId}"
|
||||||
|
- !Sub "arn:aws:s3:::meal-order-manager-reports-${AWS::AccountId}/*"
|
||||||
- !If
|
- !If
|
||||||
- IsProdAccount
|
- IsProdAccount
|
||||||
- Sid: MealOrderManagerSns
|
- Sid: MealOrderManagerSns
|
||||||
|
|
@ -1123,7 +1124,8 @@ Resources:
|
||||||
- !Ref AWS::NoValue
|
- !Ref AWS::NoValue
|
||||||
# aggregate-orders enqueues the weekly meal-deduction payload onto
|
# aggregate-orders enqueues the weekly meal-deduction payload onto
|
||||||
# paychex-integrations' checkcomponents queue (PLAT-135). Send only;
|
# paychex-integrations' checkcomponents queue (PLAT-135). Send only;
|
||||||
# the paychex processor owns receive/delete.
|
# the paychex processor owns receive/delete. Not in seahaven-dev
|
||||||
|
# (PLAT-210: Paychex queue URLs stay empty).
|
||||||
- !If
|
- !If
|
||||||
- IsProdAccount
|
- IsProdAccount
|
||||||
- Sid: MealOrderManagerSqs
|
- Sid: MealOrderManagerSqs
|
||||||
|
|
@ -1133,20 +1135,17 @@ Resources:
|
||||||
Resource:
|
Resource:
|
||||||
- !Sub "arn:aws:sqs:us-east-1:${AWS::AccountId}:paychex-checkcomponents"
|
- !Sub "arn:aws:sqs:us-east-1:${AWS::AccountId}:paychex-checkcomponents"
|
||||||
- !Ref AWS::NoValue
|
- !Ref AWS::NoValue
|
||||||
- !If
|
- Sid: MealOrderManager
|
||||||
- IsProdAccount
|
Effect: Allow
|
||||||
- Sid: MealOrderManager
|
Action:
|
||||||
Effect: Allow
|
- ssm:GetParameter
|
||||||
Action:
|
- lambda:InvokeFunction
|
||||||
- ssm:GetParameter
|
- execute-api:Invoke
|
||||||
- lambda:InvokeFunction
|
Resource:
|
||||||
- execute-api:Invoke
|
- !Sub "arn:aws:ssm:us-east-1:${AWS::AccountId}:parameter/meal-order-manager/*"
|
||||||
Resource:
|
- !Sub "arn:aws:lambda:us-east-1:${AWS::AccountId}:function:meal-order-manager-*"
|
||||||
- !Sub "arn:aws:ssm:us-east-1:${AWS::AccountId}:parameter/meal-order-manager/*"
|
- !Sub "arn:aws:execute-api:us-east-1:${AWS::AccountId}:*/*/GET/api/publish/settings"
|
||||||
- !Sub "arn:aws:lambda:us-east-1:${AWS::AccountId}:function:meal-order-manager-*"
|
- !Sub "arn:aws:execute-api:us-east-1:${AWS::AccountId}:*/*/POST/api/publish/menu"
|
||||||
- !Sub "arn:aws:execute-api:us-east-1:${AWS::AccountId}:*/*/GET/api/publish/settings"
|
|
||||||
- !Sub "arn:aws:execute-api:us-east-1:${AWS::AccountId}:*/*/POST/api/publish/menu"
|
|
||||||
- !Ref AWS::NoValue
|
|
||||||
- !If
|
- !If
|
||||||
- IsProdAccount
|
- IsProdAccount
|
||||||
- Sid: MealOrderManagerSes
|
- Sid: MealOrderManagerSes
|
||||||
|
|
|
||||||
Loading…
Add table
Reference in a new issue