fix(iam): enable meal-order-manager Lambda boundary in seahaven-dev (PLAT-210) (#149)
Some checks are pending
Deploy / deploy-management (push) Waiting to run
Deploy / deploy-external-dev (push) Waiting to run
Deploy / deploy-security (push) Waiting to run
Deploy / deploy-dev (push) Waiting to run
Deploy / deploy-prod (push) Waiting to run

* fix(iam): enable meal-order-manager Lambda boundary in seahaven-dev (PLAT-210)

The per-workload boundary was floor-only outside prod, so meals-dev Lambdas
were denied DynamoDB. Keep Paychex SQS, SNS, and SES prod-only.

* fix(iam): keep meal-order-manager boundary Description unchanged (PLAT-210)

Named IAM managed-policy Description is immutable. Changing it replaces the
resource and 409s on ManagedPolicyName. PolicyDocument still widens in place.
This commit is contained in:
Adam Moussa 2026-09-18 18:35:38 +00:00 • committed by GitHub
parent db9465deda
commit c63b5e9779
No known key found for this signature in database
GPG key ID: B5690EEEBB952194

View file

@ -147,7 +147,9 @@ Description: >-
# seahaven-lambda-execution-boundary-seahaven-site: 1159 / 6 statements # seahaven-lambda-execution-boundary-seahaven-site: 1159 / 6 statements
# seahaven-lambda-execution-boundary-seahaven-door-unlock-api: measure after deploy (PLAT-76) # seahaven-lambda-execution-boundary-seahaven-door-unlock-api: measure after deploy (PLAT-76)
# seahaven-lambda-execution-boundary-paychex-integrations: GetSecretValue on six minted ARNs (PLAT-122) # seahaven-lambda-execution-boundary-paychex-integrations: GetSecretValue on six minted ARNs (PLAT-122)
# Dev copies are floor-only (691 / 4) via IsProdAccount. # Dev copies are floor-only (691 / 4) via IsProdAccount, except
# meal-order-manager (PLAT-210): DynamoDB/S3/SSM/invoke plus the
# seahaven-dev slack-bot-token ARN. SNS, SQS (Paychex), and SES stay prod.
# #
# Guardrail PolicyDocuments also cap at 6,144. Each extra allow-list ARN # Guardrail PolicyDocuments also cap at 6,144. Each extra allow-list ARN
# is copied into four Sids in EACH of SamCfnIamManagementPolicy and # is copied into four Sids in EACH of SamCfnIamManagementPolicy and
@ -1075,43 +1077,42 @@ Resources:
- secretsmanager:GetSecretValue - secretsmanager:GetSecretValue
Resource: Resource:
- arn:aws:secretsmanager:us-east-1:011934824531:secret:meal-order-manager/slack-bot-token-ZGmSGw - arn:aws:secretsmanager:us-east-1:011934824531:secret:meal-order-manager/slack-bot-token-ZGmSGw
- !Ref AWS::NoValue - Sid: MealOrderManagerSecrets
- !If
- IsProdAccount
- Sid: MealOrderManagerDynamoDB
Effect: Allow Effect: Allow
Action: Action:
- dynamodb:GetItem - secretsmanager:GetSecretValue
- dynamodb:PutItem
- dynamodb:UpdateItem
- dynamodb:DeleteItem
- dynamodb:Query
- dynamodb:Scan
- dynamodb:BatchGetItem
- dynamodb:BatchWriteItem
- dynamodb:DescribeTable
- dynamodb:ConditionCheckItem
Resource: Resource:
- !Sub "arn:aws:dynamodb:us-east-1:${AWS::AccountId}:table/meal-order-manager-orders" - arn:aws:secretsmanager:us-east-1:710827005802:secret:meal-order-manager/slack-bot-token-y37snU
- !Sub "arn:aws:dynamodb:us-east-1:${AWS::AccountId}:table/meal-order-manager-orders/index/*" - Sid: MealOrderManagerDynamoDB
- !Ref AWS::NoValue Effect: Allow
- !If Action:
- IsProdAccount - dynamodb:GetItem
- Sid: MealOrderManagerS3 - dynamodb:PutItem
Effect: Allow - dynamodb:UpdateItem
Action: - dynamodb:DeleteItem
- s3:GetObject* - dynamodb:Query
- s3:GetBucket* - dynamodb:Scan
- s3:List* - dynamodb:BatchGetItem
- s3:PutObject* - dynamodb:BatchWriteItem
- s3:DeleteObject* - dynamodb:DescribeTable
- s3:AbortMultipartUpload - dynamodb:ConditionCheckItem
Resource: Resource:
- !Sub "arn:aws:s3:::meal-order-manager-form-${AWS::AccountId}" - !Sub "arn:aws:dynamodb:us-east-1:${AWS::AccountId}:table/meal-order-manager-orders"
- !Sub "arn:aws:s3:::meal-order-manager-form-${AWS::AccountId}/*" - !Sub "arn:aws:dynamodb:us-east-1:${AWS::AccountId}:table/meal-order-manager-orders/index/*"
- !Sub "arn:aws:s3:::meal-order-manager-reports-${AWS::AccountId}" - Sid: MealOrderManagerS3
- !Sub "arn:aws:s3:::meal-order-manager-reports-${AWS::AccountId}/*" Effect: Allow
- !Ref AWS::NoValue Action:
- s3:GetObject*
- s3:GetBucket*
- s3:List*
- s3:PutObject*
- s3:DeleteObject*
- s3:AbortMultipartUpload
Resource:
- !Sub "arn:aws:s3:::meal-order-manager-form-${AWS::AccountId}"
- !Sub "arn:aws:s3:::meal-order-manager-form-${AWS::AccountId}/*"
- !Sub "arn:aws:s3:::meal-order-manager-reports-${AWS::AccountId}"
- !Sub "arn:aws:s3:::meal-order-manager-reports-${AWS::AccountId}/*"
- !If - !If
- IsProdAccount - IsProdAccount
- Sid: MealOrderManagerSns - Sid: MealOrderManagerSns
@ -1123,7 +1124,8 @@ Resources:
- !Ref AWS::NoValue - !Ref AWS::NoValue
# aggregate-orders enqueues the weekly meal-deduction payload onto # aggregate-orders enqueues the weekly meal-deduction payload onto
# paychex-integrations' checkcomponents queue (PLAT-135). Send only; # paychex-integrations' checkcomponents queue (PLAT-135). Send only;
# the paychex processor owns receive/delete. # the paychex processor owns receive/delete. Not in seahaven-dev
# (PLAT-210: Paychex queue URLs stay empty).
- !If - !If
- IsProdAccount - IsProdAccount
- Sid: MealOrderManagerSqs - Sid: MealOrderManagerSqs
@ -1133,20 +1135,17 @@ Resources:
Resource: Resource:
- !Sub "arn:aws:sqs:us-east-1:${AWS::AccountId}:paychex-checkcomponents" - !Sub "arn:aws:sqs:us-east-1:${AWS::AccountId}:paychex-checkcomponents"
- !Ref AWS::NoValue - !Ref AWS::NoValue
- !If - Sid: MealOrderManager
- IsProdAccount Effect: Allow
- Sid: MealOrderManager Action:
Effect: Allow - ssm:GetParameter
Action: - lambda:InvokeFunction
- ssm:GetParameter - execute-api:Invoke
- lambda:InvokeFunction Resource:
- execute-api:Invoke - !Sub "arn:aws:ssm:us-east-1:${AWS::AccountId}:parameter/meal-order-manager/*"
Resource: - !Sub "arn:aws:lambda:us-east-1:${AWS::AccountId}:function:meal-order-manager-*"
- !Sub "arn:aws:ssm:us-east-1:${AWS::AccountId}:parameter/meal-order-manager/*" - !Sub "arn:aws:execute-api:us-east-1:${AWS::AccountId}:*/*/GET/api/publish/settings"
- !Sub "arn:aws:lambda:us-east-1:${AWS::AccountId}:function:meal-order-manager-*" - !Sub "arn:aws:execute-api:us-east-1:${AWS::AccountId}:*/*/POST/api/publish/menu"
- !Sub "arn:aws:execute-api:us-east-1:${AWS::AccountId}:*/*/GET/api/publish/settings"
- !Sub "arn:aws:execute-api:us-east-1:${AWS::AccountId}:*/*/POST/api/publish/menu"
- !Ref AWS::NoValue
- !If - !If
- IsProdAccount - IsProdAccount
- Sid: MealOrderManagerSes - Sid: MealOrderManagerSes