mirror of
https://github.com/Sea-Haven-Industries/seahaven-org-baseline.git
synced 2026-09-30 06:53:17 +00:00
fix(iam): enable meal-order-manager Lambda boundary in seahaven-dev (PLAT-210) (#149)
* fix(iam): enable meal-order-manager Lambda boundary in seahaven-dev (PLAT-210) The per-workload boundary was floor-only outside prod, so meals-dev Lambdas were denied DynamoDB. Keep Paychex SQS, SNS, and SES prod-only. * fix(iam): keep meal-order-manager boundary Description unchanged (PLAT-210) Named IAM managed-policy Description is immutable. Changing it replaces the resource and 409s on ManagedPolicyName. PolicyDocument still widens in place.
This commit is contained in:
parent
db9465deda
commit
c63b5e9779
1 changed files with 49 additions and 50 deletions
|
|
@ -147,7 +147,9 @@ Description: >-
|
|||
# seahaven-lambda-execution-boundary-seahaven-site: 1159 / 6 statements
|
||||
# seahaven-lambda-execution-boundary-seahaven-door-unlock-api: measure after deploy (PLAT-76)
|
||||
# seahaven-lambda-execution-boundary-paychex-integrations: GetSecretValue on six minted ARNs (PLAT-122)
|
||||
# Dev copies are floor-only (691 / 4) via IsProdAccount.
|
||||
# Dev copies are floor-only (691 / 4) via IsProdAccount, except
|
||||
# meal-order-manager (PLAT-210): DynamoDB/S3/SSM/invoke plus the
|
||||
# seahaven-dev slack-bot-token ARN. SNS, SQS (Paychex), and SES stay prod.
|
||||
#
|
||||
# Guardrail PolicyDocuments also cap at 6,144. Each extra allow-list ARN
|
||||
# is copied into four Sids in EACH of SamCfnIamManagementPolicy and
|
||||
|
|
@ -1075,9 +1077,12 @@ Resources:
|
|||
- secretsmanager:GetSecretValue
|
||||
Resource:
|
||||
- arn:aws:secretsmanager:us-east-1:011934824531:secret:meal-order-manager/slack-bot-token-ZGmSGw
|
||||
- !Ref AWS::NoValue
|
||||
- !If
|
||||
- IsProdAccount
|
||||
- Sid: MealOrderManagerSecrets
|
||||
Effect: Allow
|
||||
Action:
|
||||
- secretsmanager:GetSecretValue
|
||||
Resource:
|
||||
- arn:aws:secretsmanager:us-east-1:710827005802:secret:meal-order-manager/slack-bot-token-y37snU
|
||||
- Sid: MealOrderManagerDynamoDB
|
||||
Effect: Allow
|
||||
Action:
|
||||
|
|
@ -1094,9 +1099,6 @@ Resources:
|
|||
Resource:
|
||||
- !Sub "arn:aws:dynamodb:us-east-1:${AWS::AccountId}:table/meal-order-manager-orders"
|
||||
- !Sub "arn:aws:dynamodb:us-east-1:${AWS::AccountId}:table/meal-order-manager-orders/index/*"
|
||||
- !Ref AWS::NoValue
|
||||
- !If
|
||||
- IsProdAccount
|
||||
- Sid: MealOrderManagerS3
|
||||
Effect: Allow
|
||||
Action:
|
||||
|
|
@ -1111,7 +1113,6 @@ Resources:
|
|||
- !Sub "arn:aws:s3:::meal-order-manager-form-${AWS::AccountId}/*"
|
||||
- !Sub "arn:aws:s3:::meal-order-manager-reports-${AWS::AccountId}"
|
||||
- !Sub "arn:aws:s3:::meal-order-manager-reports-${AWS::AccountId}/*"
|
||||
- !Ref AWS::NoValue
|
||||
- !If
|
||||
- IsProdAccount
|
||||
- Sid: MealOrderManagerSns
|
||||
|
|
@ -1123,7 +1124,8 @@ Resources:
|
|||
- !Ref AWS::NoValue
|
||||
# aggregate-orders enqueues the weekly meal-deduction payload onto
|
||||
# paychex-integrations' checkcomponents queue (PLAT-135). Send only;
|
||||
# the paychex processor owns receive/delete.
|
||||
# the paychex processor owns receive/delete. Not in seahaven-dev
|
||||
# (PLAT-210: Paychex queue URLs stay empty).
|
||||
- !If
|
||||
- IsProdAccount
|
||||
- Sid: MealOrderManagerSqs
|
||||
|
|
@ -1133,8 +1135,6 @@ Resources:
|
|||
Resource:
|
||||
- !Sub "arn:aws:sqs:us-east-1:${AWS::AccountId}:paychex-checkcomponents"
|
||||
- !Ref AWS::NoValue
|
||||
- !If
|
||||
- IsProdAccount
|
||||
- Sid: MealOrderManager
|
||||
Effect: Allow
|
||||
Action:
|
||||
|
|
@ -1146,7 +1146,6 @@ Resources:
|
|||
- !Sub "arn:aws:lambda:us-east-1:${AWS::AccountId}:function:meal-order-manager-*"
|
||||
- !Sub "arn:aws:execute-api:us-east-1:${AWS::AccountId}:*/*/GET/api/publish/settings"
|
||||
- !Sub "arn:aws:execute-api:us-east-1:${AWS::AccountId}:*/*/POST/api/publish/menu"
|
||||
- !Ref AWS::NoValue
|
||||
- !If
|
||||
- IsProdAccount
|
||||
- Sid: MealOrderManagerSes
|
||||
|
|
|
|||
Loading…
Add table
Reference in a new issue