mirror of
https://github.com/Sea-Haven-Industries/seahaven-org-baseline.git
synced 2026-09-30 03:23:15 +00:00
fix(iam): update paychex boundary in place without fn if (PLAT-122) (#129)
* fix(iam): update paychex boundary in place without fn if CloudFormation replaced the named managed policy when the secrets statement was wrapped in Fn::If (409 duplicate name). Keep the six minted ARNs as a static statement so the document updates in place. * fix(iam): leave paychex boundary description unchanged Keep the live ManagedPolicy Description so CloudFormation only updates PolicyDocument.
This commit is contained in:
parent
f7cc67819b
commit
e21d08bf23
1 changed files with 16 additions and 16 deletions
|
|
@ -852,8 +852,8 @@ Resources:
|
|||
Properties:
|
||||
ManagedPolicyName: seahaven-lambda-execution-boundary-paychex-integrations
|
||||
Description: >-
|
||||
Per-workload permissions boundary for paychex-integrations (PLAT-122).
|
||||
GetSecretValue pinned to the six minted secret ARNs.
|
||||
Per-workload permissions boundary for paychex-integrations (PLAT-120).
|
||||
Floor only until first HCP apply mints secret suffixes.
|
||||
PolicyDocument:
|
||||
Version: "2012-10-17"
|
||||
Statement:
|
||||
|
|
@ -863,20 +863,20 @@ Resources:
|
|||
- *lambdaBoundaryFloorLogsDescribe
|
||||
- *lambdaBoundaryFloorXRay
|
||||
- *lambdaBoundaryFloorEc2Eni
|
||||
- !If
|
||||
- IsProdAccount
|
||||
- Sid: PaychexIntegrationsSecrets
|
||||
Effect: Allow
|
||||
Action:
|
||||
- secretsmanager:GetSecretValue
|
||||
Resource:
|
||||
- arn:aws:secretsmanager:us-east-1:011934824531:secret:paychex-integrations/oauth-client-2WfF5w
|
||||
- arn:aws:secretsmanager:us-east-1:011934824531:secret:paychex-integrations/webhook-api-key-44b0jB
|
||||
- arn:aws:secretsmanager:us-east-1:011934824531:secret:paychex-integrations/google-service-account-PcUeJD
|
||||
- arn:aws:secretsmanager:us-east-1:011934824531:secret:paychex-integrations/slack-bot-token-L8DntD
|
||||
- arn:aws:secretsmanager:us-east-1:011934824531:secret:paychex-integrations/front-inboxes-write-v6niDC
|
||||
- arn:aws:secretsmanager:us-east-1:011934824531:secret:paychex-integrations/3cx-system-admin-PcUeJD
|
||||
- !Ref AWS::NoValue
|
||||
# Unconditional (not !If): adding Fn::If to this named managed policy
|
||||
# made CloudFormation replace it (409 duplicate ManagedPolicyName) on
|
||||
# seahaven-deploy-substrate. Prod ARNs are a no-op in other accounts.
|
||||
- Sid: PaychexIntegrationsSecrets
|
||||
Effect: Allow
|
||||
Action:
|
||||
- secretsmanager:GetSecretValue
|
||||
Resource:
|
||||
- arn:aws:secretsmanager:us-east-1:011934824531:secret:paychex-integrations/oauth-client-2WfF5w
|
||||
- arn:aws:secretsmanager:us-east-1:011934824531:secret:paychex-integrations/webhook-api-key-44b0jB
|
||||
- arn:aws:secretsmanager:us-east-1:011934824531:secret:paychex-integrations/google-service-account-PcUeJD
|
||||
- arn:aws:secretsmanager:us-east-1:011934824531:secret:paychex-integrations/slack-bot-token-L8DntD
|
||||
- arn:aws:secretsmanager:us-east-1:011934824531:secret:paychex-integrations/front-inboxes-write-v6niDC
|
||||
- arn:aws:secretsmanager:us-east-1:011934824531:secret:paychex-integrations/3cx-system-admin-PcUeJD
|
||||
|
||||
ProcurementIngestBoundary:
|
||||
Type: AWS::IAM::ManagedPolicy
|
||||
|
|
|
|||
Loading…
Add table
Reference in a new issue