fix(iam): update paychex boundary in place without fn if (PLAT-122) (#129)
Some checks are pending
Deploy / deploy-management (push) Waiting to run
Deploy / deploy-external-dev (push) Waiting to run
Deploy / deploy-security (push) Waiting to run
Deploy / deploy-dev (push) Waiting to run
Deploy / deploy-prod (push) Waiting to run

* fix(iam): update paychex boundary in place without fn if

CloudFormation replaced the named managed policy when the secrets statement was wrapped in Fn::If (409 duplicate name). Keep the six minted ARNs as a static statement so the document updates in place.

* fix(iam): leave paychex boundary description unchanged

Keep the live ManagedPolicy Description so CloudFormation only updates PolicyDocument.
This commit is contained in:
Adam Moussa 2026-08-27 23:56:49 +00:00 • committed by GitHub
parent f7cc67819b
commit e21d08bf23
No known key found for this signature in database
GPG key ID: B5690EEEBB952194

View file

@ -852,8 +852,8 @@ Resources:
Properties:
ManagedPolicyName: seahaven-lambda-execution-boundary-paychex-integrations
Description: >-
Per-workload permissions boundary for paychex-integrations (PLAT-122).
GetSecretValue pinned to the six minted secret ARNs.
Per-workload permissions boundary for paychex-integrations (PLAT-120).
Floor only until first HCP apply mints secret suffixes.
PolicyDocument:
Version: "2012-10-17"
Statement:
@ -863,20 +863,20 @@ Resources:
- *lambdaBoundaryFloorLogsDescribe
- *lambdaBoundaryFloorXRay
- *lambdaBoundaryFloorEc2Eni
- !If
- IsProdAccount
- Sid: PaychexIntegrationsSecrets
Effect: Allow
Action:
- secretsmanager:GetSecretValue
Resource:
- arn:aws:secretsmanager:us-east-1:011934824531:secret:paychex-integrations/oauth-client-2WfF5w
- arn:aws:secretsmanager:us-east-1:011934824531:secret:paychex-integrations/webhook-api-key-44b0jB
- arn:aws:secretsmanager:us-east-1:011934824531:secret:paychex-integrations/google-service-account-PcUeJD
- arn:aws:secretsmanager:us-east-1:011934824531:secret:paychex-integrations/slack-bot-token-L8DntD
- arn:aws:secretsmanager:us-east-1:011934824531:secret:paychex-integrations/front-inboxes-write-v6niDC
- arn:aws:secretsmanager:us-east-1:011934824531:secret:paychex-integrations/3cx-system-admin-PcUeJD
- !Ref AWS::NoValue
# Unconditional (not !If): adding Fn::If to this named managed policy
# made CloudFormation replace it (409 duplicate ManagedPolicyName) on
# seahaven-deploy-substrate. Prod ARNs are a no-op in other accounts.
- Sid: PaychexIntegrationsSecrets
Effect: Allow
Action:
- secretsmanager:GetSecretValue
Resource:
- arn:aws:secretsmanager:us-east-1:011934824531:secret:paychex-integrations/oauth-client-2WfF5w
- arn:aws:secretsmanager:us-east-1:011934824531:secret:paychex-integrations/webhook-api-key-44b0jB
- arn:aws:secretsmanager:us-east-1:011934824531:secret:paychex-integrations/google-service-account-PcUeJD
- arn:aws:secretsmanager:us-east-1:011934824531:secret:paychex-integrations/slack-bot-token-L8DntD
- arn:aws:secretsmanager:us-east-1:011934824531:secret:paychex-integrations/front-inboxes-write-v6niDC
- arn:aws:secretsmanager:us-east-1:011934824531:secret:paychex-integrations/3cx-system-admin-PcUeJD
ProcurementIngestBoundary:
Type: AWS::IAM::ManagedPolicy