diff --git a/lib/deploy-substrate/deploy-substrate.template.yaml b/lib/deploy-substrate/deploy-substrate.template.yaml index 298828f..a65aa92 100644 --- a/lib/deploy-substrate/deploy-substrate.template.yaml +++ b/lib/deploy-substrate/deploy-substrate.template.yaml @@ -852,8 +852,8 @@ Resources: Properties: ManagedPolicyName: seahaven-lambda-execution-boundary-paychex-integrations Description: >- - Per-workload permissions boundary for paychex-integrations (PLAT-122). - GetSecretValue pinned to the six minted secret ARNs. + Per-workload permissions boundary for paychex-integrations (PLAT-120). + Floor only until first HCP apply mints secret suffixes. PolicyDocument: Version: "2012-10-17" Statement: @@ -863,20 +863,20 @@ Resources: - *lambdaBoundaryFloorLogsDescribe - *lambdaBoundaryFloorXRay - *lambdaBoundaryFloorEc2Eni - - !If - - IsProdAccount - - Sid: PaychexIntegrationsSecrets - Effect: Allow - Action: - - secretsmanager:GetSecretValue - Resource: - - arn:aws:secretsmanager:us-east-1:011934824531:secret:paychex-integrations/oauth-client-2WfF5w - - arn:aws:secretsmanager:us-east-1:011934824531:secret:paychex-integrations/webhook-api-key-44b0jB - - arn:aws:secretsmanager:us-east-1:011934824531:secret:paychex-integrations/google-service-account-PcUeJD - - arn:aws:secretsmanager:us-east-1:011934824531:secret:paychex-integrations/slack-bot-token-L8DntD - - arn:aws:secretsmanager:us-east-1:011934824531:secret:paychex-integrations/front-inboxes-write-v6niDC - - arn:aws:secretsmanager:us-east-1:011934824531:secret:paychex-integrations/3cx-system-admin-PcUeJD - - !Ref AWS::NoValue + # Unconditional (not !If): adding Fn::If to this named managed policy + # made CloudFormation replace it (409 duplicate ManagedPolicyName) on + # seahaven-deploy-substrate. Prod ARNs are a no-op in other accounts. + - Sid: PaychexIntegrationsSecrets + Effect: Allow + Action: + - secretsmanager:GetSecretValue + Resource: + - arn:aws:secretsmanager:us-east-1:011934824531:secret:paychex-integrations/oauth-client-2WfF5w + - arn:aws:secretsmanager:us-east-1:011934824531:secret:paychex-integrations/webhook-api-key-44b0jB + - arn:aws:secretsmanager:us-east-1:011934824531:secret:paychex-integrations/google-service-account-PcUeJD + - arn:aws:secretsmanager:us-east-1:011934824531:secret:paychex-integrations/slack-bot-token-L8DntD + - arn:aws:secretsmanager:us-east-1:011934824531:secret:paychex-integrations/front-inboxes-write-v6niDC + - arn:aws:secretsmanager:us-east-1:011934824531:secret:paychex-integrations/3cx-system-admin-PcUeJD ProcurementIngestBoundary: Type: AWS::IAM::ManagedPolicy