fix(iam): allow paychex worker ledger dynamodb (#130)
Some checks failed
Deploy / deploy-management (push) Has been cancelled
Deploy / deploy-external-dev (push) Has been cancelled
Deploy / deploy-security (push) Has been cancelled
Deploy / deploy-dev (push) Has been cancelled
Deploy / deploy-prod (push) Has been cancelled

HCP plan/apply and the paychex Lambda boundary need the paychex-worker-ledger table ARN so PLAT-123 can create and use the identity ledger.
This commit is contained in:
Adam Moussa 2026-08-28 16:11:23 +00:00 • committed by GitHub
parent e21d08bf23
commit ee233379dd
No known key found for this signature in database
GPG key ID: B5690EEEBB952194
2 changed files with 36 additions and 6 deletions

View file

@ -877,6 +877,17 @@ Resources:
- arn:aws:secretsmanager:us-east-1:011934824531:secret:paychex-integrations/slack-bot-token-L8DntD
- arn:aws:secretsmanager:us-east-1:011934824531:secret:paychex-integrations/front-inboxes-write-v6niDC
- arn:aws:secretsmanager:us-east-1:011934824531:secret:paychex-integrations/3cx-system-admin-PcUeJD
- Sid: PaychexIntegrationsDynamoDB
Effect: Allow
Action:
- dynamodb:GetItem
- dynamodb:PutItem
- dynamodb:UpdateItem
- dynamodb:DeleteItem
- dynamodb:ConditionCheckItem
- dynamodb:DescribeTable
Resource:
- !Sub "arn:aws:dynamodb:us-east-1:${AWS::AccountId}:table/paychex-worker-ledger"
ProcurementIngestBoundary:
Type: AWS::IAM::ManagedPolicy

View file

@ -743,12 +743,10 @@ Resources:
- !Sub "arn:aws:sns:us-east-1:${AWS::AccountId}:site-alerts"
# ---------------------------------------------------------------------------
# paychex-integrations (PLAT-120) — plan + apply roles for workspace
# paychex-integrations-prod. Copy shape from front-integrations; scaffold
# first apply is Lambda + artifact bucket + alarms + secret shells only
# (no EventBridge, no DynamoDB). Secret Get/Put value stays off the apply
# role. Lambda execution boundary is floor-only until first apply mints
# secret suffixes.
# paychex-integrations (PLAT-120/123) — plan + apply roles for workspace
# paychex-integrations-prod. Copy shape from front-integrations. Secret
# Get/Put value stays off the apply role. Lambda execution boundary pins
# minted secret ARNs and table paychex-worker-ledger.
# ---------------------------------------------------------------------------
HcptfPaychexIntegrationsPlanRole:
Type: AWS::IAM::Role
@ -830,6 +828,15 @@ Resources:
- secretsmanager:ListSecretVersionIds
Resource:
- !Sub "arn:aws:secretsmanager:us-east-1:${AWS::AccountId}:secret:paychex-integrations/*"
- Sid: RefreshDynamoDB
Effect: Allow
Action:
- dynamodb:DescribeTable
- dynamodb:DescribeTimeToLive
- dynamodb:DescribeContinuousBackups
- dynamodb:ListTagsOfResource
Resource:
- !Sub "arn:aws:dynamodb:us-east-1:${AWS::AccountId}:table/paychex-worker-ledger"
HcptfPaychexIntegrationsApplyRole:
Type: AWS::IAM::Role
@ -930,6 +937,18 @@ Resources:
- paychex-integrations/slack-bot-token
- paychex-integrations/front-inboxes-write
- paychex-integrations/3cx-system-admin
- Sid: DynamoDBTable
Effect: Allow
Action:
- dynamodb:*
Resource:
- !Sub "arn:aws:dynamodb:us-east-1:${AWS::AccountId}:table/paychex-worker-ledger"
- !Sub "arn:aws:dynamodb:us-east-1:${AWS::AccountId}:table/paychex-worker-ledger/index/*"
- Sid: DynamoDBList
Effect: Allow
Action:
- dynamodb:ListTables
Resource: "*"
# ---------------------------------------------------------------------------
# Per-workspace hcptf-* roles for sh-openswe-traces-prod (PLAT-73).