mirror of
https://github.com/Sea-Haven-Industries/seahaven-org-baseline.git
synced 2026-09-30 08:03:19 +00:00
fix(iam): allow paychex worker ledger dynamodb (#130)
Some checks failed
Some checks failed
HCP plan/apply and the paychex Lambda boundary need the paychex-worker-ledger table ARN so PLAT-123 can create and use the identity ledger.
This commit is contained in:
parent
e21d08bf23
commit
ee233379dd
2 changed files with 36 additions and 6 deletions
|
|
@ -877,6 +877,17 @@ Resources:
|
|||
- arn:aws:secretsmanager:us-east-1:011934824531:secret:paychex-integrations/slack-bot-token-L8DntD
|
||||
- arn:aws:secretsmanager:us-east-1:011934824531:secret:paychex-integrations/front-inboxes-write-v6niDC
|
||||
- arn:aws:secretsmanager:us-east-1:011934824531:secret:paychex-integrations/3cx-system-admin-PcUeJD
|
||||
- Sid: PaychexIntegrationsDynamoDB
|
||||
Effect: Allow
|
||||
Action:
|
||||
- dynamodb:GetItem
|
||||
- dynamodb:PutItem
|
||||
- dynamodb:UpdateItem
|
||||
- dynamodb:DeleteItem
|
||||
- dynamodb:ConditionCheckItem
|
||||
- dynamodb:DescribeTable
|
||||
Resource:
|
||||
- !Sub "arn:aws:dynamodb:us-east-1:${AWS::AccountId}:table/paychex-worker-ledger"
|
||||
|
||||
ProcurementIngestBoundary:
|
||||
Type: AWS::IAM::ManagedPolicy
|
||||
|
|
|
|||
|
|
@ -743,12 +743,10 @@ Resources:
|
|||
- !Sub "arn:aws:sns:us-east-1:${AWS::AccountId}:site-alerts"
|
||||
|
||||
# ---------------------------------------------------------------------------
|
||||
# paychex-integrations (PLAT-120) — plan + apply roles for workspace
|
||||
# paychex-integrations-prod. Copy shape from front-integrations; scaffold
|
||||
# first apply is Lambda + artifact bucket + alarms + secret shells only
|
||||
# (no EventBridge, no DynamoDB). Secret Get/Put value stays off the apply
|
||||
# role. Lambda execution boundary is floor-only until first apply mints
|
||||
# secret suffixes.
|
||||
# paychex-integrations (PLAT-120/123) — plan + apply roles for workspace
|
||||
# paychex-integrations-prod. Copy shape from front-integrations. Secret
|
||||
# Get/Put value stays off the apply role. Lambda execution boundary pins
|
||||
# minted secret ARNs and table paychex-worker-ledger.
|
||||
# ---------------------------------------------------------------------------
|
||||
HcptfPaychexIntegrationsPlanRole:
|
||||
Type: AWS::IAM::Role
|
||||
|
|
@ -830,6 +828,15 @@ Resources:
|
|||
- secretsmanager:ListSecretVersionIds
|
||||
Resource:
|
||||
- !Sub "arn:aws:secretsmanager:us-east-1:${AWS::AccountId}:secret:paychex-integrations/*"
|
||||
- Sid: RefreshDynamoDB
|
||||
Effect: Allow
|
||||
Action:
|
||||
- dynamodb:DescribeTable
|
||||
- dynamodb:DescribeTimeToLive
|
||||
- dynamodb:DescribeContinuousBackups
|
||||
- dynamodb:ListTagsOfResource
|
||||
Resource:
|
||||
- !Sub "arn:aws:dynamodb:us-east-1:${AWS::AccountId}:table/paychex-worker-ledger"
|
||||
|
||||
HcptfPaychexIntegrationsApplyRole:
|
||||
Type: AWS::IAM::Role
|
||||
|
|
@ -930,6 +937,18 @@ Resources:
|
|||
- paychex-integrations/slack-bot-token
|
||||
- paychex-integrations/front-inboxes-write
|
||||
- paychex-integrations/3cx-system-admin
|
||||
- Sid: DynamoDBTable
|
||||
Effect: Allow
|
||||
Action:
|
||||
- dynamodb:*
|
||||
Resource:
|
||||
- !Sub "arn:aws:dynamodb:us-east-1:${AWS::AccountId}:table/paychex-worker-ledger"
|
||||
- !Sub "arn:aws:dynamodb:us-east-1:${AWS::AccountId}:table/paychex-worker-ledger/index/*"
|
||||
- Sid: DynamoDBList
|
||||
Effect: Allow
|
||||
Action:
|
||||
- dynamodb:ListTables
|
||||
Resource: "*"
|
||||
|
||||
# ---------------------------------------------------------------------------
|
||||
# Per-workspace hcptf-* roles for sh-openswe-traces-prod (PLAT-73).
|
||||
|
|
|
|||
Loading…
Add table
Reference in a new issue