diff --git a/lib/deploy-substrate/deploy-substrate.template.yaml b/lib/deploy-substrate/deploy-substrate.template.yaml index a65aa92..0b31b59 100644 --- a/lib/deploy-substrate/deploy-substrate.template.yaml +++ b/lib/deploy-substrate/deploy-substrate.template.yaml @@ -877,6 +877,17 @@ Resources: - arn:aws:secretsmanager:us-east-1:011934824531:secret:paychex-integrations/slack-bot-token-L8DntD - arn:aws:secretsmanager:us-east-1:011934824531:secret:paychex-integrations/front-inboxes-write-v6niDC - arn:aws:secretsmanager:us-east-1:011934824531:secret:paychex-integrations/3cx-system-admin-PcUeJD + - Sid: PaychexIntegrationsDynamoDB + Effect: Allow + Action: + - dynamodb:GetItem + - dynamodb:PutItem + - dynamodb:UpdateItem + - dynamodb:DeleteItem + - dynamodb:ConditionCheckItem + - dynamodb:DescribeTable + Resource: + - !Sub "arn:aws:dynamodb:us-east-1:${AWS::AccountId}:table/paychex-worker-ledger" ProcurementIngestBoundary: Type: AWS::IAM::ManagedPolicy diff --git a/lib/terraform-substrate/terraform-substrate.template.yaml b/lib/terraform-substrate/terraform-substrate.template.yaml index 449cd94..a478aa7 100644 --- a/lib/terraform-substrate/terraform-substrate.template.yaml +++ b/lib/terraform-substrate/terraform-substrate.template.yaml @@ -743,12 +743,10 @@ Resources: - !Sub "arn:aws:sns:us-east-1:${AWS::AccountId}:site-alerts" # --------------------------------------------------------------------------- - # paychex-integrations (PLAT-120) — plan + apply roles for workspace - # paychex-integrations-prod. Copy shape from front-integrations; scaffold - # first apply is Lambda + artifact bucket + alarms + secret shells only - # (no EventBridge, no DynamoDB). Secret Get/Put value stays off the apply - # role. Lambda execution boundary is floor-only until first apply mints - # secret suffixes. + # paychex-integrations (PLAT-120/123) — plan + apply roles for workspace + # paychex-integrations-prod. Copy shape from front-integrations. Secret + # Get/Put value stays off the apply role. Lambda execution boundary pins + # minted secret ARNs and table paychex-worker-ledger. # --------------------------------------------------------------------------- HcptfPaychexIntegrationsPlanRole: Type: AWS::IAM::Role @@ -830,6 +828,15 @@ Resources: - secretsmanager:ListSecretVersionIds Resource: - !Sub "arn:aws:secretsmanager:us-east-1:${AWS::AccountId}:secret:paychex-integrations/*" + - Sid: RefreshDynamoDB + Effect: Allow + Action: + - dynamodb:DescribeTable + - dynamodb:DescribeTimeToLive + - dynamodb:DescribeContinuousBackups + - dynamodb:ListTagsOfResource + Resource: + - !Sub "arn:aws:dynamodb:us-east-1:${AWS::AccountId}:table/paychex-worker-ledger" HcptfPaychexIntegrationsApplyRole: Type: AWS::IAM::Role @@ -930,6 +937,18 @@ Resources: - paychex-integrations/slack-bot-token - paychex-integrations/front-inboxes-write - paychex-integrations/3cx-system-admin + - Sid: DynamoDBTable + Effect: Allow + Action: + - dynamodb:* + Resource: + - !Sub "arn:aws:dynamodb:us-east-1:${AWS::AccountId}:table/paychex-worker-ledger" + - !Sub "arn:aws:dynamodb:us-east-1:${AWS::AccountId}:table/paychex-worker-ledger/index/*" + - Sid: DynamoDBList + Effect: Allow + Action: + - dynamodb:ListTables + Resource: "*" # --------------------------------------------------------------------------- # Per-workspace hcptf-* roles for sh-openswe-traces-prod (PLAT-73).