Merge pull request #103 from Sea-Haven-Industries/fix/meal-order-weekly-menu-execute-api
Some checks failed
Deploy / deploy-management (push) Has been cancelled
Deploy / deploy-external-dev (push) Has been cancelled
Deploy / deploy-security (push) Has been cancelled
Deploy / deploy-dev (push) Has been cancelled
Deploy / deploy-prod (push) Has been cancelled

fix(iam): meal-order weekly-menu execute-api boundary (PLAT-100)
This commit is contained in:
Adam Moussa 2026-08-10 16:05:18 -04:00 • committed by GitHub
commit ef1afab33b
No known key found for this signature in database
GPG key ID: B5690EEEBB952194

View file

@ -121,13 +121,15 @@ Description: >-
# correctly left untouched.
#
# SIZE BUDGET: an attached managed policy document is capped at 6,144 characters
# (whitespace excluded). LambdaExecutionBoundary measures 5903 characters across
# 16 statements as of 2026-08-07 (PLAT-93 consolidation after the meal-order
# PolicySize rollback). Measure before widening — len(json.dumps(doc,
# separators=(',',':'))) on the synthesized PolicyDocument with
# ${AWS::AccountId} resolved, and UPDATE THESE TWO NUMBERS in the same edit.
# (whitespace excluded). LambdaExecutionBoundary measures 5986 characters across
# 15 statements as of 2026-08-10 (PLAT-100: MealOrderManagerSsm+LambdaInvoke
# consolidated with execute-api:Invoke; SES kept separate because Resource:"*"
# must not share a statement with execute-api:Invoke. Was 5903/16 after PLAT-93).
# Measure before widening — len(json.dumps(doc, separators=(',',':'))) on the
# synthesized PolicyDocument with ${AWS::AccountId} resolved, and UPDATE THESE
# TWO NUMBERS in the same edit.
#
# Headroom is 241 characters. Statement consolidation (shared WorkloadSecrets /
# Headroom is 158 characters. Statement consolidation (shared WorkloadSecrets /
# WorkloadDynamoDB / extended WorkloadS3 Resource lists; no new action wildcards)
# is the only remaining lever short of per-workload boundaries. If the budget
# tightens again, the end-state fix is per-workload boundaries
@ -670,26 +672,29 @@ Resources:
- !Sub "arn:aws:cloudfront::${AWS::AccountId}:distribution/*"
- !Ref AWS::NoValue
# ── meal-order-manager (PLAT-70) — statements not covered above ─────
# ── meal-order-manager (PLAT-70 / PLAT-100) — not covered above ─────
# Secrets → WorkloadSecrets; DynamoDB → WorkloadDynamoDB; S3 → WorkloadS3;
# SNS → ProcurementIngestSns. Trimmed to identity-policy needs.
# SNS → ProcurementIngestSns. SSM + Lambda Invoke + execute-api share
# one Sid (scoped Resources only) so PolicySize stays under 6,144 —
# a standalone execute-api Sid is ~243 chars against 241 headroom and
# would fail UPDATE with LimitExceeded. SES stays in its own Sid:
# Resource:"*" must not share a statement with execute-api:Invoke
# (that would allow Invoke on every API in the account).
# Weekly-menu OIDC identity policy pins the API id; boundary pins
# method/path only.
- !If
- IsProdAccount
- Sid: MealOrderManagerSsm
- Sid: MealOrderManager
Effect: Allow
Action:
- ssm:GetParameter
- lambda:InvokeFunction
- execute-api:Invoke
Resource:
- !Sub "arn:aws:ssm:us-east-1:${AWS::AccountId}:parameter/meal-order-manager/*"
- !Ref AWS::NoValue
- !If
- IsProdAccount
- Sid: MealOrderManagerLambdaInvoke
Effect: Allow
Action:
- lambda:InvokeFunction
Resource:
- !Sub "arn:aws:lambda:us-east-1:${AWS::AccountId}:function:meal-order-manager-*"
- !Sub "arn:aws:execute-api:us-east-1:${AWS::AccountId}:*/*/GET/api/publish/settings"
- !Sub "arn:aws:execute-api:us-east-1:${AWS::AccountId}:*/*/POST/api/publish/menu"
- !Ref AWS::NoValue
- !If
- IsProdAccount