mirror of
https://github.com/Sea-Haven-Industries/seahaven-org-baseline.git
synced 2026-09-30 05:43:17 +00:00
Merge pull request #103 from Sea-Haven-Industries/fix/meal-order-weekly-menu-execute-api
Some checks failed
Some checks failed
fix(iam): meal-order weekly-menu execute-api boundary (PLAT-100)
This commit is contained in:
commit
ef1afab33b
1 changed files with 22 additions and 17 deletions
|
|
@ -121,13 +121,15 @@ Description: >-
|
|||
# correctly left untouched.
|
||||
#
|
||||
# SIZE BUDGET: an attached managed policy document is capped at 6,144 characters
|
||||
# (whitespace excluded). LambdaExecutionBoundary measures 5903 characters across
|
||||
# 16 statements as of 2026-08-07 (PLAT-93 consolidation after the meal-order
|
||||
# PolicySize rollback). Measure before widening — len(json.dumps(doc,
|
||||
# separators=(',',':'))) on the synthesized PolicyDocument with
|
||||
# ${AWS::AccountId} resolved, and UPDATE THESE TWO NUMBERS in the same edit.
|
||||
# (whitespace excluded). LambdaExecutionBoundary measures 5986 characters across
|
||||
# 15 statements as of 2026-08-10 (PLAT-100: MealOrderManagerSsm+LambdaInvoke
|
||||
# consolidated with execute-api:Invoke; SES kept separate because Resource:"*"
|
||||
# must not share a statement with execute-api:Invoke. Was 5903/16 after PLAT-93).
|
||||
# Measure before widening — len(json.dumps(doc, separators=(',',':'))) on the
|
||||
# synthesized PolicyDocument with ${AWS::AccountId} resolved, and UPDATE THESE
|
||||
# TWO NUMBERS in the same edit.
|
||||
#
|
||||
# Headroom is 241 characters. Statement consolidation (shared WorkloadSecrets /
|
||||
# Headroom is 158 characters. Statement consolidation (shared WorkloadSecrets /
|
||||
# WorkloadDynamoDB / extended WorkloadS3 Resource lists; no new action wildcards)
|
||||
# is the only remaining lever short of per-workload boundaries. If the budget
|
||||
# tightens again, the end-state fix is per-workload boundaries
|
||||
|
|
@ -670,26 +672,29 @@ Resources:
|
|||
- !Sub "arn:aws:cloudfront::${AWS::AccountId}:distribution/*"
|
||||
- !Ref AWS::NoValue
|
||||
|
||||
# ── meal-order-manager (PLAT-70) — statements not covered above ─────
|
||||
# ── meal-order-manager (PLAT-70 / PLAT-100) — not covered above ─────
|
||||
# Secrets → WorkloadSecrets; DynamoDB → WorkloadDynamoDB; S3 → WorkloadS3;
|
||||
# SNS → ProcurementIngestSns. Trimmed to identity-policy needs.
|
||||
# SNS → ProcurementIngestSns. SSM + Lambda Invoke + execute-api share
|
||||
# one Sid (scoped Resources only) so PolicySize stays under 6,144 —
|
||||
# a standalone execute-api Sid is ~243 chars against 241 headroom and
|
||||
# would fail UPDATE with LimitExceeded. SES stays in its own Sid:
|
||||
# Resource:"*" must not share a statement with execute-api:Invoke
|
||||
# (that would allow Invoke on every API in the account).
|
||||
# Weekly-menu OIDC identity policy pins the API id; boundary pins
|
||||
# method/path only.
|
||||
- !If
|
||||
- IsProdAccount
|
||||
- Sid: MealOrderManagerSsm
|
||||
- Sid: MealOrderManager
|
||||
Effect: Allow
|
||||
Action:
|
||||
- ssm:GetParameter
|
||||
- lambda:InvokeFunction
|
||||
- execute-api:Invoke
|
||||
Resource:
|
||||
- !Sub "arn:aws:ssm:us-east-1:${AWS::AccountId}:parameter/meal-order-manager/*"
|
||||
- !Ref AWS::NoValue
|
||||
- !If
|
||||
- IsProdAccount
|
||||
- Sid: MealOrderManagerLambdaInvoke
|
||||
Effect: Allow
|
||||
Action:
|
||||
- lambda:InvokeFunction
|
||||
Resource:
|
||||
- !Sub "arn:aws:lambda:us-east-1:${AWS::AccountId}:function:meal-order-manager-*"
|
||||
- !Sub "arn:aws:execute-api:us-east-1:${AWS::AccountId}:*/*/GET/api/publish/settings"
|
||||
- !Sub "arn:aws:execute-api:us-east-1:${AWS::AccountId}:*/*/POST/api/publish/menu"
|
||||
- !Ref AWS::NoValue
|
||||
- !If
|
||||
- IsProdAccount
|
||||
|
|
|
|||
Loading…
Add table
Reference in a new issue