feat(paychex): allow the payroll schedule queue on the execution boundary (PLAT-238) (#177)
Some checks are pending
Deploy / deploy-management (push) Waiting to run
Deploy / deploy-external-dev (push) Waiting to run
Deploy / deploy-security (push) Waiting to run
Deploy / deploy-dev (push) Waiting to run
Deploy / deploy-prod (push) Waiting to run

* feat(paychex): allow the payroll schedule queue on the execution boundary (PLAT-238)

The schedule role and the function role cannot use paychex-payroll-schedule until the boundary names it.

* docs(paychex): record the measured boundary size after the queue allow (PLAT-238)
This commit is contained in:
Adam Moussa 2026-10-05 16:31:57 +00:00 • committed by GitHub
parent 5589c6d34c
commit f76b767dcb
No known key found for this signature in database
GPG key ID: B5690EEEBB952194

View file

@ -148,7 +148,7 @@ Description: >-
# seahaven-lambda-execution-boundary-meal-order-manager: 2530 / 11 statements (PLAT-135)
# seahaven-lambda-execution-boundary-seahaven-site: 1159 / 6 statements
# seahaven-lambda-execution-boundary-seahaven-door-unlock-api: measure after deploy (PLAT-76)
# seahaven-lambda-execution-boundary-paychex-integrations: 3250 / 10 statements (PLAT-228)
# seahaven-lambda-execution-boundary-paychex-integrations: 3374 / 10 statements (PLAT-238)
# The same four floor statements measure 691 / 4 on the dev policies once
# IsProdAccount drops the prod-only statements. meal-order-manager
# (PLAT-210) also keeps DynamoDB/S3/SSM/invoke plus the seahaven-dev
@ -382,7 +382,10 @@ Resources:
# - lambda:InvokeFunction on function:paychex-payroll-schedule only
# (PLAT-228). No other function ARN.
# - sqs:SendMessage on paychex-checkcomponents so the schedule role can
# enqueue the Monday flush. Identity policies still name the queue.
# enqueue the Monday flush, and on paychex-payroll-schedule so
# Scheduler can deliver the Monday and Thursday jobs. The function
# role may consume paychex-payroll-schedule. Identity policies still
# name the queues.
#
# afi-backup-monitor (functions: afi-*)
# - secretsmanager:GetSecretValue on TWO exact prod secret ARNs
@ -704,6 +707,7 @@ Resources:
- !Sub "arn:aws:sqs:us-east-1:${AWS::AccountId}:paychex-webhook-events"
- !Sub "arn:aws:sqs:us-east-1:${AWS::AccountId}:paychex-login-delay"
- !Sub "arn:aws:sqs:us-east-1:${AWS::AccountId}:paychex-checkcomponents"
- !Sub "arn:aws:sqs:us-east-1:${AWS::AccountId}:paychex-payroll-schedule"
- Sid: PaychexIntegrationsSqsSend
Effect: Allow
Action:
@ -712,6 +716,7 @@ Resources:
- !Sub "arn:aws:sqs:us-east-1:${AWS::AccountId}:paychex-webhook-events"
- !Sub "arn:aws:sqs:us-east-1:${AWS::AccountId}:paychex-login-delay"
- !Sub "arn:aws:sqs:us-east-1:${AWS::AccountId}:paychex-checkcomponents"
- !Sub "arn:aws:sqs:us-east-1:${AWS::AccountId}:paychex-payroll-schedule"
- Sid: PaychexIntegrationsSns
Effect: Allow
Action: