diff --git a/lib/deploy-substrate/deploy-substrate.template.yaml b/lib/deploy-substrate/deploy-substrate.template.yaml index 97181a2..6c96362 100644 --- a/lib/deploy-substrate/deploy-substrate.template.yaml +++ b/lib/deploy-substrate/deploy-substrate.template.yaml @@ -148,7 +148,7 @@ Description: >- # seahaven-lambda-execution-boundary-meal-order-manager: 2530 / 11 statements (PLAT-135) # seahaven-lambda-execution-boundary-seahaven-site: 1159 / 6 statements # seahaven-lambda-execution-boundary-seahaven-door-unlock-api: measure after deploy (PLAT-76) -# seahaven-lambda-execution-boundary-paychex-integrations: 3250 / 10 statements (PLAT-228) +# seahaven-lambda-execution-boundary-paychex-integrations: 3374 / 10 statements (PLAT-238) # The same four floor statements measure 691 / 4 on the dev policies once # IsProdAccount drops the prod-only statements. meal-order-manager # (PLAT-210) also keeps DynamoDB/S3/SSM/invoke plus the seahaven-dev @@ -382,7 +382,10 @@ Resources: # - lambda:InvokeFunction on function:paychex-payroll-schedule only # (PLAT-228). No other function ARN. # - sqs:SendMessage on paychex-checkcomponents so the schedule role can -# enqueue the Monday flush. Identity policies still name the queue. +# enqueue the Monday flush, and on paychex-payroll-schedule so +# Scheduler can deliver the Monday and Thursday jobs. The function +# role may consume paychex-payroll-schedule. Identity policies still +# name the queues. # # afi-backup-monitor (functions: afi-*) # - secretsmanager:GetSecretValue on TWO exact prod secret ARNs @@ -704,6 +707,7 @@ Resources: - !Sub "arn:aws:sqs:us-east-1:${AWS::AccountId}:paychex-webhook-events" - !Sub "arn:aws:sqs:us-east-1:${AWS::AccountId}:paychex-login-delay" - !Sub "arn:aws:sqs:us-east-1:${AWS::AccountId}:paychex-checkcomponents" + - !Sub "arn:aws:sqs:us-east-1:${AWS::AccountId}:paychex-payroll-schedule" - Sid: PaychexIntegrationsSqsSend Effect: Allow Action: @@ -712,6 +716,7 @@ Resources: - !Sub "arn:aws:sqs:us-east-1:${AWS::AccountId}:paychex-webhook-events" - !Sub "arn:aws:sqs:us-east-1:${AWS::AccountId}:paychex-login-delay" - !Sub "arn:aws:sqs:us-east-1:${AWS::AccountId}:paychex-checkcomponents" + - !Sub "arn:aws:sqs:us-east-1:${AWS::AccountId}:paychex-payroll-schedule" - Sid: PaychexIntegrationsSns Effect: Allow Action: