From f7cc67819bc15113ae23ef37249b30e714ca3d38 Mon Sep 17 00:00:00 2001 From: Adam Moussa <166072409+amoussa1229@users.noreply.github.com> Date: Thu, 27 Aug 2026 23:30:43 +0000 Subject: [PATCH] fix(iam): pin paychex secret arns on lambda boundary (#128) First HCP apply minted the six secret suffixes. Pin GetSecretValue to those ARNs so paychex-placeholder can read oauth-client. --- .../deploy-substrate.template.yaml | 28 +++++++++++++------ 1 file changed, 20 insertions(+), 8 deletions(-) diff --git a/lib/deploy-substrate/deploy-substrate.template.yaml b/lib/deploy-substrate/deploy-substrate.template.yaml index 0f4542a..298828f 100644 --- a/lib/deploy-substrate/deploy-substrate.template.yaml +++ b/lib/deploy-substrate/deploy-substrate.template.yaml @@ -148,7 +148,7 @@ Description: >- # seahaven-lambda-execution-boundary-meal-order-manager: 2380 / 10 statements # seahaven-lambda-execution-boundary-seahaven-site: 1159 / 6 statements # seahaven-lambda-execution-boundary-seahaven-door-unlock-api: measure after deploy (PLAT-76) -# seahaven-lambda-execution-boundary-paychex-integrations: floor-only (PLAT-120) +# seahaven-lambda-execution-boundary-paychex-integrations: GetSecretValue on six minted ARNs (PLAT-122) # Dev copies are floor-only (691 / 4) via IsProdAccount. # # Guardrail PolicyDocuments also cap at 6,144. Each extra allow-list ARN @@ -369,12 +369,10 @@ Resources: # - no IAM permissions for S3 / SQS / SSM / SES / KMS / VPC in this # stack's template as of 2026-07-30 # - # paychex-integrations (functions: paychex-*, PLAT-120) + # paychex-integrations (functions: paychex-*, PLAT-122) # - Authority: Sea-Haven-Industries/paychex-integrations terraform/ - # (placeholder Lambda). Floor only in this PR: secrets do not exist - # yet so exact GetSecretValue ARNs cannot be pinned. Do NOT add - # secret:paychex-integrations/* patterns. After first HCP apply, - # widen with the six minted secret ARNs. + # (placeholder Lambda). GetSecretValue on six exact prod secret ARNs + # minted by first HCP apply on 2026-08-27. No name-prefix wildcards. # - CloudWatch Logs (floor) # - no DynamoDB / EventBridge / S3 data plane / SES / KMS / VPC in the # scaffold Terraform @@ -854,8 +852,8 @@ Resources: Properties: ManagedPolicyName: seahaven-lambda-execution-boundary-paychex-integrations Description: >- - Per-workload permissions boundary for paychex-integrations (PLAT-120). - Floor only until first HCP apply mints secret suffixes. + Per-workload permissions boundary for paychex-integrations (PLAT-122). + GetSecretValue pinned to the six minted secret ARNs. PolicyDocument: Version: "2012-10-17" Statement: @@ -865,6 +863,20 @@ Resources: - *lambdaBoundaryFloorLogsDescribe - *lambdaBoundaryFloorXRay - *lambdaBoundaryFloorEc2Eni + - !If + - IsProdAccount + - Sid: PaychexIntegrationsSecrets + Effect: Allow + Action: + - secretsmanager:GetSecretValue + Resource: + - arn:aws:secretsmanager:us-east-1:011934824531:secret:paychex-integrations/oauth-client-2WfF5w + - arn:aws:secretsmanager:us-east-1:011934824531:secret:paychex-integrations/webhook-api-key-44b0jB + - arn:aws:secretsmanager:us-east-1:011934824531:secret:paychex-integrations/google-service-account-PcUeJD + - arn:aws:secretsmanager:us-east-1:011934824531:secret:paychex-integrations/slack-bot-token-L8DntD + - arn:aws:secretsmanager:us-east-1:011934824531:secret:paychex-integrations/front-inboxes-write-v6niDC + - arn:aws:secretsmanager:us-east-1:011934824531:secret:paychex-integrations/3cx-system-admin-PcUeJD + - !Ref AWS::NoValue ProcurementIngestBoundary: Type: AWS::IAM::ManagedPolicy