fix(iam): pin paychex secret arns on lambda boundary (#128)
Some checks are pending
Deploy / deploy-management (push) Waiting to run
Deploy / deploy-external-dev (push) Waiting to run
Deploy / deploy-security (push) Waiting to run
Deploy / deploy-dev (push) Waiting to run
Deploy / deploy-prod (push) Waiting to run

First HCP apply minted the six secret suffixes. Pin GetSecretValue to those ARNs so paychex-placeholder can read oauth-client.
This commit is contained in:
Adam Moussa 2026-08-27 23:30:43 +00:00 • committed by GitHub
parent 2f5e5e6e66
commit f7cc67819b
No known key found for this signature in database
GPG key ID: B5690EEEBB952194

View file

@ -148,7 +148,7 @@ Description: >-
# seahaven-lambda-execution-boundary-meal-order-manager: 2380 / 10 statements
# seahaven-lambda-execution-boundary-seahaven-site: 1159 / 6 statements
# seahaven-lambda-execution-boundary-seahaven-door-unlock-api: measure after deploy (PLAT-76)
# seahaven-lambda-execution-boundary-paychex-integrations: floor-only (PLAT-120)
# seahaven-lambda-execution-boundary-paychex-integrations: GetSecretValue on six minted ARNs (PLAT-122)
# Dev copies are floor-only (691 / 4) via IsProdAccount.
#
# Guardrail PolicyDocuments also cap at 6,144. Each extra allow-list ARN
@ -369,12 +369,10 @@ Resources:
# - no IAM permissions for S3 / SQS / SSM / SES / KMS / VPC in this
# stack's template as of 2026-07-30
#
# paychex-integrations (functions: paychex-*, PLAT-120)
# paychex-integrations (functions: paychex-*, PLAT-122)
# - Authority: Sea-Haven-Industries/paychex-integrations terraform/
# (placeholder Lambda). Floor only in this PR: secrets do not exist
# yet so exact GetSecretValue ARNs cannot be pinned. Do NOT add
# secret:paychex-integrations/* patterns. After first HCP apply,
# widen with the six minted secret ARNs.
# (placeholder Lambda). GetSecretValue on six exact prod secret ARNs
# minted by first HCP apply on 2026-08-27. No name-prefix wildcards.
# - CloudWatch Logs (floor)
# - no DynamoDB / EventBridge / S3 data plane / SES / KMS / VPC in the
# scaffold Terraform
@ -854,8 +852,8 @@ Resources:
Properties:
ManagedPolicyName: seahaven-lambda-execution-boundary-paychex-integrations
Description: >-
Per-workload permissions boundary for paychex-integrations (PLAT-120).
Floor only until first HCP apply mints secret suffixes.
Per-workload permissions boundary for paychex-integrations (PLAT-122).
GetSecretValue pinned to the six minted secret ARNs.
PolicyDocument:
Version: "2012-10-17"
Statement:
@ -865,6 +863,20 @@ Resources:
- *lambdaBoundaryFloorLogsDescribe
- *lambdaBoundaryFloorXRay
- *lambdaBoundaryFloorEc2Eni
- !If
- IsProdAccount
- Sid: PaychexIntegrationsSecrets
Effect: Allow
Action:
- secretsmanager:GetSecretValue
Resource:
- arn:aws:secretsmanager:us-east-1:011934824531:secret:paychex-integrations/oauth-client-2WfF5w
- arn:aws:secretsmanager:us-east-1:011934824531:secret:paychex-integrations/webhook-api-key-44b0jB
- arn:aws:secretsmanager:us-east-1:011934824531:secret:paychex-integrations/google-service-account-PcUeJD
- arn:aws:secretsmanager:us-east-1:011934824531:secret:paychex-integrations/slack-bot-token-L8DntD
- arn:aws:secretsmanager:us-east-1:011934824531:secret:paychex-integrations/front-inboxes-write-v6niDC
- arn:aws:secretsmanager:us-east-1:011934824531:secret:paychex-integrations/3cx-system-admin-PcUeJD
- !Ref AWS::NoValue
ProcurementIngestBoundary:
Type: AWS::IAM::ManagedPolicy