mirror of
https://github.com/Sea-Haven-Industries/seahaven-org-baseline.git
synced 2026-09-30 06:53:17 +00:00
fix(iam): pin paychex secret arns on lambda boundary (#128)
First HCP apply minted the six secret suffixes. Pin GetSecretValue to those ARNs so paychex-placeholder can read oauth-client.
This commit is contained in:
parent
2f5e5e6e66
commit
f7cc67819b
1 changed files with 20 additions and 8 deletions
|
|
@ -148,7 +148,7 @@ Description: >-
|
|||
# seahaven-lambda-execution-boundary-meal-order-manager: 2380 / 10 statements
|
||||
# seahaven-lambda-execution-boundary-seahaven-site: 1159 / 6 statements
|
||||
# seahaven-lambda-execution-boundary-seahaven-door-unlock-api: measure after deploy (PLAT-76)
|
||||
# seahaven-lambda-execution-boundary-paychex-integrations: floor-only (PLAT-120)
|
||||
# seahaven-lambda-execution-boundary-paychex-integrations: GetSecretValue on six minted ARNs (PLAT-122)
|
||||
# Dev copies are floor-only (691 / 4) via IsProdAccount.
|
||||
#
|
||||
# Guardrail PolicyDocuments also cap at 6,144. Each extra allow-list ARN
|
||||
|
|
@ -369,12 +369,10 @@ Resources:
|
|||
# - no IAM permissions for S3 / SQS / SSM / SES / KMS / VPC in this
|
||||
# stack's template as of 2026-07-30
|
||||
#
|
||||
# paychex-integrations (functions: paychex-*, PLAT-120)
|
||||
# paychex-integrations (functions: paychex-*, PLAT-122)
|
||||
# - Authority: Sea-Haven-Industries/paychex-integrations terraform/
|
||||
# (placeholder Lambda). Floor only in this PR: secrets do not exist
|
||||
# yet so exact GetSecretValue ARNs cannot be pinned. Do NOT add
|
||||
# secret:paychex-integrations/* patterns. After first HCP apply,
|
||||
# widen with the six minted secret ARNs.
|
||||
# (placeholder Lambda). GetSecretValue on six exact prod secret ARNs
|
||||
# minted by first HCP apply on 2026-08-27. No name-prefix wildcards.
|
||||
# - CloudWatch Logs (floor)
|
||||
# - no DynamoDB / EventBridge / S3 data plane / SES / KMS / VPC in the
|
||||
# scaffold Terraform
|
||||
|
|
@ -854,8 +852,8 @@ Resources:
|
|||
Properties:
|
||||
ManagedPolicyName: seahaven-lambda-execution-boundary-paychex-integrations
|
||||
Description: >-
|
||||
Per-workload permissions boundary for paychex-integrations (PLAT-120).
|
||||
Floor only until first HCP apply mints secret suffixes.
|
||||
Per-workload permissions boundary for paychex-integrations (PLAT-122).
|
||||
GetSecretValue pinned to the six minted secret ARNs.
|
||||
PolicyDocument:
|
||||
Version: "2012-10-17"
|
||||
Statement:
|
||||
|
|
@ -865,6 +863,20 @@ Resources:
|
|||
- *lambdaBoundaryFloorLogsDescribe
|
||||
- *lambdaBoundaryFloorXRay
|
||||
- *lambdaBoundaryFloorEc2Eni
|
||||
- !If
|
||||
- IsProdAccount
|
||||
- Sid: PaychexIntegrationsSecrets
|
||||
Effect: Allow
|
||||
Action:
|
||||
- secretsmanager:GetSecretValue
|
||||
Resource:
|
||||
- arn:aws:secretsmanager:us-east-1:011934824531:secret:paychex-integrations/oauth-client-2WfF5w
|
||||
- arn:aws:secretsmanager:us-east-1:011934824531:secret:paychex-integrations/webhook-api-key-44b0jB
|
||||
- arn:aws:secretsmanager:us-east-1:011934824531:secret:paychex-integrations/google-service-account-PcUeJD
|
||||
- arn:aws:secretsmanager:us-east-1:011934824531:secret:paychex-integrations/slack-bot-token-L8DntD
|
||||
- arn:aws:secretsmanager:us-east-1:011934824531:secret:paychex-integrations/front-inboxes-write-v6niDC
|
||||
- arn:aws:secretsmanager:us-east-1:011934824531:secret:paychex-integrations/3cx-system-admin-PcUeJD
|
||||
- !Ref AWS::NoValue
|
||||
|
||||
ProcurementIngestBoundary:
|
||||
Type: AWS::IAM::ManagedPolicy
|
||||
|
|
|
|||
Loading…
Add table
Reference in a new issue