diff --git a/lib/deploy-substrate/deploy-substrate.template.yaml b/lib/deploy-substrate/deploy-substrate.template.yaml index 47325f5..0b787f0 100644 --- a/lib/deploy-substrate/deploy-substrate.template.yaml +++ b/lib/deploy-substrate/deploy-substrate.template.yaml @@ -143,7 +143,7 @@ Description: >- # seahaven-lambda-execution-boundary-afi-backup-monitor: 952 / 5 statements # seahaven-lambda-execution-boundary-front-integrations: 1532 / 6 statements # seahaven-lambda-execution-boundary-procurement-ingest: 3977 / 11 statements -# seahaven-lambda-execution-boundary-meal-order-manager: 2380 / 10 statements +# seahaven-lambda-execution-boundary-meal-order-manager: 2530 / 11 statements (PLAT-135) # seahaven-lambda-execution-boundary-seahaven-site: 1159 / 6 statements # seahaven-lambda-execution-boundary-seahaven-door-unlock-api: measure after deploy (PLAT-76) # seahaven-lambda-execution-boundary-paychex-integrations: GetSecretValue on six minted ARNs (PLAT-122) @@ -1089,6 +1089,18 @@ Resources: Resource: - !Sub "arn:aws:sns:us-east-1:${AWS::AccountId}:site-alerts" - !Ref AWS::NoValue + # aggregate-orders enqueues the weekly meal-deduction payload onto + # paychex-integrations' checkcomponents queue (PLAT-135). Send only; + # the paychex processor owns receive/delete. + - !If + - IsProdAccount + - Sid: MealOrderManagerSqs + Effect: Allow + Action: + - sqs:SendMessage + Resource: + - !Sub "arn:aws:sqs:us-east-1:${AWS::AccountId}:paychex-checkcomponents" + - !Ref AWS::NoValue - !If - IsProdAccount - Sid: MealOrderManager