Commit graph

96 commits

Author SHA1 Message Date
af47bf6455
fix(iam): allow paychex period table and optional secrets (PLAT-195)
The processor role already allows these ARNs. The live boundary denied
them, so GetSecretValue and period PutItem returned HTTP 400. Sync the
template to the live ceiling and add the missing period table plus
slack-admin and afterhours secret suffixes.
2026-09-14 14:10:47 -04:00
Adam Moussa
a492a45e07
chore(iam): remove frontend tf-poc substrate after teardown (PLAT-194) (#146)
Some checks failed
Deploy / deploy-management (push) Has been cancelled
Deploy / deploy-external-dev (push) Has been cancelled
Deploy / deploy-security (push) Has been cancelled
Deploy / deploy-dev (push) Has been cancelled
Deploy / deploy-prod (push) Has been cancelled
2026-09-11 22:17:00 +00:00
Adam Moussa
5d613c73bc
feat(iam): allow frontend tf-poc HCP apply destroy (PLAT-193) (#145) 2026-09-11 21:46:59 +00:00
Adam Moussa
3c54df6341
fix(iam): allow GitHub frontend deploy roles to GetDistribution (PLAT-192) (#144)
Some checks are pending
Deploy / deploy-management (push) Waiting to run
Deploy / deploy-external-dev (push) Waiting to run
Deploy / deploy-security (push) Waiting to run
Deploy / deploy-dev (push) Waiting to run
Deploy / deploy-prod (push) Waiting to run
Verify and live-state summary call get-distribution; the identity policy already granted it, but the permissions boundary denied the action.
2026-09-11 19:37:24 +00:00
Adam Moussa
60b978aa2a
feat(iam): allow frontend HCP apply to own release pointer and invalidation (PLAT-188) (#143)
Some checks are pending
Deploy / deploy-management (push) Waiting to run
Deploy / deploy-external-dev (push) Waiting to run
Deploy / deploy-security (push) Waiting to run
Deploy / deploy-dev (push) Waiting to run
Deploy / deploy-prod (push) Waiting to run
* feat(iam): allow frontend HCP apply to own release pointer and invalidation (PLAT-188)

Plan and apply roles can read .release/current; apply can PutObject that key and CreateInvalidation on the exact distribution.

* fix(iam): allow frontend HCP roles to tag the release pointer (PLAT-188)

Terraform aws_s3_object lists object tags on every refresh, so plan and apply need GetObjectTagging and apply needs PutObjectTagging on the exact .release/current key.
2026-09-11 17:37:42 +00:00
Adam Moussa
0c6f307b61
feat(iam): allow frontend HCP apply to update exact CloudFront resources (PLAT-187) (#142)
Some checks are pending
Deploy / deploy-management (push) Waiting to run
Deploy / deploy-external-dev (push) Waiting to run
Deploy / deploy-security (push) Waiting to run
Deploy / deploy-dev (push) Waiting to run
Deploy / deploy-prod (push) Waiting to run
* feat(iam): allow frontend HCP apply to update exact CloudFront resources (PLAT-187)

Phase 2 ownership tags cannot apply while UpdateDistribution and UpdateFunction are denied on *. Allow those two actions only on the pinned distribution and function ARNs.

* fix(iam): allow PublishFunction on exact frontend CloudFront functions (PLAT-187)

The AWS provider publishes after UpdateFunction, including tag-only applies, so denying PublishFunction on * still blocked Phase 2 function updates.
2026-09-11 15:08:21 +00:00
Adam Moussa
fa940e69c6
feat(iam): allow meal-order-manager to send to paychex-checkcomponents (PLAT-135) (#140)
Some checks are pending
Deploy / deploy-management (push) Waiting to run
Deploy / deploy-external-dev (push) Waiting to run
Deploy / deploy-security (push) Waiting to run
Deploy / deploy-dev (push) Waiting to run
Deploy / deploy-prod (push) Waiting to run
2026-09-09 23:58:42 +00:00
Adam Moussa
6bc4f6e095
chore(iam): remove backend tf-poc boundaries (#139)
Some checks failed
Deploy / deploy-management (push) Has been cancelled
Deploy / deploy-external-dev (push) Has been cancelled
Deploy / deploy-security (push) Has been cancelled
Deploy / deploy-dev (push) Has been cancelled
Deploy / deploy-prod (push) Has been cancelled
2026-09-03 15:04:58 +00:00
Adam Moussa
4f0d84cddb
fix(iam): use unique HCP bootstrap workspace names (PLAT-143) (#138)
Some checks are pending
Deploy / deploy-management (push) Waiting to run
Deploy / deploy-external-dev (push) Waiting to run
Deploy / deploy-security (push) Waiting to run
Deploy / deploy-dev (push) Waiting to run
Deploy / deploy-prod (push) Waiting to run
HCP workspace names are org-unique, so prod and dev cannot both be iam-bootstrap. Pin trust to iam-bootstrap-prod and iam-bootstrap-dev.
2026-09-02 15:51:39 +00:00
Adam Moussa
b02f52b805
feat(iam): lock app-owned HCP IAM and add bootstrap SCP (PLAT-143) (#137)
* feat(iam): lock app-owned HCP IAM and add bootstrap SCP (PLAT-143)

* fix(iam): pin HCP boundary ARNs and bootstrap trust window (PLAT-143)

Null on iam:PermissionsBoundary accepted any ceiling, including AdministratorAccess. Import apply cannot self-mutate hcptf-* while bootstrap trust is iam-bootstrap only; add a time-boxed exact StringEquals workspace grant instead of StringLike.
2026-09-02 15:22:48 +00:00
Adam Moussa
35dc61b806
feat(iam): allow tf-poc HCP apply destroy (#136)
Some checks are pending
Deploy / deploy-management (push) Waiting to run
Deploy / deploy-external-dev (push) Waiting to run
Deploy / deploy-security (push) Waiting to run
Deploy / deploy-dev (push) Waiting to run
Deploy / deploy-prod (push) Waiting to run
2026-09-01 16:14:06 +00:00
Adam Moussa
6d5811f08e
fix(iam): codify live terraform-substrate IAM (PLAT-142) (#135)
Some checks are pending
Deploy / deploy-management (push) Waiting to run
Deploy / deploy-external-dev (push) Waiting to run
Deploy / deploy-security (push) Waiting to run
Deploy / deploy-dev (push) Waiting to run
Deploy / deploy-prod (push) Waiting to run
* fix(iam): allow frontend import plan to read deploy boundaries

* fix(iam): grant backend apply role EB UpdateEnvironment follow-on perms
2026-09-01 00:16:34 +00:00
Adam Moussa
559eed1e98
fix(iam): allow backend Terraform refresh (PLAT-141) (#134)
Some checks are pending
Deploy / deploy-management (push) Waiting to run
Deploy / deploy-external-dev (push) Waiting to run
Deploy / deploy-security (push) Waiting to run
Deploy / deploy-dev (push) Waiting to run
Deploy / deploy-prod (push) Waiting to run
* fix(iam): allow backend import plan reads

* fix(iam): authorize backend EB refresh

* fix(iam): authorize backend EB ownership check
2026-08-31 17:04:00 +00:00
Adam Moussa
6a0713f49d
feat(iam): add frontend Terraform substrate (#133)
Some checks are pending
Deploy / deploy-management (push) Waiting to run
Deploy / deploy-external-dev (push) Waiting to run
Deploy / deploy-security (push) Waiting to run
Deploy / deploy-dev (push) Waiting to run
Deploy / deploy-prod (push) Waiting to run
* feat(iam): add frontend Terraform substrate

* fix(iam): align frontend Terraform substrate

* feat(iam): enable frontend live Terraform roles
2026-08-31 02:25:47 +00:00
Adam Moussa
08191ded4c
chore(iam): finalize backend role ownership (#132)
Some checks are pending
Deploy / deploy-management (push) Waiting to run
Deploy / deploy-external-dev (push) Waiting to run
Deploy / deploy-security (push) Waiting to run
Deploy / deploy-dev (push) Waiting to run
Deploy / deploy-prod (push) Waiting to run
* chore(iam): finalize backend role ownership

* fix(iam): complete backend import permissions
2026-08-30 20:12:54 +00:00
Adam Moussa
dba0871587
feat(iam): add external-dev backend Terraform substrate (#131)
Some checks are pending
Deploy / deploy-management (push) Waiting to run
Deploy / deploy-external-dev (push) Waiting to run
Deploy / deploy-security (push) Waiting to run
Deploy / deploy-dev (push) Waiting to run
Deploy / deploy-prod (push) Waiting to run
* feat(iam): add external-dev backend terraform substrate

* fix(iam): require boundaries for SHOC policy writes
2026-08-29 21:04:40 +00:00
Adam Moussa
ee233379dd
fix(iam): allow paychex worker ledger dynamodb (#130)
Some checks failed
Deploy / deploy-management (push) Has been cancelled
Deploy / deploy-external-dev (push) Has been cancelled
Deploy / deploy-security (push) Has been cancelled
Deploy / deploy-dev (push) Has been cancelled
Deploy / deploy-prod (push) Has been cancelled
HCP plan/apply and the paychex Lambda boundary need the paychex-worker-ledger table ARN so PLAT-123 can create and use the identity ledger.
2026-08-28 16:11:23 +00:00
Adam Moussa
e21d08bf23
fix(iam): update paychex boundary in place without fn if (PLAT-122) (#129)
Some checks are pending
Deploy / deploy-management (push) Waiting to run
Deploy / deploy-external-dev (push) Waiting to run
Deploy / deploy-security (push) Waiting to run
Deploy / deploy-dev (push) Waiting to run
Deploy / deploy-prod (push) Waiting to run
* fix(iam): update paychex boundary in place without fn if

CloudFormation replaced the named managed policy when the secrets statement was wrapped in Fn::If (409 duplicate name). Keep the six minted ARNs as a static statement so the document updates in place.

* fix(iam): leave paychex boundary description unchanged

Keep the live ManagedPolicy Description so CloudFormation only updates PolicyDocument.
2026-08-27 23:56:49 +00:00
Adam Moussa
f7cc67819b
fix(iam): pin paychex secret arns on lambda boundary (#128)
Some checks are pending
Deploy / deploy-management (push) Waiting to run
Deploy / deploy-external-dev (push) Waiting to run
Deploy / deploy-security (push) Waiting to run
Deploy / deploy-dev (push) Waiting to run
Deploy / deploy-prod (push) Waiting to run
First HCP apply minted the six secret suffixes. Pin GetSecretValue to those ARNs so paychex-placeholder can read oauth-client.
2026-08-27 23:30:43 +00:00
Adam Moussa
2f5e5e6e66
fix(iam): drop unscoped door-unlock domain create (#127)
CreateDomainName cannot be hostname-pinned, and mgmt still holds doorunlock.seahaven.com. Attach the domain at cutover instead of granting collection POST.
2026-08-27 23:03:35 +00:00
Adam Moussa
23d954369d
fix(iam): allow door-unlock apply to create api domain (#126)
Some checks are pending
Deploy / deploy-management (push) Waiting to run
Deploy / deploy-external-dev (push) Waiting to run
Deploy / deploy-security (push) Waiting to run
Deploy / deploy-dev (push) Waiting to run
Deploy / deploy-prod (push) Waiting to run
CreateDomainName authorizes against the /domainnames collection, so the hostname-pinned ARN cannot complete first apply.
2026-08-27 22:43:48 +00:00
Adam Moussa
28a064966b
fix(iam): allow door-unlock plan to read 3cx secret metadata (#125)
The AWS secrets data source calls GetResourcePolicy; the first HCP plan failed without it on the three exact 3CX ARNs.
2026-08-27 22:16:11 +00:00
Adam Moussa
e5e7980508
feat(iam): add paychex-integrations hcptf roles and boundary (PLAT-120) (#124)
* feat(iam): add paychex-integrations hcptf roles and boundary

* fix(iam): split paychex plan lambda list onto Resource *
2026-08-27 21:50:11 +00:00
Adam Moussa
689ec147a3
feat(iam): add door-unlock-api hcptf roles and boundary (PLAT-76) (#123)
Some checks are pending
Deploy / deploy-management (push) Waiting to run
Deploy / deploy-external-dev (push) Waiting to run
Deploy / deploy-security (push) Waiting to run
Deploy / deploy-dev (push) Waiting to run
Deploy / deploy-prod (push) Waiting to run
* feat(iam): add door-unlock-api hcptf roles and boundary

Give HCP Terraform a prod plan/apply pair, a per-workload Lambda boundary with exact SSM and 3CX ARNs, and API access-log delivery so PLAT-76 can leave the mgmt CDK stack.

* fix(iam): pin door-unlock apigw domain and ssm reads

Stop the apply role from managing every HTTP API custom domain, and keep SecureString door-unlock parameters off HCP plan and apply GetParameter.
2026-08-27 21:26:27 +00:00
9bffddfd7b
fix(iam): allow site plan role to describe CF function (PLAT-106) 2026-08-20 15:22:09 -04:00
5fa4267798
chore(iam): drop PascalCase WO Dynamo and alarm ARNs 2026-08-14 11:58:41 -04:00
0f84d7808b
feat(iam): add per-workload lambda execution boundaries
Shared seahaven-lambda-execution-boundary stays unchanged for live roles.
New named policies plus an enumerated StringEquals allow-list unblock the
next PLAT-71 widen without growing the 6144-character shared document.
2026-08-13 16:47:53 -04:00
81cc8eb4f9
fix(iam): consolidate meal-order boundary Sid under PolicySize cap 2026-08-10 15:57:08 -04:00
7c43c867e3
fix(iam): allow execute-api Invoke for meal-order weekly-menu boundary 2026-08-10 15:42:12 -04:00
b76d0578e0
fix(iam): drop PutResourcePolicy from meal-order apply role
Pre-grant delivery.logs write via MealOrderApiAccessLogResourcePolicy on
substrate so the HCP apply role cannot mutate account-wide log resource
policies.
2026-08-10 14:57:17 -04:00
e10462d25e
fix(iam): allow API GW Log Delivery on meal-order apply role 2026-08-10 14:47:30 -04:00
6bb2d54814
fix(iam): allow PassRole to apigateway for meal-order authorizer 2026-08-10 13:46:12 -04:00
1bb5e79ea0
fix(iam): allow ssm:ListTagsForResource on meal-order plan role 2026-08-10 13:23:56 -04:00
Adam Moussa
f44b88732e
fix(iam): allow ssm:DescribeParameters for meal-order hcptf roles (#99)
Some checks failed
Deploy / deploy-management (push) Has been cancelled
Deploy / deploy-external-dev (push) Has been cancelled
Deploy / deploy-security (push) Has been cancelled
Deploy / deploy-dev (push) Has been cancelled
Deploy / deploy-prod (push) Has been cancelled
2026-08-08 00:11:48 +00:00
Adam Moussa
3605215a28
refactor(iam): consolidate boundary statements under PolicySize cap (#98)
Some checks are pending
Deploy / deploy-management (push) Waiting to run
Deploy / deploy-external-dev (push) Waiting to run
Deploy / deploy-security (push) Waiting to run
Deploy / deploy-dev (push) Waiting to run
Deploy / deploy-prod (push) Waiting to run
Merge workload secret/DDB/S3 SIDs and trim meal-order extras so the
shared lambda execution boundary fits under the 6144-character limit.
2026-08-07 23:54:28 +00:00
Adam Moussa
44b672ae9a
feat(iam): add hcptf roles and boundary widen for meal-order-manager (PLAT-70) (#97)
* feat(iam): add hcptf roles and boundary widen for meal-order-manager

Append plan/apply OIDC roles for meal-order-manager-prod and widen the lambda execution boundary with exact prod secret ARN and data-plane statements.

* fix(iam): make meal-order plan role Lambda refresh read-only

Replace plan-role lambda:* with Get*/List* so plan-phase credentials cannot mutate functions or layers.
2026-08-07 19:36:20 -04:00
Adam Moussa
a6f22880db
feat(waf): add seahaven-prod shared CloudFront WebACL (PLAT-92) (#96)
Some checks are pending
Deploy / deploy-management (push) Waiting to run
Deploy / deploy-external-dev (push) Waiting to run
Deploy / deploy-security (push) Waiting to run
Deploy / deploy-dev (push) Waiting to run
Deploy / deploy-prod (push) Waiting to run
* feat(waf): add seahaven-prod shared CloudFront WebACL stack

Stand up AppWebAcl in a thin prod stack and widen seahaven-site HCP
roles to read the SSM ARN so CloudFront can associate the ACL in-account.

* fix(deploy): add app-web-acl-prod to deploy.yaml
2026-08-07 17:07:04 -04:00
Adam Moussa
35461d9267
feat(iam): add hcptf-seahaven-site plan/apply roles (PLAT-91) (#89)
Some checks are pending
Deploy / deploy-management (push) Waiting to run
Deploy / deploy-external-dev (push) Waiting to run
Deploy / deploy-security (push) Waiting to run
Deploy / deploy-dev (push) Waiting to run
Deploy / deploy-prod (push) Waiting to run
* feat(iam): add hcptf-seahaven-site plan/apply roles

Static-site HCP substrate for seahaven-site-prod plus boundary widen for
the TF-managed content-deploy role (S3 origin + CloudFront invalidate).

* fix(iam): allow seahaven-site HCP roles to read GitHub OIDC provider

Plan refresh needs iam:GetOpenIDConnectProvider for the content-deploy
role trust data source (PLAT-91 first-plan AccessDenied).
2026-08-07 15:09:57 -04:00
Adam Moussa
e12944a42d
fix(iam): allow kebab WO tables on lambda execution boundary (#90)
Widen ProcurementIngestDynamoDB so workorder Lambdas can read/write
work-orders and work-order-comments after the PLAT-11 rename.
2026-08-07 14:20:40 -04:00
Adam Moussa
ff77ffd421
fix(iam): allow HCP procurement-ingest kebab WO Dynamo tables (#88)
Some checks are pending
Deploy / deploy-management (push) Waiting to run
Deploy / deploy-external-dev (push) Waiting to run
Deploy / deploy-security (push) Waiting to run
Deploy / deploy-dev (push) Waiting to run
Deploy / deploy-prod (push) Waiting to run
Widen hcptf-procurement-ingest apply and plan-refresh DynamoDB/CloudWatch
ARN pins for work-orders and work-order-comments (PLAT-11 rename).
2026-08-07 13:53:42 -04:00
202103041c
fix(iam): allow API GW and ESM tagging for procurement-ingest
Provider default_tags need apigateway /tags/* and unconditioned ESM
TagResource after import-in-place.
2026-08-07 11:09:06 -04:00
a5997f878b
fix(iam): widen procurement-ingest plan refresh for import
Add GetEventSourceMapping, SSM GetParameter pins, and Resource "*" for
kms:ListAliases so the first HCP import plan can refresh.
2026-08-07 11:00:49 -04:00
Adam Moussa
a5fa0b16a3
feat(iam): add hcptf roles and boundary for procurement-ingest (PLAT-86) (#85)
* feat(iam): add hcptf roles and boundary for procurement-ingest

* fix(iam): tighten procurement-ingest apply and plan scopes

Replace kms:* and secret-value writes on shell statements; split IAM
collection APIs onto Resource "*".
2026-08-07 10:41:12 -04:00
Adam Moussa
69f31842cb
feat(iam): add hcptf roles for sh-openswe-traces-prod (PLAT-73) (#80)
Some checks are pending
Deploy / deploy-management (push) Waiting to run
Deploy / deploy-external-dev (push) Waiting to run
Deploy / deploy-security (push) Waiting to run
Deploy / deploy-dev (push) Waiting to run
Deploy / deploy-prod (push) Waiting to run
* feat(iam): add hcptf roles for sh-openswe-traces-prod

Storage/IAM-user apply and plan roles for the HCP workspace. No Lambda
boundary widen; explicit IAM user CRUD because hcptf-iam-management is
role-path-only.

* fix(iam): pin CreateSecret to exact export secret name

Remove CreateSecret and UpdateSecret from the ARN-prefix shell grant so
apply cannot create longer-named secrets or overwrite SecretString.
2026-08-05 22:46:32 +00:00
Adam Moussa
fc64b03e3d
feat(iam): hcptf front-integrations roles and boundary (PLAT-72) (#81)
* feat(iam): add hcptf front-integrations roles and boundary widen

Add plan/apply OIDC roles for front-integrations-prod and widen the
Lambda execution boundary with exact prod secret ARNs plus DynamoDB
CRUD on front-sla-alerts.

* fix(iam): restrict front-integrations plan role to lambda Get/List

Keep mutate APIs on the apply role so a compromised plan-phase
OIDC session cannot update or delete front-* functions.
2026-08-05 18:33:31 -04:00
Adam Moussa
9ee4d4a3d7
docs(iam): codify hcp terraform migration checklist from PLAT-56 (#79)
Some checks are pending
Deploy / deploy-management (push) Waiting to run
Deploy / deploy-external-dev (push) Waiting to run
Deploy / deploy-security (push) Waiting to run
Deploy / deploy-dev (push) Waiting to run
Deploy / deploy-prod (push) Waiting to run
Expand the README playbook to steps 0–10 and document the required
plan-refresh sidecar plus prefix-scoped apply-role wildcards so the
next workload copies afi patterns instead of relearning first-apply misses.
2026-08-05 16:14:16 -04:00
46829fc2c1
fix(iam): use lambda:* and events:* on afi hcptf apply scope
Provider refresh needs GetFunctionCodeSigningConfig and similar reads;
keep blast radius on afi-* function/layer/rule ARNs only.
2026-08-05 12:59:19 -04:00
f4292832fe
fix(iam): add plan-role refresh reads for afi terraform state
ViewOnlyAccess omits iam:GetRole and events:DescribeRule; without a
scoped refresh policy, HCP plans fail after the first partial apply.
2026-08-05 12:57:23 -04:00
3512214d14
fix(iam): allow s3:* on afi artifact bucket for provider reads
First HCP apply failed on s3:GetBucketAcl after CreateBucket; scope
remains the single artifact bucket ARN.
2026-08-05 12:56:24 -04:00
Adam Moussa
4e1cf4c0bd
feat(iam): add hcptf roles/boundary widen - afi-backup-monitor (PLAT-56) (#76)
* feat(iam): add hcptf roles and boundary widen for afi-backup-monitor

Provision plan/apply OIDC roles for workspace afi-backup-monitor-prod
and widen the prod Lambda boundary with the two exact secret ARNs.

* fix(iam): split DescribeLogGroups and allow afi artifact bucket

logs:DescribeLogGroups cannot be resource-scoped; grant it on *. Add
S3 permissions for the HCP Lambda artifact bucket used by PLAT-56.
2026-08-05 12:44:52 -04:00