Adam Moussa
db9465deda
fix(iam): allow shoc-backend HCP apply to write deploy SSM and matching githubdeploy trust (PLAT-148) ( #148 )
...
* fix(iam): allow shoc-backend HCP apply to write deploy SSM and matching githubdeploy trust (PLAT-148)
* fix(iam): grant shoc-backend staging plan named inventory reads (PLAT-148)
* fix(iam): allow staging githubdeploy to GetObject release zips (PLAT-148)
* fix(iam): allow staging githubdeploy to write EB processed extensions (PLAT-148)
* fix(iam): allow staging githubdeploy GetObjectAcl on release zips (PLAT-148)
* fix(iam): grant staging githubdeploy named S3 reads on EB resources prefix (PLAT-148)
* fix(iam): allow staging githubdeploy to delete EB version cache objects (PLAT-148)
* fix(iam): scope staging githubdeploy S3 object access to the EB bucket (PLAT-148)
* fix(iam): allow staging githubdeploy PutObjectVersionAcl on EB artifacts (PLAT-148)
* fix(iam): allow staging githubdeploy GetBucketPolicy on the EB bucket (PLAT-148)
* fix(iam): scope staging githubdeploy S3 objects to SHOC and staging EB prefixes (PLAT-148)
2026-09-18 18:13:01 +00:00
Adam Moussa
7a1623e8d4
fix(iam): allow paychex period table and optional secrets (PLAT-195) ( #147 )
...
Deploy / deploy-management (push) Has been cancelled
Deploy / deploy-external-dev (push) Has been cancelled
Deploy / deploy-security (push) Has been cancelled
Deploy / deploy-dev (push) Has been cancelled
Deploy / deploy-prod (push) Has been cancelled
* fix(iam): allow paychex period table and optional secrets (PLAT-195)
The processor role already allows these ARNs. The live boundary denied
them, so GetSecretValue and period PutItem returned HTTP 400. Sync the
template to the live ceiling and add the missing period table plus
slack-admin and afterhours secret suffixes.
* fix(iam): keep paychex boundary description unchanged (PLAT-195)
IAM managed-policy Description is immutable. Changing it on a named
policy forces replacement and 409s against the live ManagedPolicyName.
Widen PolicyDocument only.
2026-09-14 18:31:08 +00:00
Adam Moussa
a492a45e07
chore(iam): remove frontend tf-poc substrate after teardown (PLAT-194) ( #146 )
Deploy / deploy-management (push) Has been cancelled
Deploy / deploy-external-dev (push) Has been cancelled
Deploy / deploy-security (push) Has been cancelled
Deploy / deploy-dev (push) Has been cancelled
Deploy / deploy-prod (push) Has been cancelled
2026-09-11 22:17:00 +00:00
Adam Moussa
5d613c73bc
feat(iam): allow frontend tf-poc HCP apply destroy (PLAT-193) ( #145 )
2026-09-11 21:46:59 +00:00
Adam Moussa
3c54df6341
fix(iam): allow GitHub frontend deploy roles to GetDistribution (PLAT-192) ( #144 )
...
Deploy / deploy-management (push) Waiting to run
Deploy / deploy-external-dev (push) Waiting to run
Deploy / deploy-security (push) Waiting to run
Deploy / deploy-dev (push) Waiting to run
Deploy / deploy-prod (push) Waiting to run
Verify and live-state summary call get-distribution; the identity policy already granted it, but the permissions boundary denied the action.
2026-09-11 19:37:24 +00:00
Adam Moussa
60b978aa2a
feat(iam): allow frontend HCP apply to own release pointer and invalidation (PLAT-188) ( #143 )
...
Deploy / deploy-management (push) Waiting to run
Deploy / deploy-external-dev (push) Waiting to run
Deploy / deploy-security (push) Waiting to run
Deploy / deploy-dev (push) Waiting to run
Deploy / deploy-prod (push) Waiting to run
* feat(iam): allow frontend HCP apply to own release pointer and invalidation (PLAT-188)
Plan and apply roles can read .release/current; apply can PutObject that key and CreateInvalidation on the exact distribution.
* fix(iam): allow frontend HCP roles to tag the release pointer (PLAT-188)
Terraform aws_s3_object lists object tags on every refresh, so plan and apply need GetObjectTagging and apply needs PutObjectTagging on the exact .release/current key.
2026-09-11 17:37:42 +00:00
Adam Moussa
0c6f307b61
feat(iam): allow frontend HCP apply to update exact CloudFront resources (PLAT-187) ( #142 )
...
Deploy / deploy-management (push) Waiting to run
Deploy / deploy-external-dev (push) Waiting to run
Deploy / deploy-security (push) Waiting to run
Deploy / deploy-dev (push) Waiting to run
Deploy / deploy-prod (push) Waiting to run
* feat(iam): allow frontend HCP apply to update exact CloudFront resources (PLAT-187)
Phase 2 ownership tags cannot apply while UpdateDistribution and UpdateFunction are denied on *. Allow those two actions only on the pinned distribution and function ARNs.
* fix(iam): allow PublishFunction on exact frontend CloudFront functions (PLAT-187)
The AWS provider publishes after UpdateFunction, including tag-only applies, so denying PublishFunction on * still blocked Phase 2 function updates.
2026-09-11 15:08:21 +00:00
Adam Moussa
a829854cd0
feat(hcp): flag workspaces that skip source-path file triggers (PLAT-183) ( #141 )
Deploy / deploy-management (push) Waiting to run
Deploy / deploy-external-dev (push) Waiting to run
Deploy / deploy-security (push) Waiting to run
Deploy / deploy-dev (push) Waiting to run
Deploy / deploy-prod (push) Waiting to run
2026-09-10 21:00:33 +00:00
Adam Moussa
fa940e69c6
feat(iam): allow meal-order-manager to send to paychex-checkcomponents (PLAT-135) ( #140 )
Deploy / deploy-management (push) Waiting to run
Deploy / deploy-external-dev (push) Waiting to run
Deploy / deploy-security (push) Waiting to run
Deploy / deploy-dev (push) Waiting to run
Deploy / deploy-prod (push) Waiting to run
2026-09-09 23:58:42 +00:00
Adam Moussa
6bc4f6e095
chore(iam): remove backend tf-poc boundaries ( #139 )
Deploy / deploy-management (push) Has been cancelled
Deploy / deploy-external-dev (push) Has been cancelled
Deploy / deploy-security (push) Has been cancelled
Deploy / deploy-dev (push) Has been cancelled
Deploy / deploy-prod (push) Has been cancelled
2026-09-03 15:04:58 +00:00
Adam Moussa
4f0d84cddb
fix(iam): use unique HCP bootstrap workspace names (PLAT-143) ( #138 )
...
Deploy / deploy-management (push) Waiting to run
Deploy / deploy-external-dev (push) Waiting to run
Deploy / deploy-security (push) Waiting to run
Deploy / deploy-dev (push) Waiting to run
Deploy / deploy-prod (push) Waiting to run
HCP workspace names are org-unique, so prod and dev cannot both be iam-bootstrap. Pin trust to iam-bootstrap-prod and iam-bootstrap-dev.
2026-09-02 15:51:39 +00:00
Adam Moussa
b02f52b805
feat(iam): lock app-owned HCP IAM and add bootstrap SCP (PLAT-143) ( #137 )
...
* feat(iam): lock app-owned HCP IAM and add bootstrap SCP (PLAT-143)
* fix(iam): pin HCP boundary ARNs and bootstrap trust window (PLAT-143)
Null on iam:PermissionsBoundary accepted any ceiling, including AdministratorAccess. Import apply cannot self-mutate hcptf-* while bootstrap trust is iam-bootstrap only; add a time-boxed exact StringEquals workspace grant instead of StringLike.
2026-09-02 15:22:48 +00:00
Adam Moussa
35dc61b806
feat(iam): allow tf-poc HCP apply destroy ( #136 )
Deploy / deploy-management (push) Waiting to run
Deploy / deploy-external-dev (push) Waiting to run
Deploy / deploy-security (push) Waiting to run
Deploy / deploy-dev (push) Waiting to run
Deploy / deploy-prod (push) Waiting to run
2026-09-01 16:14:06 +00:00
Adam Moussa
6d5811f08e
fix(iam): codify live terraform-substrate IAM (PLAT-142) ( #135 )
...
Deploy / deploy-management (push) Waiting to run
Deploy / deploy-external-dev (push) Waiting to run
Deploy / deploy-security (push) Waiting to run
Deploy / deploy-dev (push) Waiting to run
Deploy / deploy-prod (push) Waiting to run
* fix(iam): allow frontend import plan to read deploy boundaries
* fix(iam): grant backend apply role EB UpdateEnvironment follow-on perms
2026-09-01 00:16:34 +00:00
Adam Moussa
559eed1e98
fix(iam): allow backend Terraform refresh (PLAT-141) ( #134 )
...
Deploy / deploy-management (push) Waiting to run
Deploy / deploy-external-dev (push) Waiting to run
Deploy / deploy-security (push) Waiting to run
Deploy / deploy-dev (push) Waiting to run
Deploy / deploy-prod (push) Waiting to run
* fix(iam): allow backend import plan reads
* fix(iam): authorize backend EB refresh
* fix(iam): authorize backend EB ownership check
2026-08-31 17:04:00 +00:00
Adam Moussa
6a0713f49d
feat(iam): add frontend Terraform substrate ( #133 )
...
Deploy / deploy-management (push) Waiting to run
Deploy / deploy-external-dev (push) Waiting to run
Deploy / deploy-security (push) Waiting to run
Deploy / deploy-dev (push) Waiting to run
Deploy / deploy-prod (push) Waiting to run
* feat(iam): add frontend Terraform substrate
* fix(iam): align frontend Terraform substrate
* feat(iam): enable frontend live Terraform roles
2026-08-31 02:25:47 +00:00
Adam Moussa
08191ded4c
chore(iam): finalize backend role ownership ( #132 )
...
Deploy / deploy-management (push) Waiting to run
Deploy / deploy-external-dev (push) Waiting to run
Deploy / deploy-security (push) Waiting to run
Deploy / deploy-dev (push) Waiting to run
Deploy / deploy-prod (push) Waiting to run
* chore(iam): finalize backend role ownership
* fix(iam): complete backend import permissions
2026-08-30 20:12:54 +00:00
Adam Moussa
dba0871587
feat(iam): add external-dev backend Terraform substrate ( #131 )
...
Deploy / deploy-management (push) Waiting to run
Deploy / deploy-external-dev (push) Waiting to run
Deploy / deploy-security (push) Waiting to run
Deploy / deploy-dev (push) Waiting to run
Deploy / deploy-prod (push) Waiting to run
* feat(iam): add external-dev backend terraform substrate
* fix(iam): require boundaries for SHOC policy writes
2026-08-29 21:04:40 +00:00
Adam Moussa
ee233379dd
fix(iam): allow paychex worker ledger dynamodb ( #130 )
...
Deploy / deploy-management (push) Has been cancelled
Deploy / deploy-external-dev (push) Has been cancelled
Deploy / deploy-security (push) Has been cancelled
Deploy / deploy-dev (push) Has been cancelled
Deploy / deploy-prod (push) Has been cancelled
HCP plan/apply and the paychex Lambda boundary need the paychex-worker-ledger table ARN so PLAT-123 can create and use the identity ledger.
2026-08-28 16:11:23 +00:00
Adam Moussa
e21d08bf23
fix(iam): update paychex boundary in place without fn if (PLAT-122) ( #129 )
...
Deploy / deploy-management (push) Waiting to run
Deploy / deploy-external-dev (push) Waiting to run
Deploy / deploy-security (push) Waiting to run
Deploy / deploy-dev (push) Waiting to run
Deploy / deploy-prod (push) Waiting to run
* fix(iam): update paychex boundary in place without fn if
CloudFormation replaced the named managed policy when the secrets statement was wrapped in Fn::If (409 duplicate name). Keep the six minted ARNs as a static statement so the document updates in place.
* fix(iam): leave paychex boundary description unchanged
Keep the live ManagedPolicy Description so CloudFormation only updates PolicyDocument.
2026-08-27 23:56:49 +00:00
Adam Moussa
f7cc67819b
fix(iam): pin paychex secret arns on lambda boundary ( #128 )
...
Deploy / deploy-management (push) Waiting to run
Deploy / deploy-external-dev (push) Waiting to run
Deploy / deploy-security (push) Waiting to run
Deploy / deploy-dev (push) Waiting to run
Deploy / deploy-prod (push) Waiting to run
First HCP apply minted the six secret suffixes. Pin GetSecretValue to those ARNs so paychex-placeholder can read oauth-client.
2026-08-27 23:30:43 +00:00
Adam Moussa
2f5e5e6e66
fix(iam): drop unscoped door-unlock domain create ( #127 )
...
CreateDomainName cannot be hostname-pinned, and mgmt still holds doorunlock.seahaven.com. Attach the domain at cutover instead of granting collection POST.
2026-08-27 23:03:35 +00:00
Adam Moussa
23d954369d
fix(iam): allow door-unlock apply to create api domain ( #126 )
...
Deploy / deploy-management (push) Waiting to run
Deploy / deploy-external-dev (push) Waiting to run
Deploy / deploy-security (push) Waiting to run
Deploy / deploy-dev (push) Waiting to run
Deploy / deploy-prod (push) Waiting to run
CreateDomainName authorizes against the /domainnames collection, so the hostname-pinned ARN cannot complete first apply.
2026-08-27 22:43:48 +00:00
Adam Moussa
28a064966b
fix(iam): allow door-unlock plan to read 3cx secret metadata ( #125 )
...
The AWS secrets data source calls GetResourcePolicy; the first HCP plan failed without it on the three exact 3CX ARNs.
2026-08-27 22:16:11 +00:00
Adam Moussa
e5e7980508
feat(iam): add paychex-integrations hcptf roles and boundary (PLAT-120) ( #124 )
...
* feat(iam): add paychex-integrations hcptf roles and boundary
* fix(iam): split paychex plan lambda list onto Resource *
2026-08-27 21:50:11 +00:00
Adam Moussa
689ec147a3
feat(iam): add door-unlock-api hcptf roles and boundary (PLAT-76) ( #123 )
...
Deploy / deploy-management (push) Waiting to run
Deploy / deploy-external-dev (push) Waiting to run
Deploy / deploy-security (push) Waiting to run
Deploy / deploy-dev (push) Waiting to run
Deploy / deploy-prod (push) Waiting to run
* feat(iam): add door-unlock-api hcptf roles and boundary
Give HCP Terraform a prod plan/apply pair, a per-workload Lambda boundary with exact SSM and 3CX ARNs, and API access-log delivery so PLAT-76 can leave the mgmt CDK stack.
* fix(iam): pin door-unlock apigw domain and ssm reads
Stop the apply role from managing every HTTP API custom domain, and keep SecureString door-unlock parameters off HCP plan and apply GetParameter.
2026-08-27 21:26:27 +00:00
Adam Moussa
608c11ed0a
chore(deps): remove dependabot version updates ( #122 )
...
Deploy / deploy-management (push) Has been cancelled
Deploy / deploy-external-dev (push) Has been cancelled
Deploy / deploy-security (push) Has been cancelled
Deploy / deploy-dev (push) Has been cancelled
Deploy / deploy-prod (push) Has been cancelled
Renovate is the version-update bot. GitHub Dependabot alerts stay.
2026-08-25 11:51:32 -04:00
dependabot[bot]
e13bf89545
chore(deps): bump the minor-and-patch group across 1 directory with 3 updates ( #120 )
Deploy / deploy-management (push) Waiting to run
Deploy / deploy-external-dev (push) Waiting to run
Deploy / deploy-security (push) Waiting to run
Deploy / deploy-dev (push) Waiting to run
Deploy / deploy-prod (push) Waiting to run
2026-08-25 01:23:05 +00:00
Adam Moussa
91fde44ec3
chore(ci): remove pr policy workflow caller ( #119 )
Deploy / deploy-management (push) Waiting to run
Deploy / deploy-external-dev (push) Waiting to run
Deploy / deploy-security (push) Waiting to run
Deploy / deploy-dev (push) Waiting to run
Deploy / deploy-prod (push) Waiting to run
2026-08-24 15:12:40 -04:00
Adam Moussa
dbf72e692b
chore(ci): switch auto-merge from seahaven-bot to Mergify ( #118 )
Deploy / deploy-management (push) Waiting to run
Deploy / deploy-external-dev (push) Waiting to run
Deploy / deploy-security (push) Waiting to run
Deploy / deploy-dev (push) Waiting to run
Deploy / deploy-prod (push) Waiting to run
2026-08-24 13:52:39 -04:00
Adam Moussa
c8e8a3287e
fix(ci): enqueue merge queue as seahaven-bot (PLAT-108) ( #116 )
...
Deploy / deploy-management (push) Waiting to run
Deploy / deploy-external-dev (push) Waiting to run
Deploy / deploy-security (push) Waiting to run
Deploy / deploy-dev (push) Waiting to run
Deploy / deploy-prod (push) Waiting to run
* fix(ci): enqueue merge queue as seahaven-bot
* fix(ci): limit seahaven-bot enqueue to PRs targeting main
2026-08-24 15:17:55 +00:00
Adam Moussa
de0e7456e9
ci: enable squash auto-merge on ready PRs (PLAT-108) ( #115 )
...
Deploy / deploy-management (push) Has been cancelled
Deploy / deploy-external-dev (push) Has been cancelled
Deploy / deploy-security (push) Has been cancelled
Deploy / deploy-dev (push) Has been cancelled
Deploy / deploy-prod (push) Has been cancelled
* ci: enable squash auto-merge on ready PRs
* fix(ci): grant contents read so auto-merge can query the PR
* fix(ci): restore contents write for enablePullRequestAutoMerge
* fix(ci): serialize auto-merge enable and ignore already-enabled
* fix(ci): request squash auto-merge so PRs enter the merge queue
2026-08-21 23:32:53 +00:00
Adam Moussa
e8f241712a
ci: add merge_group trigger for required ci / ci ( #114 )
Deploy / deploy-management (push) Waiting to run
Deploy / deploy-external-dev (push) Waiting to run
Deploy / deploy-security (push) Waiting to run
Deploy / deploy-dev (push) Waiting to run
Deploy / deploy-prod (push) Waiting to run
2026-08-21 17:41:38 -04:00
Adam Moussa
14bcbc8384
Merge pull request #112 from Sea-Haven-Industries/fix/site-plan-describe-function
...
Deploy / deploy-management (push) Waiting to run
Deploy / deploy-external-dev (push) Waiting to run
Deploy / deploy-security (push) Waiting to run
Deploy / deploy-dev (push) Waiting to run
Deploy / deploy-prod (push) Waiting to run
fix(iam): allow site plan role to describe CF function (PLAT-106)
2026-08-20 15:58:21 -04:00
9bffddfd7b
fix(iam): allow site plan role to describe CF function (PLAT-106)
2026-08-20 15:22:09 -04:00
Adam Moussa
e2b4b635e3
Merge pull request #95 from Sea-Haven-Industries/dependabot/npm_and_yarn/minor-and-patch-32f5f3edd0
...
Deploy / deploy-management (push) Has been cancelled
Deploy / deploy-external-dev (push) Has been cancelled
Deploy / deploy-security (push) Has been cancelled
Deploy / deploy-dev (push) Has been cancelled
Deploy / deploy-prod (push) Has been cancelled
chore(deps): bump the minor-and-patch group with 4 updates
2026-08-17 16:26:13 -04:00
d1f6f6ac46
fix: bump aws-cdk-lib to 2.265.0
2026-08-17 16:14:53 -04:00
Adam Moussa
314c8e3042
Merge branch 'main' into dependabot/npm_and_yarn/minor-and-patch-32f5f3edd0
2026-08-17 15:49:43 -04:00
dependabot[bot]
411307aaaf
Merge pull request #107 from Sea-Haven-Industries/dependabot/github_actions/Sea-Haven-Industries/dot-github/dot-github/workflows/callable-labeler.yaml-1.0.7
...
Deploy / deploy-management (push) Has been cancelled
Deploy / deploy-external-dev (push) Has been cancelled
Deploy / deploy-security (push) Has been cancelled
Deploy / deploy-dev (push) Has been cancelled
Deploy / deploy-prod (push) Has been cancelled
chore(deps): bump Sea-Haven-Industries/.github/.github/workflows/callable-labeler.yaml from 1.0.6 to 1.0.7
2026-08-14 20:31:36 -04:00
dependabot[bot]
c61f444e8f
chore(deps): bump callable-labeler.yaml from 1.0.6 to 1.0.7
...
Bumps [Sea-Haven-Industries/.github/.github/workflows/callable-labeler.yaml](https://github.com/sea-haven-industries/.github ) from 1.0.6 to 1.0.7.
- [Release notes](https://github.com/sea-haven-industries/.github/releases )
- [Commits](7ac3528750...e5691d8a7f )
---
updated-dependencies:
- dependency-name: Sea-Haven-Industries/.github/.github/workflows/callable-labeler.yaml
dependency-version: 1.0.7
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com>
2026-08-14 20:30:19 -04:00
dependabot[bot]
9b1cf9c9e7
chore(deps): bump cd-cdk.yaml from 1.0.6 to 1.0.7
...
Bumps [Sea-Haven-Industries/.github/.github/workflows/cd-cdk.yaml](https://github.com/sea-haven-industries/.github ) from 1.0.6 to 1.0.7.
- [Release notes](https://github.com/sea-haven-industries/.github/releases )
- [Commits](7ac3528750...e5691d8a7f )
---
updated-dependencies:
- dependency-name: Sea-Haven-Industries/.github/.github/workflows/cd-cdk.yaml
dependency-version: 1.0.7
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com>
2026-08-14 20:29:55 -04:00
dependabot[bot]
e8e74073c7
chore(deps): bump callable-pr-policy.yaml from 1.0.6 to 1.0.7
...
Bumps [Sea-Haven-Industries/.github/.github/workflows/callable-pr-policy.yaml](https://github.com/sea-haven-industries/.github ) from 1.0.6 to 1.0.7.
- [Release notes](https://github.com/sea-haven-industries/.github/releases )
- [Commits](7ac3528750...e5691d8a7f )
---
updated-dependencies:
- dependency-name: Sea-Haven-Industries/.github/.github/workflows/callable-pr-policy.yaml
dependency-version: 1.0.7
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com>
2026-08-14 20:29:10 -04:00
dependabot[bot]
9f7b7d522e
chore(deps): bump ci-typescript-cdk.yaml from 1.0.6 to 1.0.7
...
Bumps [Sea-Haven-Industries/.github/.github/workflows/ci-typescript-cdk.yaml](https://github.com/sea-haven-industries/.github ) from 1.0.6 to 1.0.7.
- [Release notes](https://github.com/sea-haven-industries/.github/releases )
- [Commits](7ac3528750...e5691d8a7f )
---
updated-dependencies:
- dependency-name: Sea-Haven-Industries/.github/.github/workflows/ci-typescript-cdk.yaml
dependency-version: 1.0.7
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com>
2026-08-14 20:28:36 -04:00
dependabot[bot]
c52aa5bf99
chore(deps): bump callable-dependency-review.yaml from 1.0.6 to 1.0.7
...
Bumps [Sea-Haven-Industries/.github/.github/workflows/callable-dependency-review.yaml](https://github.com/sea-haven-industries/.github ) from 1.0.6 to 1.0.7.
- [Release notes](https://github.com/sea-haven-industries/.github/releases )
- [Commits](7ac3528750...e5691d8a7f )
---
updated-dependencies:
- dependency-name: Sea-Haven-Industries/.github/.github/workflows/callable-dependency-review.yaml
dependency-version: 1.0.7
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com>
2026-08-14 20:27:37 -04:00
Adam Moussa
a81acbf18d
Merge pull request #105 from Sea-Haven-Industries/chore/strip-pascalcase-wo-iam-pins
...
Deploy / deploy-management (push) Waiting to run
Deploy / deploy-external-dev (push) Waiting to run
Deploy / deploy-security (push) Waiting to run
Deploy / deploy-dev (push) Waiting to run
Deploy / deploy-prod (push) Waiting to run
chore(iam): drop PascalCase WO Dynamo and alarm ARNs (PLAT-11)
2026-08-14 12:12:48 -04:00
5fa4267798
chore(iam): drop PascalCase WO Dynamo and alarm ARNs
2026-08-14 11:58:41 -04:00
Adam Moussa
a2e9449ef1
Merge pull request #104 from Sea-Haven-Industries/feature/per-workload-lambda-boundaries
...
Deploy / deploy-management (push) Waiting to run
Deploy / deploy-external-dev (push) Waiting to run
Deploy / deploy-security (push) Waiting to run
Deploy / deploy-dev (push) Waiting to run
Deploy / deploy-prod (push) Waiting to run
feat(iam): add per-workload lambda execution boundaries (PLAT-52)
2026-08-13 17:51:53 -04:00
0f84d7808b
feat(iam): add per-workload lambda execution boundaries
...
Shared seahaven-lambda-execution-boundary stays unchanged for live roles.
New named policies plus an enumerated StringEquals allow-list unblock the
next PLAT-71 widen without growing the 6144-character shared document.
2026-08-13 16:47:53 -04:00
Adam Moussa
ef1afab33b
Merge pull request #103 from Sea-Haven-Industries/fix/meal-order-weekly-menu-execute-api
...
Deploy / deploy-management (push) Has been cancelled
Deploy / deploy-external-dev (push) Has been cancelled
Deploy / deploy-security (push) Has been cancelled
Deploy / deploy-dev (push) Has been cancelled
Deploy / deploy-prod (push) Has been cancelled
fix(iam): meal-order weekly-menu execute-api boundary (PLAT-100)
2026-08-10 16:05:18 -04:00
81cc8eb4f9
fix(iam): consolidate meal-order boundary Sid under PolicySize cap
2026-08-10 15:57:08 -04:00