feat(exec-aide): CMK SSE on exec-aide DynamoDB table (INFRA-95) #53

Merged
amoussa1229 merged 2 commits from infra-95-execaide-cmk into main 2026-06-09 16:41:56 +00:00
amoussa1229 commented 2026-06-09 15:59:40 +00:00 (Migrated from github.com)

Summary

Enables customer-managed CMK SSE on the exec-aide DynamoDB table (was AWS-owned key), completing the last table in INFRA-95 / M-3.

  • Imports the shared alias/seahaven-dynamodb CMK via SSM /seahaven/dynamodb/cmk-arn.
  • In-place UpdateTable (no replacement, no data loss) — confirmed via change-set cdk diff.
  • CDK auto-grants kms:* (Decrypt/DescribeKey + Encrypt/GenerateDataKey*/ReEncrypt* for writers) to the 5 in-stack consumer roles (4 pipeline Lambdas + SocketMode Fargate task role).

Deploy-before-merge (done)

Deployed to prod 2026-06-09 and verified:

  • describe-table exec-aide → SSEType: KMS, key 0b660af3… (alias/seahaven-dynamodb)
  • scan --limit 1 decrypts successfully
  • SocketMode ECS service 1/1, rollout COMPLETED

Review

Cross-reviewed for breaking changes (IAM/KMS). Key policy verified: statement 1 (root: kms:*) delegates to IAM so the identity grants suffice; statement 2 (AllowDynamoDbSSEViaService + CreateGrant) covers SSE activation. 4 peer tables already run on this key.

Closes INFRA-95 (pending the slack-bot consumer-grant codification PR).

## Summary Enables customer-managed CMK SSE on the `exec-aide` DynamoDB table (was AWS-owned key), completing the last table in **INFRA-95 / M-3**. - Imports the shared `alias/seahaven-dynamodb` CMK via SSM `/seahaven/dynamodb/cmk-arn`. - In-place `UpdateTable` (no replacement, no data loss) — confirmed via change-set `cdk diff`. - CDK auto-grants `kms:*` (Decrypt/DescribeKey + Encrypt/GenerateDataKey*/ReEncrypt* for writers) to the 5 in-stack consumer roles (4 pipeline Lambdas + SocketMode Fargate task role). ## Deploy-before-merge (done) Deployed to prod 2026-06-09 and verified: - `describe-table exec-aide` → `SSEType: KMS`, key `0b660af3…` (alias/seahaven-dynamodb) - `scan --limit 1` decrypts successfully - SocketMode ECS service 1/1, rollout COMPLETED ## Review Cross-reviewed for breaking changes (IAM/KMS). Key policy verified: statement 1 (`root: kms:*`) delegates to IAM so the identity grants suffice; statement 2 (`AllowDynamoDbSSEViaService` + CreateGrant) covers SSE activation. 4 peer tables already run on this key. Closes INFRA-95 (pending the slack-bot consumer-grant codification PR).
This repo is archived. You cannot comment on pull requests.
No description provided.