feat(exec-aide): CMK SSE on exec-aide DynamoDB table (INFRA-95) #53
No reviewers
Labels
No labels
app
bug
ci
compliance
dependencies
docs
documentation
duplicate
enhancement
good first issue
help wanted
infra
invalid
javascript
python
question
wontfix
No milestone
No project
No assignees
1 participant
Due date
No due date set.
Dependencies
No dependencies set.
Reference: adam/exec-aide#53
Loading…
Add table
Reference in a new issue
No description provided.
Delete branch "infra-95-execaide-cmk"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Summary
Enables customer-managed CMK SSE on the
exec-aideDynamoDB table (was AWS-owned key), completing the last table in INFRA-95 / M-3.alias/seahaven-dynamodbCMK via SSM/seahaven/dynamodb/cmk-arn.UpdateTable(no replacement, no data loss) — confirmed via change-setcdk diff.kms:*(Decrypt/DescribeKey + Encrypt/GenerateDataKey*/ReEncrypt* for writers) to the 5 in-stack consumer roles (4 pipeline Lambdas + SocketMode Fargate task role).Deploy-before-merge (done)
Deployed to prod 2026-06-09 and verified:
describe-table exec-aide→SSEType: KMS, key0b660af3…(alias/seahaven-dynamodb)scan --limit 1decrypts successfullyReview
Cross-reviewed for breaking changes (IAM/KMS). Key policy verified: statement 1 (
root: kms:*) delegates to IAM so the identity grants suffice; statement 2 (AllowDynamoDbSSEViaService+ CreateGrant) covers SSE activation. 4 peer tables already run on this key.Closes INFRA-95 (pending the slack-bot consumer-grant codification PR).