Remove gratuitous KMS grant on shared DynamoDB CMK

wo-email-processor held grant_encrypt_decrypt on the shared
seahaven-dynamodb CMK, but the WorkOrders/WorkOrderComments tables
are not encrypted with that CMK. The grant was dead weight that
extended the WO processor's decrypt reach to the CMK protecting the
purchase-orders table (cross-stack decrypt). Drop it to restore
least privilege; re-add as part of the table CMK migration (INFRA-6).

Refs: INFRA-6
This commit is contained in:
Adam Moussa 2026-06-17 11:37:03 -04:00
parent cab4a035ed
commit 31d5f5d432

View file

@ -8,7 +8,6 @@ from aws_cdk import (
aws_cloudwatch as cloudwatch,
aws_cloudwatch_actions as cw_actions,
aws_dynamodb as dynamodb,
aws_kms as kms,
aws_lambda as lambda_,
aws_logs as logs,
aws_s3 as s3,
@ -129,21 +128,15 @@ class WorkorderIngestStack(Stack):
comments_table.grant_read_write_data(email_processor)
anthropic_secret.grant_read(email_processor)
# Pre-emptive KMS grant on the shared DynamoDB CMK (alias/seahaven-dynamodb,
# /seahaven/dynamodb/cmk-arn). The WorkOrders/WorkOrderComments tables are
# NOT yet SSE-KMS encrypted, so this grant is currently unused; it is added
# ahead of the CMK migration so the processor role does not hit AccessDenied
# the moment those tables are migrated. The actual table migration + kebab
# rename is tracked in INFRA-6 (and the set-aside wo_stack CMK WIP); fold the
# web-ui read grant in there.
dynamodb_cmk = kms.Key.from_key_arn(
self,
"DynamoDbCmk",
ssm.StringParameter.value_for_string_parameter(
self, "/seahaven/dynamodb/cmk-arn"
),
)
dynamodb_cmk.grant_encrypt_decrypt(email_processor)
# NOTE: The pre-emptive grant_encrypt_decrypt on the shared DynamoDB CMK
# (alias/seahaven-dynamodb) was removed (security sweep 2026-06-17). The
# WorkOrders/WorkOrderComments tables are NOT SSE-KMS encrypted with that
# CMK, so the grant was unused for these tables yet handed
# wo-email-processor kms:Decrypt on the CMK that also protects the
# purchase-orders table (cross-stack decrypt reach). Re-add this grant only
# as part of the actual CMK migration of these tables (INFRA-6), at which
# point grant_read_write_data on the (then encrypted) tables would propagate
# the needed key permissions automatically.
# --- Errors alarm (INFRA-41 / audit H-8) ---
# ALARM-only (no OK action, per the CloudWatch-alarm preference) to the