diff --git a/cdk/wo_stack.py b/cdk/wo_stack.py index c26313c..acedb1a 100644 --- a/cdk/wo_stack.py +++ b/cdk/wo_stack.py @@ -8,7 +8,6 @@ from aws_cdk import ( aws_cloudwatch as cloudwatch, aws_cloudwatch_actions as cw_actions, aws_dynamodb as dynamodb, - aws_kms as kms, aws_lambda as lambda_, aws_logs as logs, aws_s3 as s3, @@ -129,21 +128,15 @@ class WorkorderIngestStack(Stack): comments_table.grant_read_write_data(email_processor) anthropic_secret.grant_read(email_processor) - # Pre-emptive KMS grant on the shared DynamoDB CMK (alias/seahaven-dynamodb, - # /seahaven/dynamodb/cmk-arn). The WorkOrders/WorkOrderComments tables are - # NOT yet SSE-KMS encrypted, so this grant is currently unused; it is added - # ahead of the CMK migration so the processor role does not hit AccessDenied - # the moment those tables are migrated. The actual table migration + kebab - # rename is tracked in INFRA-6 (and the set-aside wo_stack CMK WIP); fold the - # web-ui read grant in there. - dynamodb_cmk = kms.Key.from_key_arn( - self, - "DynamoDbCmk", - ssm.StringParameter.value_for_string_parameter( - self, "/seahaven/dynamodb/cmk-arn" - ), - ) - dynamodb_cmk.grant_encrypt_decrypt(email_processor) + # NOTE: The pre-emptive grant_encrypt_decrypt on the shared DynamoDB CMK + # (alias/seahaven-dynamodb) was removed (security sweep 2026-06-17). The + # WorkOrders/WorkOrderComments tables are NOT SSE-KMS encrypted with that + # CMK, so the grant was unused for these tables yet handed + # wo-email-processor kms:Decrypt on the CMK that also protects the + # purchase-orders table (cross-stack decrypt reach). Re-add this grant only + # as part of the actual CMK migration of these tables (INFRA-6), at which + # point grant_read_write_data on the (then encrypted) tables would propagate + # the needed key permissions automatically. # --- Errors alarm (INFRA-41 / audit H-8) --- # ALARM-only (no OK action, per the CloudWatch-alarm preference) to the