Remove gratuitous KMS grant on shared DynamoDB CMK

wo-email-processor held grant_encrypt_decrypt on the shared
seahaven-dynamodb CMK, but the WorkOrders/WorkOrderComments tables
are not encrypted with that CMK. The grant was dead weight that
extended the WO processor's decrypt reach to the CMK protecting the
purchase-orders table (cross-stack decrypt). Drop it to restore
least privilege; re-add as part of the table CMK migration (INFRA-6).

Refs: INFRA-6
This commit is contained in:
Adam Moussa 2026-06-17 11:37:03 -04:00
parent cab4a035ed
commit 31d5f5d432

View file

@ -8,7 +8,6 @@ from aws_cdk import (
aws_cloudwatch as cloudwatch, aws_cloudwatch as cloudwatch,
aws_cloudwatch_actions as cw_actions, aws_cloudwatch_actions as cw_actions,
aws_dynamodb as dynamodb, aws_dynamodb as dynamodb,
aws_kms as kms,
aws_lambda as lambda_, aws_lambda as lambda_,
aws_logs as logs, aws_logs as logs,
aws_s3 as s3, aws_s3 as s3,
@ -129,21 +128,15 @@ class WorkorderIngestStack(Stack):
comments_table.grant_read_write_data(email_processor) comments_table.grant_read_write_data(email_processor)
anthropic_secret.grant_read(email_processor) anthropic_secret.grant_read(email_processor)
# Pre-emptive KMS grant on the shared DynamoDB CMK (alias/seahaven-dynamodb, # NOTE: The pre-emptive grant_encrypt_decrypt on the shared DynamoDB CMK
# /seahaven/dynamodb/cmk-arn). The WorkOrders/WorkOrderComments tables are # (alias/seahaven-dynamodb) was removed (security sweep 2026-06-17). The
# NOT yet SSE-KMS encrypted, so this grant is currently unused; it is added # WorkOrders/WorkOrderComments tables are NOT SSE-KMS encrypted with that
# ahead of the CMK migration so the processor role does not hit AccessDenied # CMK, so the grant was unused for these tables yet handed
# the moment those tables are migrated. The actual table migration + kebab # wo-email-processor kms:Decrypt on the CMK that also protects the
# rename is tracked in INFRA-6 (and the set-aside wo_stack CMK WIP); fold the # purchase-orders table (cross-stack decrypt reach). Re-add this grant only
# web-ui read grant in there. # as part of the actual CMK migration of these tables (INFRA-6), at which
dynamodb_cmk = kms.Key.from_key_arn( # point grant_read_write_data on the (then encrypted) tables would propagate
self, # the needed key permissions automatically.
"DynamoDbCmk",
ssm.StringParameter.value_for_string_parameter(
self, "/seahaven/dynamodb/cmk-arn"
),
)
dynamodb_cmk.grant_encrypt_decrypt(email_processor)
# --- Errors alarm (INFRA-41 / audit H-8) --- # --- Errors alarm (INFRA-41 / audit H-8) ---
# ALARM-only (no OK action, per the CloudWatch-alarm preference) to the # ALARM-only (no OK action, per the CloudWatch-alarm preference) to the