mirror of
https://github.com/Sea-Haven-Industries/procurement-ingest.git
synced 2026-10-03 03:23:11 +00:00
Remove gratuitous KMS grant on shared DynamoDB CMK
wo-email-processor held grant_encrypt_decrypt on the shared seahaven-dynamodb CMK, but the WorkOrders/WorkOrderComments tables are not encrypted with that CMK. The grant was dead weight that extended the WO processor's decrypt reach to the CMK protecting the purchase-orders table (cross-stack decrypt). Drop it to restore least privilege; re-add as part of the table CMK migration (INFRA-6). Refs: INFRA-6
This commit is contained in:
parent
cab4a035ed
commit
31d5f5d432
1 changed files with 9 additions and 16 deletions
|
|
@ -8,7 +8,6 @@ from aws_cdk import (
|
||||||
aws_cloudwatch as cloudwatch,
|
aws_cloudwatch as cloudwatch,
|
||||||
aws_cloudwatch_actions as cw_actions,
|
aws_cloudwatch_actions as cw_actions,
|
||||||
aws_dynamodb as dynamodb,
|
aws_dynamodb as dynamodb,
|
||||||
aws_kms as kms,
|
|
||||||
aws_lambda as lambda_,
|
aws_lambda as lambda_,
|
||||||
aws_logs as logs,
|
aws_logs as logs,
|
||||||
aws_s3 as s3,
|
aws_s3 as s3,
|
||||||
|
|
@ -129,21 +128,15 @@ class WorkorderIngestStack(Stack):
|
||||||
comments_table.grant_read_write_data(email_processor)
|
comments_table.grant_read_write_data(email_processor)
|
||||||
anthropic_secret.grant_read(email_processor)
|
anthropic_secret.grant_read(email_processor)
|
||||||
|
|
||||||
# Pre-emptive KMS grant on the shared DynamoDB CMK (alias/seahaven-dynamodb,
|
# NOTE: The pre-emptive grant_encrypt_decrypt on the shared DynamoDB CMK
|
||||||
# /seahaven/dynamodb/cmk-arn). The WorkOrders/WorkOrderComments tables are
|
# (alias/seahaven-dynamodb) was removed (security sweep 2026-06-17). The
|
||||||
# NOT yet SSE-KMS encrypted, so this grant is currently unused; it is added
|
# WorkOrders/WorkOrderComments tables are NOT SSE-KMS encrypted with that
|
||||||
# ahead of the CMK migration so the processor role does not hit AccessDenied
|
# CMK, so the grant was unused for these tables yet handed
|
||||||
# the moment those tables are migrated. The actual table migration + kebab
|
# wo-email-processor kms:Decrypt on the CMK that also protects the
|
||||||
# rename is tracked in INFRA-6 (and the set-aside wo_stack CMK WIP); fold the
|
# purchase-orders table (cross-stack decrypt reach). Re-add this grant only
|
||||||
# web-ui read grant in there.
|
# as part of the actual CMK migration of these tables (INFRA-6), at which
|
||||||
dynamodb_cmk = kms.Key.from_key_arn(
|
# point grant_read_write_data on the (then encrypted) tables would propagate
|
||||||
self,
|
# the needed key permissions automatically.
|
||||||
"DynamoDbCmk",
|
|
||||||
ssm.StringParameter.value_for_string_parameter(
|
|
||||||
self, "/seahaven/dynamodb/cmk-arn"
|
|
||||||
),
|
|
||||||
)
|
|
||||||
dynamodb_cmk.grant_encrypt_decrypt(email_processor)
|
|
||||||
|
|
||||||
# --- Errors alarm (INFRA-41 / audit H-8) ---
|
# --- Errors alarm (INFRA-41 / audit H-8) ---
|
||||||
# ALARM-only (no OK action, per the CloudWatch-alarm preference) to the
|
# ALARM-only (no OK action, per the CloudWatch-alarm preference) to the
|
||||||
|
|
|
||||||
Loading…
Add table
Reference in a new issue