From 5fc749bc0e7a8a6ae3b740410c2ab8080fb03629 Mon Sep 17 00:00:00 2001 From: Adam Moussa Date: Mon, 6 Jul 2026 18:09:19 -0400 Subject: [PATCH] refactor(cdk): encrypt migrated log groups with seahaven-logs CMK (INFRA-114) --- cdk/po_stack.py | 15 +++++++++++++++ cdk/wo_stack.py | 13 +++++++++++++ 2 files changed, 28 insertions(+) diff --git a/cdk/po_stack.py b/cdk/po_stack.py index 787ce07..7771250 100644 --- a/cdk/po_stack.py +++ b/cdk/po_stack.py @@ -118,6 +118,18 @@ class PoIngestStack(Stack): ), ) + # --- Shared customer-managed CMK for CloudWatch log encryption --- + # alias/seahaven-logs. The po-email-processor log group was already + # associated with this CMK out-of-band; declaring encryption_key on the + # migrated LogGroups below reconciles that drift and hardens the remaining + # groups (INFRA-114, per cross-review). The key policy already permits + # logs.us-east-1.amazonaws.com (verified in use on po-email-processor). + logs_cmk = kms.Key.from_key_arn( + self, + "LogsKey", + "arn:aws:kms:us-east-1:328440206208:key/b748750c-3b26-478d-acfb-d0126cc97f56", + ) + # --- Purchase-orders DynamoDB table --- # Owned by this stack. Streams enabled for the site-extractor pipeline. # Other stacks (seahaven-slack-bot) reference this table via fromTableName(). @@ -169,6 +181,7 @@ class PoIngestStack(Stack): "EmailProcessorLogGroup", log_group_name="/aws/lambda/po-email-processor", retention=logs.RetentionDays.TWO_MONTHS, + encryption_key=logs_cmk, removal_policy=RemovalPolicy.RETAIN, ) @@ -317,6 +330,7 @@ class PoIngestStack(Stack): "WebUILogGroup", log_group_name="/aws/lambda/po-web-ui", retention=logs.RetentionDays.TWO_MONTHS, + encryption_key=logs_cmk, removal_policy=RemovalPolicy.RETAIN, ) @@ -397,6 +411,7 @@ class PoIngestStack(Stack): "SiteExtractorLogGroup", log_group_name="/aws/lambda/po-ingest-site-extractor", retention=logs.RetentionDays.TWO_MONTHS, + encryption_key=logs_cmk, removal_policy=RemovalPolicy.RETAIN, ) diff --git a/cdk/wo_stack.py b/cdk/wo_stack.py index e1cb926..761967a 100644 --- a/cdk/wo_stack.py +++ b/cdk/wo_stack.py @@ -156,6 +156,17 @@ class WorkorderIngestStack(Stack): enforce_ssl=True, ) + # --- Shared customer-managed CMK for CloudWatch log encryption --- + # alias/seahaven-logs. Same CMK the po-email-processor log group was + # already associated with out-of-band; declaring encryption_key on the + # migrated LogGroups below hardens these groups (INFRA-114, per + # cross-review). The key policy already permits logs.us-east-1.amazonaws.com. + logs_cmk = kms.Key.from_key_arn( + self, + "LogsKey", + "arn:aws:kms:us-east-1:328440206208:key/b748750c-3b26-478d-acfb-d0126cc97f56", + ) + # --- Explicit log group (INFRA-114) --- # Replaces the deprecated log_retention prop, which provisioned a # LogRetention custom resource whose role held logs:PutRetentionPolicy/ @@ -168,6 +179,7 @@ class WorkorderIngestStack(Stack): "EmailProcessorLogGroup", log_group_name="/aws/lambda/workorder-email-processor", retention=logs.RetentionDays.TWO_MONTHS, + encryption_key=logs_cmk, removal_policy=RemovalPolicy.RETAIN, ) @@ -331,6 +343,7 @@ class WorkorderIngestStack(Stack): "WebUILogGroup", log_group_name="/aws/lambda/workorder-web-ui", retention=logs.RetentionDays.TWO_MONTHS, + encryption_key=logs_cmk, removal_policy=RemovalPolicy.RETAIN, )