mirror of
https://github.com/Sea-Haven-Industries/procurement-ingest.git
synced 2026-09-30 04:53:12 +00:00
refactor(cdk): encrypt migrated log groups with seahaven-logs CMK (INFRA-114)
This commit is contained in:
parent
62a3a7f0be
commit
5fc749bc0e
2 changed files with 28 additions and 0 deletions
|
|
@ -118,6 +118,18 @@ class PoIngestStack(Stack):
|
||||||
),
|
),
|
||||||
)
|
)
|
||||||
|
|
||||||
|
# --- Shared customer-managed CMK for CloudWatch log encryption ---
|
||||||
|
# alias/seahaven-logs. The po-email-processor log group was already
|
||||||
|
# associated with this CMK out-of-band; declaring encryption_key on the
|
||||||
|
# migrated LogGroups below reconciles that drift and hardens the remaining
|
||||||
|
# groups (INFRA-114, per cross-review). The key policy already permits
|
||||||
|
# logs.us-east-1.amazonaws.com (verified in use on po-email-processor).
|
||||||
|
logs_cmk = kms.Key.from_key_arn(
|
||||||
|
self,
|
||||||
|
"LogsKey",
|
||||||
|
"arn:aws:kms:us-east-1:328440206208:key/b748750c-3b26-478d-acfb-d0126cc97f56",
|
||||||
|
)
|
||||||
|
|
||||||
# --- Purchase-orders DynamoDB table ---
|
# --- Purchase-orders DynamoDB table ---
|
||||||
# Owned by this stack. Streams enabled for the site-extractor pipeline.
|
# Owned by this stack. Streams enabled for the site-extractor pipeline.
|
||||||
# Other stacks (seahaven-slack-bot) reference this table via fromTableName().
|
# Other stacks (seahaven-slack-bot) reference this table via fromTableName().
|
||||||
|
|
@ -169,6 +181,7 @@ class PoIngestStack(Stack):
|
||||||
"EmailProcessorLogGroup",
|
"EmailProcessorLogGroup",
|
||||||
log_group_name="/aws/lambda/po-email-processor",
|
log_group_name="/aws/lambda/po-email-processor",
|
||||||
retention=logs.RetentionDays.TWO_MONTHS,
|
retention=logs.RetentionDays.TWO_MONTHS,
|
||||||
|
encryption_key=logs_cmk,
|
||||||
removal_policy=RemovalPolicy.RETAIN,
|
removal_policy=RemovalPolicy.RETAIN,
|
||||||
)
|
)
|
||||||
|
|
||||||
|
|
@ -317,6 +330,7 @@ class PoIngestStack(Stack):
|
||||||
"WebUILogGroup",
|
"WebUILogGroup",
|
||||||
log_group_name="/aws/lambda/po-web-ui",
|
log_group_name="/aws/lambda/po-web-ui",
|
||||||
retention=logs.RetentionDays.TWO_MONTHS,
|
retention=logs.RetentionDays.TWO_MONTHS,
|
||||||
|
encryption_key=logs_cmk,
|
||||||
removal_policy=RemovalPolicy.RETAIN,
|
removal_policy=RemovalPolicy.RETAIN,
|
||||||
)
|
)
|
||||||
|
|
||||||
|
|
@ -397,6 +411,7 @@ class PoIngestStack(Stack):
|
||||||
"SiteExtractorLogGroup",
|
"SiteExtractorLogGroup",
|
||||||
log_group_name="/aws/lambda/po-ingest-site-extractor",
|
log_group_name="/aws/lambda/po-ingest-site-extractor",
|
||||||
retention=logs.RetentionDays.TWO_MONTHS,
|
retention=logs.RetentionDays.TWO_MONTHS,
|
||||||
|
encryption_key=logs_cmk,
|
||||||
removal_policy=RemovalPolicy.RETAIN,
|
removal_policy=RemovalPolicy.RETAIN,
|
||||||
)
|
)
|
||||||
|
|
||||||
|
|
|
||||||
|
|
@ -156,6 +156,17 @@ class WorkorderIngestStack(Stack):
|
||||||
enforce_ssl=True,
|
enforce_ssl=True,
|
||||||
)
|
)
|
||||||
|
|
||||||
|
# --- Shared customer-managed CMK for CloudWatch log encryption ---
|
||||||
|
# alias/seahaven-logs. Same CMK the po-email-processor log group was
|
||||||
|
# already associated with out-of-band; declaring encryption_key on the
|
||||||
|
# migrated LogGroups below hardens these groups (INFRA-114, per
|
||||||
|
# cross-review). The key policy already permits logs.us-east-1.amazonaws.com.
|
||||||
|
logs_cmk = kms.Key.from_key_arn(
|
||||||
|
self,
|
||||||
|
"LogsKey",
|
||||||
|
"arn:aws:kms:us-east-1:328440206208:key/b748750c-3b26-478d-acfb-d0126cc97f56",
|
||||||
|
)
|
||||||
|
|
||||||
# --- Explicit log group (INFRA-114) ---
|
# --- Explicit log group (INFRA-114) ---
|
||||||
# Replaces the deprecated log_retention prop, which provisioned a
|
# Replaces the deprecated log_retention prop, which provisioned a
|
||||||
# LogRetention custom resource whose role held logs:PutRetentionPolicy/
|
# LogRetention custom resource whose role held logs:PutRetentionPolicy/
|
||||||
|
|
@ -168,6 +179,7 @@ class WorkorderIngestStack(Stack):
|
||||||
"EmailProcessorLogGroup",
|
"EmailProcessorLogGroup",
|
||||||
log_group_name="/aws/lambda/workorder-email-processor",
|
log_group_name="/aws/lambda/workorder-email-processor",
|
||||||
retention=logs.RetentionDays.TWO_MONTHS,
|
retention=logs.RetentionDays.TWO_MONTHS,
|
||||||
|
encryption_key=logs_cmk,
|
||||||
removal_policy=RemovalPolicy.RETAIN,
|
removal_policy=RemovalPolicy.RETAIN,
|
||||||
)
|
)
|
||||||
|
|
||||||
|
|
@ -331,6 +343,7 @@ class WorkorderIngestStack(Stack):
|
||||||
"WebUILogGroup",
|
"WebUILogGroup",
|
||||||
log_group_name="/aws/lambda/workorder-web-ui",
|
log_group_name="/aws/lambda/workorder-web-ui",
|
||||||
retention=logs.RetentionDays.TWO_MONTHS,
|
retention=logs.RetentionDays.TWO_MONTHS,
|
||||||
|
encryption_key=logs_cmk,
|
||||||
removal_policy=RemovalPolicy.RETAIN,
|
removal_policy=RemovalPolicy.RETAIN,
|
||||||
)
|
)
|
||||||
|
|
||||||
|
|
|
||||||
Loading…
Add table
Reference in a new issue