refactor(cdk): encrypt migrated log groups with seahaven-logs CMK (INFRA-114)

This commit is contained in:
Adam Moussa 2026-07-06 18:09:19 -04:00
parent 62a3a7f0be
commit 5fc749bc0e
No known key found for this signature in database
2 changed files with 28 additions and 0 deletions

View file

@ -118,6 +118,18 @@ class PoIngestStack(Stack):
),
)
# --- Shared customer-managed CMK for CloudWatch log encryption ---
# alias/seahaven-logs. The po-email-processor log group was already
# associated with this CMK out-of-band; declaring encryption_key on the
# migrated LogGroups below reconciles that drift and hardens the remaining
# groups (INFRA-114, per cross-review). The key policy already permits
# logs.us-east-1.amazonaws.com (verified in use on po-email-processor).
logs_cmk = kms.Key.from_key_arn(
self,
"LogsKey",
"arn:aws:kms:us-east-1:328440206208:key/b748750c-3b26-478d-acfb-d0126cc97f56",
)
# --- Purchase-orders DynamoDB table ---
# Owned by this stack. Streams enabled for the site-extractor pipeline.
# Other stacks (seahaven-slack-bot) reference this table via fromTableName().
@ -169,6 +181,7 @@ class PoIngestStack(Stack):
"EmailProcessorLogGroup",
log_group_name="/aws/lambda/po-email-processor",
retention=logs.RetentionDays.TWO_MONTHS,
encryption_key=logs_cmk,
removal_policy=RemovalPolicy.RETAIN,
)
@ -317,6 +330,7 @@ class PoIngestStack(Stack):
"WebUILogGroup",
log_group_name="/aws/lambda/po-web-ui",
retention=logs.RetentionDays.TWO_MONTHS,
encryption_key=logs_cmk,
removal_policy=RemovalPolicy.RETAIN,
)
@ -397,6 +411,7 @@ class PoIngestStack(Stack):
"SiteExtractorLogGroup",
log_group_name="/aws/lambda/po-ingest-site-extractor",
retention=logs.RetentionDays.TWO_MONTHS,
encryption_key=logs_cmk,
removal_policy=RemovalPolicy.RETAIN,
)

View file

@ -156,6 +156,17 @@ class WorkorderIngestStack(Stack):
enforce_ssl=True,
)
# --- Shared customer-managed CMK for CloudWatch log encryption ---
# alias/seahaven-logs. Same CMK the po-email-processor log group was
# already associated with out-of-band; declaring encryption_key on the
# migrated LogGroups below hardens these groups (INFRA-114, per
# cross-review). The key policy already permits logs.us-east-1.amazonaws.com.
logs_cmk = kms.Key.from_key_arn(
self,
"LogsKey",
"arn:aws:kms:us-east-1:328440206208:key/b748750c-3b26-478d-acfb-d0126cc97f56",
)
# --- Explicit log group (INFRA-114) ---
# Replaces the deprecated log_retention prop, which provisioned a
# LogRetention custom resource whose role held logs:PutRetentionPolicy/
@ -168,6 +179,7 @@ class WorkorderIngestStack(Stack):
"EmailProcessorLogGroup",
log_group_name="/aws/lambda/workorder-email-processor",
retention=logs.RetentionDays.TWO_MONTHS,
encryption_key=logs_cmk,
removal_policy=RemovalPolicy.RETAIN,
)
@ -331,6 +343,7 @@ class WorkorderIngestStack(Stack):
"WebUILogGroup",
log_group_name="/aws/lambda/workorder-web-ui",
retention=logs.RetentionDays.TWO_MONTHS,
encryption_key=logs_cmk,
removal_policy=RemovalPolicy.RETAIN,
)