Codify S3 Block Public Access on ingest buckets (#71)

Add block_public_access=BlockPublicAccess.BLOCK_ALL to the po-ingest and
workorder-ingest EmailBucket constructs. The buckets are already private
at runtime via account-level and AWS-default BPA, so this is a no-op for
behavior; it closes the codification gap that left CKV_AWS_53-56 firing
on the synthesized templates and blocking the security pre-push gate
(and the DLQ-alarm PRs that ride on it).
This commit is contained in:
Adam Moussa 2026-06-17 17:23:06 -04:00 • committed by GitHub
parent 0fdf407e1d
commit 86f2ebb42d
No known key found for this signature in database
GPG key ID: B5690EEEBB952194
2 changed files with 2 additions and 0 deletions

View file

@ -97,6 +97,7 @@ class PoIngestStack(Stack):
self,
"EmailBucket",
bucket_name=f"po-ingest-emails-{self.account}",
block_public_access=s3.BlockPublicAccess.BLOCK_ALL,
removal_policy=RemovalPolicy.RETAIN,
lifecycle_rules=[
s3.LifecycleRule(expiration=Duration.days(90)),

View file

@ -96,6 +96,7 @@ class WorkorderIngestStack(Stack):
self,
"EmailBucket",
bucket_name=f"workorder-ingest-emails-{self.account}",
block_public_access=s3.BlockPublicAccess.BLOCK_ALL,
removal_policy=RemovalPolicy.RETAIN,
lifecycle_rules=[
s3.LifecycleRule(expiration=Duration.days(90)),