From 86f2ebb42dd1adca7e726fda894384839393482f Mon Sep 17 00:00:00 2001 From: Adam Moussa <166072409+amoussa1229@users.noreply.github.com> Date: Wed, 17 Jun 2026 17:23:06 -0400 Subject: [PATCH] Codify S3 Block Public Access on ingest buckets (#71) Add block_public_access=BlockPublicAccess.BLOCK_ALL to the po-ingest and workorder-ingest EmailBucket constructs. The buckets are already private at runtime via account-level and AWS-default BPA, so this is a no-op for behavior; it closes the codification gap that left CKV_AWS_53-56 firing on the synthesized templates and blocking the security pre-push gate (and the DLQ-alarm PRs that ride on it). --- cdk/po_stack.py | 1 + cdk/wo_stack.py | 1 + 2 files changed, 2 insertions(+) diff --git a/cdk/po_stack.py b/cdk/po_stack.py index 3e2036e..ee30ecc 100644 --- a/cdk/po_stack.py +++ b/cdk/po_stack.py @@ -97,6 +97,7 @@ class PoIngestStack(Stack): self, "EmailBucket", bucket_name=f"po-ingest-emails-{self.account}", + block_public_access=s3.BlockPublicAccess.BLOCK_ALL, removal_policy=RemovalPolicy.RETAIN, lifecycle_rules=[ s3.LifecycleRule(expiration=Duration.days(90)), diff --git a/cdk/wo_stack.py b/cdk/wo_stack.py index 8aa766d..637c0c2 100644 --- a/cdk/wo_stack.py +++ b/cdk/wo_stack.py @@ -96,6 +96,7 @@ class WorkorderIngestStack(Stack): self, "EmailBucket", bucket_name=f"workorder-ingest-emails-{self.account}", + block_public_access=s3.BlockPublicAccess.BLOCK_ALL, removal_policy=RemovalPolicy.RETAIN, lifecycle_rules=[ s3.LifecycleRule(expiration=Duration.days(90)),