seahaven-account-baseline/bin
Adam Moussa 313df882ba
refactor(prod): drop cross-account CMK grant (slack-bot decommissioned 2026-07-23)
The AllowMgmtSlackBotReadViaDynamoDb key-policy statement targeted the
seahaven-slack-bot roles, which were decommissioned 2026-07-23. Its successor
sh-mcp is undeployed and uses same-account DynamoDB access, so no cross-account
reader of the CMK-encrypted purchase-orders table exists. The prod CMK + SSM
param + alarm-topic stacks remain (procurement-ingest still imports them). Add
a scoped cross-account grant if/when a real cross-account consumer deploys.
2026-07-23 15:10:12 -04:00
..
app.ts refactor(prod): drop cross-account CMK grant (slack-bot decommissioned 2026-07-23) 2026-07-23 15:10:12 -04:00