fix(scp): exempt chatbot:* from workloads-region-lock (global service, us-east-2 control plane) (#58)
Some checks are pending
Deploy / deploy-management (push) Waiting to run
Deploy / deploy-external-dev (push) Waiting to run
Deploy / deploy-security (push) Waiting to run
Deploy / deploy-dev (push) Waiting to run
Deploy / deploy-prod (push) Waiting to run

AWS Chatbot's control-plane API is homed in us-east-2, so every chatbot call
carries aws:RequestedRegion=us-east-2 and is denied by the workloads-region-lock
region deny (approved set = us-east-1/us-west-2). This blocked Slack
workspace/channel setup in seahaven-prod (chatbot:GetSlackOauthParameters
denied), which the prod site-alerts topic needs for Slack delivery. Adds
chatbot:* to the SCP's global-service NotAction exemption list alongside
iam/organizations/cloudfront/route53 — a region-agnostic full-prefix exemption,
the same shape as the other global services. targetIds unchanged (workloads OU);
regional services (s3/kms/logs) and the Bedrock carve-out untouched.

GPT-4.1 cross-review: SAFE TO MERGE. /sh-security-review: block=false (0 confirmed
critical/high). Security-OU region-lock deliberately NOT changed (runs no such
workloads, same asymmetry as its missing Bedrock carve-out).
This commit is contained in:
Adam Moussa 2026-07-23 15:47:11 -04:00 • committed by GitHub
parent 4d3c846b88
commit 5d7ca83097
No known key found for this signature in database
GPG key ID: B5690EEEBB952194

View file

@ -143,6 +143,16 @@ export class OrgGovernanceStack extends cdk.Stack {
// are carved out of the general deny and re-denied only outside
// {us-east-1, us-west-2, us-east-2} so cross-region inference profiles
// (us.anthropic.*) that route to us-east-2 are not blocked.
// chatbot:* is exempted because AWS Chatbot ("Amazon Q Developer in chat
// applications") is a global management service: the console setup flow
// hits its control plane in us-east-2 (observed deny:
// chatbot:GetSlackOauthParameters at aws:RequestedRegion=us-east-2), which
// is outside the approved region set, so without this exemption the region
// deny blocks Slack workspace/channel setup for site-alerts → Slack. A
// full-prefix NotAction (region-agnostic, like iam:*/cloudfront:*) is the
// right shape: it names a global management service, not a workload running
// in an unapproved region. The notification-side resources (the site-alerts
// SNS topic, alarms) stay in us-east-1 and remain region-locked.
const workloadsRegionLock = new organizations.CfnPolicy(this, "WorkloadsRegionLock", {
name: "workloads-region-lock",
type: "SERVICE_CONTROL_POLICY",
@ -160,7 +170,7 @@ export class OrgGovernanceStack extends cdk.Stack {
"route53domains:*", "cloudfront:*", "waf:*", "shield:*",
"globalaccelerator:*", "budgets:*", "ce:*", "cur:*", "health:*",
"support:*", "supportplans:*", "trustedadvisor:*", "artifact:*",
"aws-portal:*",
"aws-portal:*", "chatbot:*",
...BEDROCK_INVOKE_ACTIONS,
],
Resource: "*",