mirror of
https://github.com/Sea-Haven-Industries/seahaven-org-baseline.git
synced 2026-09-30 05:43:17 +00:00
fix(scp): exempt chatbot:* from workloads-region-lock (global service, us-east-2 control plane) (#58)
AWS Chatbot's control-plane API is homed in us-east-2, so every chatbot call carries aws:RequestedRegion=us-east-2 and is denied by the workloads-region-lock region deny (approved set = us-east-1/us-west-2). This blocked Slack workspace/channel setup in seahaven-prod (chatbot:GetSlackOauthParameters denied), which the prod site-alerts topic needs for Slack delivery. Adds chatbot:* to the SCP's global-service NotAction exemption list alongside iam/organizations/cloudfront/route53 — a region-agnostic full-prefix exemption, the same shape as the other global services. targetIds unchanged (workloads OU); regional services (s3/kms/logs) and the Bedrock carve-out untouched. GPT-4.1 cross-review: SAFE TO MERGE. /sh-security-review: block=false (0 confirmed critical/high). Security-OU region-lock deliberately NOT changed (runs no such workloads, same asymmetry as its missing Bedrock carve-out).
This commit is contained in:
parent
4d3c846b88
commit
5d7ca83097
1 changed files with 11 additions and 1 deletions
|
|
@ -143,6 +143,16 @@ export class OrgGovernanceStack extends cdk.Stack {
|
|||
// are carved out of the general deny and re-denied only outside
|
||||
// {us-east-1, us-west-2, us-east-2} so cross-region inference profiles
|
||||
// (us.anthropic.*) that route to us-east-2 are not blocked.
|
||||
// chatbot:* is exempted because AWS Chatbot ("Amazon Q Developer in chat
|
||||
// applications") is a global management service: the console setup flow
|
||||
// hits its control plane in us-east-2 (observed deny:
|
||||
// chatbot:GetSlackOauthParameters at aws:RequestedRegion=us-east-2), which
|
||||
// is outside the approved region set, so without this exemption the region
|
||||
// deny blocks Slack workspace/channel setup for site-alerts → Slack. A
|
||||
// full-prefix NotAction (region-agnostic, like iam:*/cloudfront:*) is the
|
||||
// right shape: it names a global management service, not a workload running
|
||||
// in an unapproved region. The notification-side resources (the site-alerts
|
||||
// SNS topic, alarms) stay in us-east-1 and remain region-locked.
|
||||
const workloadsRegionLock = new organizations.CfnPolicy(this, "WorkloadsRegionLock", {
|
||||
name: "workloads-region-lock",
|
||||
type: "SERVICE_CONTROL_POLICY",
|
||||
|
|
@ -160,7 +170,7 @@ export class OrgGovernanceStack extends cdk.Stack {
|
|||
"route53domains:*", "cloudfront:*", "waf:*", "shield:*",
|
||||
"globalaccelerator:*", "budgets:*", "ce:*", "cur:*", "health:*",
|
||||
"support:*", "supportplans:*", "trustedadvisor:*", "artifact:*",
|
||||
"aws-portal:*",
|
||||
"aws-portal:*", "chatbot:*",
|
||||
...BEDROCK_INVOKE_ACTIONS,
|
||||
],
|
||||
Resource: "*",
|
||||
|
|
|
|||
Loading…
Add table
Reference in a new issue