From 5d7ca830978538b1d5246e1fa33c630ca523125f Mon Sep 17 00:00:00 2001 From: Adam Moussa <166072409+amoussa1229@users.noreply.github.com> Date: Thu, 23 Jul 2026 15:47:11 -0400 Subject: [PATCH] fix(scp): exempt chatbot:* from workloads-region-lock (global service, us-east-2 control plane) (#58) MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit AWS Chatbot's control-plane API is homed in us-east-2, so every chatbot call carries aws:RequestedRegion=us-east-2 and is denied by the workloads-region-lock region deny (approved set = us-east-1/us-west-2). This blocked Slack workspace/channel setup in seahaven-prod (chatbot:GetSlackOauthParameters denied), which the prod site-alerts topic needs for Slack delivery. Adds chatbot:* to the SCP's global-service NotAction exemption list alongside iam/organizations/cloudfront/route53 — a region-agnostic full-prefix exemption, the same shape as the other global services. targetIds unchanged (workloads OU); regional services (s3/kms/logs) and the Bedrock carve-out untouched. GPT-4.1 cross-review: SAFE TO MERGE. /sh-security-review: block=false (0 confirmed critical/high). Security-OU region-lock deliberately NOT changed (runs no such workloads, same asymmetry as its missing Bedrock carve-out). --- lib/org-governance-stack.ts | 12 +++++++++++- 1 file changed, 11 insertions(+), 1 deletion(-) diff --git a/lib/org-governance-stack.ts b/lib/org-governance-stack.ts index a6faf3a..a2ed2c2 100644 --- a/lib/org-governance-stack.ts +++ b/lib/org-governance-stack.ts @@ -143,6 +143,16 @@ export class OrgGovernanceStack extends cdk.Stack { // are carved out of the general deny and re-denied only outside // {us-east-1, us-west-2, us-east-2} so cross-region inference profiles // (us.anthropic.*) that route to us-east-2 are not blocked. + // chatbot:* is exempted because AWS Chatbot ("Amazon Q Developer in chat + // applications") is a global management service: the console setup flow + // hits its control plane in us-east-2 (observed deny: + // chatbot:GetSlackOauthParameters at aws:RequestedRegion=us-east-2), which + // is outside the approved region set, so without this exemption the region + // deny blocks Slack workspace/channel setup for site-alerts → Slack. A + // full-prefix NotAction (region-agnostic, like iam:*/cloudfront:*) is the + // right shape: it names a global management service, not a workload running + // in an unapproved region. The notification-side resources (the site-alerts + // SNS topic, alarms) stay in us-east-1 and remain region-locked. const workloadsRegionLock = new organizations.CfnPolicy(this, "WorkloadsRegionLock", { name: "workloads-region-lock", type: "SERVICE_CONTROL_POLICY", @@ -160,7 +170,7 @@ export class OrgGovernanceStack extends cdk.Stack { "route53domains:*", "cloudfront:*", "waf:*", "shield:*", "globalaccelerator:*", "budgets:*", "ce:*", "cur:*", "health:*", "support:*", "supportplans:*", "trustedadvisor:*", "artifact:*", - "aws-portal:*", + "aws-portal:*", "chatbot:*", ...BEDROCK_INVOKE_ACTIONS, ], Resource: "*",