feat(slack-bot): codify kms:Decrypt grants for CMK'd DynamoDB readers (INFRA-95) #51
No reviewers
Labels
No labels
app
bug
ci
compliance
dependencies
docker
docs
documentation
duplicate
enhancement
good first issue
help wanted
infra
invalid
javascript
question
wontfix
No milestone
No project
No assignees
1 participant
Due date
No due date set.
Dependencies
No dependencies set.
Reference: adam/seahaven-slack-bot#51
Loading…
Add table
Reference in a new issue
No description provided.
Delete branch "infra-95-slackbot-cmk-grants"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Summary
Codifies the
kms:Decryptgrant that the three DynamoDB readers need now that their tables (WorkOrders,WorkOrderComments,purchase-orders,PaymentsDashboard) are SSE-encrypted withalias/seahaven-dynamodb(INFRA-95 / M-3):wo-po-lookup,po-sync,workorder-sync— tables are imported by name, sograntReadDataadds no KMS perms;dynamodbCmk.grantDecrypt(fn)grantskms:Decryptexplicitly (CMK imported via SSM/seahaven/dynamodb/cmk-arn).Replaces the interim CLI inline policy (
Sid Infra95DynamoDbCmkDecrypt) currently on those three roles with IaC.Review
Cross-reviewed (IAM/KMS) → APPROVE.
grantDecrypt(kms:Decrypt+kms:ReEncryptFrom) is sufficient for reads; key policy'sroot: kms:*makes the identity grant work. No construct-ID collision (separate construct scopes).cdk diffAdds
kms:Decryptto the 3 reader role DefaultPolicies + an SSM parameter ref. (The SocketMode container / OpenSearch-CR lines in a local diff are local-vs-CI Docker asset-hash artifacts — CI rebuilds arm64; no real code change.)Deploy
Deploys via the
deploy.yamlpipeline on merge (arm64 build). Do not hand-deploy locally (x86 image → exec format error on the listener). Post-merge: verify the CDK grant is live, then delete the interim inline policies.Part of INFRA-95.