feat(slack-bot): codify kms:Decrypt grants for CMK'd DynamoDB readers (INFRA-95) #51

Merged
amoussa1229 merged 2 commits from infra-95-slackbot-cmk-grants into main 2026-06-09 16:33:07 +00:00
amoussa1229 commented 2026-06-09 16:21:42 +00:00 (Migrated from github.com)

Summary

Codifies the kms:Decrypt grant that the three DynamoDB readers need now that their tables (WorkOrders, WorkOrderComments, purchase-orders, PaymentsDashboard) are SSE-encrypted with alias/seahaven-dynamodb (INFRA-95 / M-3):

  • wo-po-lookup, po-sync, workorder-sync — tables are imported by name, so grantReadData adds no KMS perms; dynamodbCmk.grantDecrypt(fn) grants kms:Decrypt explicitly (CMK imported via SSM /seahaven/dynamodb/cmk-arn).

Replaces the interim CLI inline policy (Sid Infra95DynamoDbCmkDecrypt) currently on those three roles with IaC.

Review

Cross-reviewed (IAM/KMS) → APPROVE. grantDecrypt (kms:Decrypt + kms:ReEncryptFrom) is sufficient for reads; key policy's root: kms:* makes the identity grant work. No construct-ID collision (separate construct scopes).

cdk diff

Adds kms:Decrypt to the 3 reader role DefaultPolicies + an SSM parameter ref. (The SocketMode container / OpenSearch-CR lines in a local diff are local-vs-CI Docker asset-hash artifacts — CI rebuilds arm64; no real code change.)

Deploy

Deploys via the deploy.yaml pipeline on merge (arm64 build). Do not hand-deploy locally (x86 image → exec format error on the listener). Post-merge: verify the CDK grant is live, then delete the interim inline policies.

Part of INFRA-95.

## Summary Codifies the `kms:Decrypt` grant that the three DynamoDB readers need now that their tables (`WorkOrders`, `WorkOrderComments`, `purchase-orders`, `PaymentsDashboard`) are SSE-encrypted with `alias/seahaven-dynamodb` (INFRA-95 / M-3): - `wo-po-lookup`, `po-sync`, `workorder-sync` — tables are imported by name, so `grantReadData` adds no KMS perms; `dynamodbCmk.grantDecrypt(fn)` grants `kms:Decrypt` explicitly (CMK imported via SSM `/seahaven/dynamodb/cmk-arn`). Replaces the **interim CLI inline policy** (`Sid Infra95DynamoDbCmkDecrypt`) currently on those three roles with IaC. ## Review Cross-reviewed (IAM/KMS) → APPROVE. `grantDecrypt` (`kms:Decrypt` + `kms:ReEncryptFrom`) is sufficient for reads; key policy's `root: kms:*` makes the identity grant work. No construct-ID collision (separate construct scopes). ## `cdk diff` Adds `kms:Decrypt` to the 3 reader role DefaultPolicies + an SSM parameter ref. (The SocketMode container / OpenSearch-CR lines in a local diff are local-vs-CI Docker asset-hash artifacts — CI rebuilds arm64; no real code change.) ## Deploy Deploys via the `deploy.yaml` pipeline on merge (arm64 build). **Do not hand-deploy locally** (x86 image → exec format error on the listener). Post-merge: verify the CDK grant is live, then delete the interim inline policies. Part of INFRA-95.
This repo is archived. You cannot comment on pull requests.
No description provided.