This repository has been archived on 2026-08-04. You can view files and clone it, but cannot push or open issues or pull requests.
seahaven-slack-bot/lib/constructs
Adam Moussa 46f568f6ea
feat(slack-bot): codify kms:Decrypt grants for CMK'd DynamoDB readers (INFRA-95 / M-3) (#51)
wo-po-lookup, po-sync, and workorder-sync read WorkOrders,
WorkOrderComments, purchase-orders and PaymentsDashboard, which are now
SSE-encrypted with alias/seahaven-dynamodb. Tables are imported by name
so grantReadData adds no KMS perms; grant kms:Decrypt explicitly via the
CMK imported from SSM /seahaven/dynamodb/cmk-arn. Replaces the interim
CLI inline policy (Sid Infra95DynamoDbCmkDecrypt) with IaC.

INFRA-95
2026-06-09 12:33:06 -04:00
..
bedrock-agent.ts feat(slack-bot): codify kms:Decrypt grants for CMK'd DynamoDB readers (INFRA-95 / M-3) (#51) 2026-06-09 12:33:06 -04:00
conversation-log.ts feat: Alex rollout — persona, Socket Mode, payments, channels, App Home, unanswered questions 2026-04-30 16:38:54 -04:00
knowledge-base.ts fix(kb): lock AOSS network policy to private with Bedrock source service (#49) 2026-06-08 18:01:08 -04:00
notion-sync.ts feat: Alex rollout — persona, Socket Mode, payments, channels, App Home, unanswered questions 2026-04-30 16:38:54 -04:00
po-sync.ts feat(slack-bot): codify kms:Decrypt grants for CMK'd DynamoDB readers (INFRA-95 / M-3) (#51) 2026-06-09 12:33:06 -04:00
slack-handler.ts feat(api): add access logging and throttling to webhook HTTP API (#46) 2026-06-05 17:47:44 -04:00
socket-mode.ts Set explicit arm64 platform on Docker image build (#30) 2026-05-08 17:58:28 -04:00
workorder-sync.ts feat(slack-bot): codify kms:Decrypt grants for CMK'd DynamoDB readers (INFRA-95 / M-3) (#51) 2026-06-09 12:33:06 -04:00