mirror of
https://github.com/Sea-Haven-Industries/sh-openswe-traces.git
synced 2026-10-03 08:03:31 +00:00
Freeze SAM CD and add terraform/ for seahaven-prod with account-suffixed buckets so HCP owns deploy before mgmt cutover. Suppress CKV_AWS_40 for the LangSmith export IAM user with documented mitigations.
16 lines
2 KiB
JSON
16 lines
2 KiB
JSON
{
|
|
"suppressions": [
|
|
{
|
|
"id": "checkov-CKV_AWS_109-13",
|
|
"justification": "False positive. bootstrap.yaml ExecRole (line 13) is a CloudFormation execution role assumable ONLY by cloudformation.amazonaws.com and gated by aws:SourceAccount == this account. CKV_AWS_109 fires on the IAM user actions (iam:CreateUser/PutUserPolicy in the ExportUser block), but those are ARN-scoped to arn:aws:iam::${AWS::AccountId}:user/sh-openswe-traces-* (not Resource:*), AND the explicit DenyUserCredentialAndEscalation block denies CreateAccessKey/CreateLoginProfile/UpdateLoginProfile/AttachUserPolicy/CreateServiceSpecificCredential and boundary tampering, so any created user is credential-inert. No privesc path. iam:PassRole is conditioned to cloudformation.amazonaws.com. Verified proof-or-kill 2026-07-13."
|
|
},
|
|
{
|
|
"id": "checkov-CKV_AWS_111-13",
|
|
"justification": "False positive. Same ExecRole. CKV_AWS_111 (write without constraint on Resource:*) fires on the KMS block (kms:CreateKey/CreateAlias), which is inherent to key creation \u2014 not-yet-existent keys cannot be ARN-scoped \u2014 with blast radius bounded to this stack's deploys. The other Resource:* statement is a Deny (flagging a Deny as over-permissive is nonsensical). CFN-only assumable, SourceAccount-conditioned. Verified proof-or-kill 2026-07-13."
|
|
},
|
|
{
|
|
"id": "checkov-CKV_AWS_40-10",
|
|
"justification": "Accepted risk for LangSmith Bulk Export (PLAT-73). CKV_AWS_40 prefers groups/roles over inline user policies; LangSmith's S3 destination requires long-lived IAM user access keys, so an IAM user with a single inline write-only policy is required. Mitigations: PutObject/AbortMultipartUpload only (no GetObject/DeleteObject); KMS Encrypt/GenerateDataKey/Decrypt gated by kms:ViaService=s3; access key minted out-of-band and never stored in Terraform state; secret on aws/secretsmanager key separate from the data CMK. Same pattern as the prior SAM LangSmithExportUser. REVISIT if LangSmith supports role assumption for Bulk Export destinations."
|
|
}
|
|
]
|
|
}
|