KMS-638: Updated s3 access policy to include -ops as well. #82
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Overview
What is the feature?
The export-rdf-to-s3 lambda is not able to write to the s3 bucket kms-ref-backup-ops, we are not seeing any past published versions being archived.
What is the Solution?
The S3 access policy only includes
arn:aws:s3:::kms-rdf-backup-${stage}and sincestageis sit, uat, and prod, the never gives permissions to -ops. This change updates the access policy to include -ops as well.Note, I thought about seeing if I can rename the bucket, but in aws this is not possible, so think we should just deploy with this new access policy.
I should also note, the
mdtbucket is not needed that was left in there by accident, it was the bucket I was using for testing in the MDT ngap account.What areas of the application does this impact?
Export of past archived versions to s3.
Testing
Verify that we are seeing drafts and past published versions written to s3 after this change.
Checklist