Skip to content

fix(security): use CMK for RDS storage and Secrets Manager encryption#8

Open
sebastiancorrea81 wants to merge 1 commit intomainfrom
feature/rds-cmk-encryption
Open

fix(security): use CMK for RDS storage and Secrets Manager encryption#8
sebastiancorrea81 wants to merge 1 commit intomainfrom
feature/rds-cmk-encryption

Conversation

@sebastiancorrea81
Copy link
Copy Markdown
Contributor

Replace AWS-managed key with a Customer Managed KMS Key (CMK) to satisfy security audit finding (Estandar row 87). The CMK includes automatic key rotation, explicit service principal grants for RDS and Secrets Manager, and a dedicated IAM policy in requirements so agents can manage the key.

Replace AWS-managed key with a Customer Managed KMS Key (CMK) to satisfy
security audit finding (Estandar row 87). The CMK includes automatic key
rotation, explicit service principal grants for RDS and Secrets Manager,
and a dedicated IAM policy in requirements so agents can manage the key.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant