Use custom DB roles in EventGate Lambdas

Open
#229 0 comments 0 reactions 1 assignee View on GitHub

@tmikula-dev is already working on this.

Since Sep 15, 2026.

Assessment

This issue has not been assessed yet.

Description

enhancement

Summary

Currently, all EventGate Lambdas connect to the database using the postgres superuser. This is a significant security anti-pattern — the application should use least-privilege, role-specific database credentials instead of a superuser account.

Problem

  • Every Lambda function uses the postgres user for DB access, regardless of what operations it actually performs.
  • A compromised or buggy Lambda currently has full superuser access to the database (schema changes, other roles' data, etc.), far beyond what it needs.
  • This is effectively the worst-case DB security posture for the application.

Proposed Change

  • Update Lambdas to authenticate using the appropriate custom DB role(s) instead of postgres.
  • Custom role credentials are (or will be) stored in AWS Secrets Manager (see companion infrastructure issue in cps-eventbus-gateway for provisioning these secrets).
  • Pass the relevant Secrets Manager secret ARN into each Lambda so it can retrieve its DB credentials at runtime — likely via an environment variable (e.g. DB_SECRET_ARN), then resolved through the AWS SDK/Secrets Manager client during cold start or connection setup.
  • Ensure Lambda IAM roles are granted secretsmanager:GetSecretValue scoped to only the specific secret(s) they need.
  • Update DB connection/init code to fetch the username/password from the resolved secret instead of using hardcoded/postgres credentials.

Acceptance Criteria

  • Lambdas no longer connect to the database as postgres.
  • Each Lambda uses the custom role appropriate to its function/permissions needs.
  • Secret ARN(s) are passed into Lambdas via environment variable(s).
  • Lambda IAM permissions are scoped to only the secret(s) they require (least privilege).
  • DB connection logic updated to fetch credentials from Secrets Manager at runtime.

Dependencies

Dominant language
Python
Stars
4
Forks
0
Avg merge
20h 22m
Merged PRs (30d)
8

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from AbsaOSS/EventGate

All issues in AbsaOSS/EventGate

Similar issues

More Python issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.