Use custom DB roles in EventGate Lambdas
@tmikula-dev is already working on this.
Since Sep 15, 2026.
Assessment
This issue has not been assessed yet.
Description
Summary
Currently, all EventGate Lambdas connect to the database using the postgres superuser. This is a significant security anti-pattern — the application should use least-privilege, role-specific database credentials instead of a superuser account.
Problem
- Every Lambda function uses the
postgresuser for DB access, regardless of what operations it actually performs. - A compromised or buggy Lambda currently has full superuser access to the database (schema changes, other roles' data, etc.), far beyond what it needs.
- This is effectively the worst-case DB security posture for the application.
Proposed Change
- Update Lambdas to authenticate using the appropriate custom DB role(s) instead of
postgres. - Custom role credentials are (or will be) stored in AWS Secrets Manager (see companion infrastructure issue in
cps-eventbus-gatewayfor provisioning these secrets). - Pass the relevant Secrets Manager secret ARN into each Lambda so it can retrieve its DB credentials at runtime — likely via an environment variable (e.g.
DB_SECRET_ARN), then resolved through the AWS SDK/Secrets Manager client during cold start or connection setup. - Ensure Lambda IAM roles are granted
secretsmanager:GetSecretValuescoped to only the specific secret(s) they need. - Update DB connection/init code to fetch the username/password from the resolved secret instead of using hardcoded/
postgrescredentials.
Acceptance Criteria
- Lambdas no longer connect to the database as
postgres. - Each Lambda uses the custom role appropriate to its function/permissions needs.
- Secret ARN(s) are passed into Lambdas via environment variable(s).
- Lambda IAM permissions are scoped to only the secret(s) they require (least privilege).
- DB connection logic updated to fetch credentials from Secrets Manager at runtime.
Dependencies
- Dominant language
- Python
- Stars
- 4
- Forks
- 0
- Avg merge
- 20h 22m
- Merged PRs (30d)
- 8
Contributor guide
No contributing guide indexed for this repository
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from AbsaOSS/EventGate
-
refactoring type:tech-debt
Difficulty 2/5 1-3 hours Newbie friendliness 84/100
-
enhancement
Difficulty 2/5 1-3 hours Newbie friendliness 70/100
-
infrastructure type:tech-debt
Difficulty 3/5 1-2 days Newbie friendliness 70/100
-
bug
Difficulty 3/5 1-2 days Newbie friendliness 70/100
-
refactoring type:tech-debt
Difficulty 3/5 1-2 days Newbie friendliness 71/100
All issues in AbsaOSS/EventGate
Similar issues
-
Difficulty 2/5 1-3 hours Newbie friendliness 88/100
-
Difficulty 2/5 1-3 hours Newbie friendliness 82/100
-
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
-
enhancement
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
-
Difficulty 2/5 1-3 hours Newbie friendliness 74/100