Use custom DB roles in EventGate Lambdas
@tmikula-dev ya está trabajando en esto.
Desde el 15/9/2026.
Evaluación
Este issue todavía no se ha evaluado.
Descripción
Summary
Currently, all EventGate Lambdas connect to the database using the postgres superuser. This is a significant security anti-pattern — the application should use least-privilege, role-specific database credentials instead of a superuser account.
Problem
- Every Lambda function uses the
postgresuser for DB access, regardless of what operations it actually performs. - A compromised or buggy Lambda currently has full superuser access to the database (schema changes, other roles' data, etc.), far beyond what it needs.
- This is effectively the worst-case DB security posture for the application.
Proposed Change
- Update Lambdas to authenticate using the appropriate custom DB role(s) instead of
postgres. - Custom role credentials are (or will be) stored in AWS Secrets Manager (see companion infrastructure issue in
cps-eventbus-gatewayfor provisioning these secrets). - Pass the relevant Secrets Manager secret ARN into each Lambda so it can retrieve its DB credentials at runtime — likely via an environment variable (e.g.
DB_SECRET_ARN), then resolved through the AWS SDK/Secrets Manager client during cold start or connection setup. - Ensure Lambda IAM roles are granted
secretsmanager:GetSecretValuescoped to only the specific secret(s) they need. - Update DB connection/init code to fetch the username/password from the resolved secret instead of using hardcoded/
postgrescredentials.
Acceptance Criteria
- Lambdas no longer connect to the database as
postgres. - Each Lambda uses the custom role appropriate to its function/permissions needs.
- Secret ARN(s) are passed into Lambdas via environment variable(s).
- Lambda IAM permissions are scoped to only the secret(s) they require (least privilege).
- DB connection logic updated to fetch credentials from Secrets Manager at runtime.
Dependencies
- Lenguaje dominante
- Python
- Estrellas
- 4
- Forks
- 0
- Merge medio
- 20 h 22 min
- PR fusionados (30 d)
- 8
Guía de contribución
No hay ninguna guía de contribución indexada para este repositorio
Primeros pasos
- Lee el issue completo y luego la guía de contribución del proyecto.
- Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
- Haz un fork del repositorio y trabaja en una rama.
- Abre un pull request que haga referencia al número del issue.
Más de AbsaOSS/EventGate
-
refactoring type:tech-debt
Dificultad 2/5 1-3 horas Aptitud para principiantes 84/100
-
enhancement
Dificultad 2/5 1-3 horas Aptitud para principiantes 70/100
-
infrastructure type:tech-debt
Dificultad 3/5 1-2 días Aptitud para principiantes 70/100
-
bug
Dificultad 3/5 1-2 días Aptitud para principiantes 70/100
-
refactoring type:tech-debt
Dificultad 3/5 1-2 días Aptitud para principiantes 71/100
Todos los issues de AbsaOSS/EventGate
Issues similares
-
documentation help wanted
Dificultad 2/5 1-3 horas Aptitud para principiantes 90/100
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 90/100
simonw/sqlite-utils#872 ·
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 88/100
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 82/100
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 78/100