|
1 | 1 | from troposphere.kms import Alias, Key
|
| 2 | +from troposphere.logs import LogGroup |
2 | 3 |
|
3 | 4 | from serverless.service.plugins.kms import KMSGrant
|
4 | 5 | from serverless.service.plugins.scriptable import Scriptable
|
@@ -67,26 +68,31 @@ def pre_render(self, service):
|
67 | 68 | resource.DependsOn = "ServiceEncryptionKeyAlias"
|
68 | 69 |
|
69 | 70 | for fn in service.functions.all():
|
70 |
| - self.key.KeyPolicy["Statement"].append( |
71 |
| - { |
72 |
| - "Effect": "Allow", |
73 |
| - "Principal": {"Service": "logs.${aws:region}.amazonaws.com"}, |
74 |
| - "Action": [ |
75 |
| - "kms:Encrypt*", |
76 |
| - "kms:Decrypt*", |
77 |
| - "kms:ReEncrypt*", |
78 |
| - "kms:GenerateDataKey*", |
79 |
| - "kms:Describe*", |
80 |
| - ], |
81 |
| - "Resource": "*", |
82 |
| - "Condition": { |
83 |
| - "ArnLike": { |
84 |
| - "kms:EncryptionContext:aws:logs:arn": "arn:aws:logs:${aws:region}:${aws:accountId}:log-group:/aws/lambda/" |
85 |
| - + fn.name.spinal |
86 |
| - } |
87 |
| - }, |
| 71 | + self.key.KeyPolicy["Statement"].append(self.create_log_group_kms_statement("arn:aws:logs:${aws:region}:${aws:accountId}:log-group:/aws/lambda/" + fn.name.spinal)) |
| 72 | + |
| 73 | + for resource in service.resources.all(): |
| 74 | + if isinstance(resource, LogGroup): |
| 75 | + if resource.properties.get("KmsKeyId") is not None: |
| 76 | + self.key.KeyPolicy["Statement"].append(self.create_log_group_kms_statement("arn:aws:logs:${aws:region}:${aws:accountId}:log-group:" + resource.LogGroupName)) |
| 77 | + |
| 78 | + def create_log_group_kms_statement(self, log_group): |
| 79 | + return { |
| 80 | + "Effect": "Allow", |
| 81 | + "Principal": {"Service": "logs.${aws:region}.amazonaws.com"}, |
| 82 | + "Action": [ |
| 83 | + "kms:Encrypt*", |
| 84 | + "kms:Decrypt*", |
| 85 | + "kms:ReEncrypt*", |
| 86 | + "kms:GenerateDataKey*", |
| 87 | + "kms:Describe*", |
| 88 | + ], |
| 89 | + "Resource": "*", |
| 90 | + "Condition": { |
| 91 | + "ArnLike": { |
| 92 | + "kms:EncryptionContext:aws:logs:arn": log_group |
88 | 93 | }
|
89 |
| - ) |
| 94 | + }, |
| 95 | + } |
90 | 96 |
|
91 | 97 | def enable(self, service):
|
92 | 98 | if not service.regions:
|
|
0 commit comments