Skip to content

[AWS] Add CMK support for audit log bucket #215

@eri-adepoju

Description

@eri-adepoju

Is your feature request related to a problem? Please describe.
All buckets created by SRA has CMK enabled, apart from the Audit Log bucket. This created a compliance issue for a customer

Describe the solution you'd like
A KMS key created and added to the Audit log bucket

Steps to recreate:

  • Create aws_kms_key and alias resources with the same configuration as the catalog_storage resource
  • Create an aws_s3_bucket_server_side_encryption_configuration resource similar to the unity_catalog resource

Describe alternatives you've considered
N/A

Additional context
I've verified that this was by adding a KMS key to an audit log bucket in the AWS portal. I verified that the bucket was populated before and after the key was added,

Metadata

Metadata

Assignees

Labels

enhancementNew feature or request

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions