Skip to content

Provide one short-lived CloudTrail Event History audit session #141

Description

@alexeygrigorev

Provide one short-lived CloudTrail Event History audit session

Status: blocked — substantive collection complete and classified insufficient; waiting only for HUMAN session-expiry/revocation and authentic provenance cleanup
Tags: research, human, infra, data, P1
Depends on: None
Blocks: None — #141 blocks neither #140 nor #143; #143 independently blocks #136
Next owner: HUMAN session owner, followed by PM acceptance
Resume condition: sanitized authentic session-expiry/revocation evidence and any authentic pre-existing session/retrieval provenance are recorded; missing metadata is classified honestly rather than reconstructed

Current result

The fixed, read-only CloudTrail Event History collection is complete. It found exactly one matching historical Sponsor CRM CreateTable event. That event contains the historical DynamoDB table identifier but no exact CloudFormation stack identifier or canonical ownership tags. The independently authenticated deployment provenance contains the stack incarnation but not the table identifier. The records are not cryptographically linked.

Architecture and Security classified the result as insufficient. It is not a candidate exact binding, not a conflict, and not unavailable. #140 rejected route A and selected route B in #143.

Do not rerun or recollect these queries merely to correct process metadata. No speculative CloudTrail/Config/backup search is authorized here. A new collection requires a separately identified authoritative source capable of containing the exact historical pair and fresh grooming.

Sanitized collection record

Private evidence permissions were recorded as directory mode 0700 and file mode 0600. The private collection contained 27 entries; all 22 artifacts listed in its manifest matched the recorded byte sizes and SHA-256 digests. All nine JSON outputs parsed successfully. No response retained an unconsumed continuation token. The two queries with more than one page returned 203 and 125 events, substantiating automatic pagination beyond the page size of 50.

The local AWS CLI version did not support --no-cli-pager; omitting that client-only flag did not alter the AWS API/query scope or captured stdout.

Queries, counts, sizes, and public digests

  • Creation-source query, fixed 2026-07-12T21:15:00Z2026-07-12T21:35:00Z window in eu-west-1: 203 total events, 203 DynamoDB; 442,330 bytes; SHA-256 6574da797b9a3ea8ab36341024103e6e426192d855923316e2632c22b084ff86.
  • CreateTable, fixed 2026-07-12T21:15:00Z2026-07-31T06:11:00Z interval: 125 total events, 125 DynamoDB; 372,629 bytes; SHA-256 59fe476f2ba7a6d04335493ef805ba4bc770078099da114bc9a6e76698cb1574.
  • TagResource, same fixed interval: 3 total events, 2 DynamoDB; 6,917 bytes; SHA-256 f4c1a21f10433139ab8a34e1f16ea54a4a6d026d6ea334c43122dee7edc11eb9.
  • UntagResource, DeleteTable, RestoreTableFromBackup, RestoreTableToPointInTime, CreateBackup, and UpdateTable, same fixed interval: zero events for each; each JSON output was 21 bytes with SHA-256 450e0ee55f895199f4b307725acfc2edd9d1a11aa63b457c0ed5aa221be0476f.
  • All nine stderr artifacts were empty, each with SHA-256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855.

Private parsing selected exactly one matching target CreateTable event in the overlapping creation-source and event-name responses; the selected bytes were identical. No matching target ownership mutation was found in the bounded histories. This absence is corroboration only and does not prove the missing exact stack↔table binding.

Raw events, resource/account/principal identifiers, table/stack identifiers, private locations/links, credentials-adjacent data, and operational evidence remain outside this public repository.

Honest operation inventory and process deviation

The bounded evidence collection itself used only cloudtrail:LookupEvents and made no mutation. However, a separate read-only sts:GetCallerIdentity call occurred before collection. Therefore the public operation inventory must not claim that the complete session used only LookupEvents.

Architecture and Security accepted the content of the hashed evidence for route selection but did not accept procedural closure. Do not erase, minimize, or “repair” this deviation through a rerun.

Exact remaining procedural blockers

  1. The separate audit session's least-privilege policy, region restriction, authoritative issuance/duration, and expiry were not proven from authentic records.
  2. The private manifest lacks an explicit retrieval timestamp and principal/session provenance. Filesystem timestamps are not an adequate substitute.
  3. The session's revocation/expiry, rejected reuse, or passage of authoritative expiry remains a HUMAN responsibility and is not yet recorded in sanitized form.
  4. PM must explicitly accept the precollection sts:GetCallerIdentity deviation and decide whether unavailable provenance is recorded as unmet rather than reconstructed.

Only authentic pre-existing policy, issuance, expiry, retrieval, or principal/session records may be added. Never reconstruct, backfill, infer, or fabricate missing metadata. If an authentic record is unavailable, say so and leave the relevant criterion unmet.

Completed scope

  • The creation-source query used exactly the padded 2026-07-12T21:15:00Z2026-07-12T21:35:00Z window in eu-west-1.
  • All eight event-name queries used exactly the fixed 2026-07-12T21:15:00Z2026-07-31T06:11:00Z interval.
  • Responses were parsed locally for DynamoDB source and the private target identity.
  • Automatic pagination completed, including both multi-page query results.
  • Byte-exact raw stdout/stderr and the 22-entry hash/size manifest were retained privately with restrictive filesystem permissions.
  • The result was classified insufficient under the four-state evidence standard.
  • No mutation API, repository, IAM, deployment-role, workflow, CloudTrail configuration, environment, or resource change occurred under collection.
  • Reconcile missing CloudFormation ownership provenance for Sponsor CRM table #140 consumed the substantive result, rejected route A, and routed remediation to Reconcile Sponsor CRM table ownership with CloudFormation #143.

Acceptance criteria

Test scenarios

Authentic provenance exists

Given pre-existing policy/issuance/retrieval/session records are available
When the HUMAN stores them privately and posts only sanitized confirmation
Then the corresponding criterion may pass without rerunning AWS queries.

Provenance is unavailable

Given authentic records do not exist or cannot be retrieved
When closure is assessed
Then the criterion remains unmet or is explicitly accepted as a process deviation; metadata is never reconstructed.

Session has expired or was revoked

Given the authoritative expiry passed or an authorized HUMAN revoked the session
When sanitized evidence of expiry and rejected reuse is recorded
Then the HUMAN closure criterion may pass without disclosing identity details.

Same query is proposed again

Given the collection is complete and hashed
When a rerun is proposed only to obtain compliant metadata
Then stop; preserve the original result and resolve the procedural deviation honestly.

Out of scope

  • Recollecting the same Event History evidence.
  • Speculative CloudTrail Lake, trail, AWS Config, backup, PITR, DynamoDB, CloudFormation, IAM, S3, KMS, restore, tag, or deploy queries.
  • Creating or editing IAM identities, roles, policies, permission sets, or trust policies.
  • Modifying the deploy role, repository, workflows, environments, or CloudTrail configuration.
  • Any backup, restore, import, replacement, retag, migration, deployment, feature enablement, production data action, or queue cleanup.
  • Publishing raw evidence, identifiers, private locations, or Support material.

Metadata

Metadata

Assignees

No one assigned

    Labels

    P1ImportantdataData model, migration, storagehumanCode done or issue blocked on human verificationinfraDeployment and infrastructureresearchInvestigation before implementation

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions