Skip to content

feat(kms): make trustAccountIdentities optional in KeyGrants#36786

Merged
mergify[bot] merged 2 commits intomainfrom
otaviom/trustAccountIdentities-optional
Jan 23, 2026
Merged

feat(kms): make trustAccountIdentities optional in KeyGrants#36786
mergify[bot] merged 2 commits intomainfrom
otaviom/trustAccountIdentities-optional

Conversation

@otaviomacedo
Copy link
Copy Markdown
Contributor

Reason for this change

The KeyGrants.fromKey() method requires the user to decide whether they want to add permission to both the principal and the resource or just the principal. This is hard to reason about and most of the time customers just want a sensible default.

Description of changes

The parameter trustAccountIdentities to KeyGrants.fromKey() is being made optional, and defaults to the value of the @aws-cdk/aws-kms:defaultKeyPolicies feature flag.

Checklist


By submitting this pull request, I confirm that my contribution is made under the terms of the Apache-2.0 license

@aws-cdk-automation aws-cdk-automation requested a review from a team January 23, 2026 12:08
@github-actions github-actions bot added the p2 label Jan 23, 2026
@mergify mergify bot added the contribution/core This is a PR that came from AWS. label Jan 23, 2026
Copy link
Copy Markdown
Collaborator

@aws-cdk-automation aws-cdk-automation left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

(This review is outdated)

@aws-cdk-automation aws-cdk-automation added the pr/needs-further-review PR requires additional review from our team specialists due to the scope or complexity of changes. label Jan 23, 2026
@otaviomacedo otaviomacedo added pr-linter/exempt-readme The PR linter will not require README changes pr-linter/exempt-integ-test The PR linter will not require integ test changes labels Jan 23, 2026
@aws-cdk-automation aws-cdk-automation dismissed their stale review January 23, 2026 12:46

✅ Updated pull request passes all PRLinter validations. Dismissing previous PRLinter review.

@mergify
Copy link
Copy Markdown
Contributor

mergify bot commented Jan 23, 2026

Thank you for contributing! Your pull request will be updated from main and then merged automatically (do not update manually, and be sure to allow changes to be pushed to your fork).

@mergify mergify bot merged commit 06676ac into main Jan 23, 2026
52 of 53 checks passed
@mergify
Copy link
Copy Markdown
Contributor

mergify bot commented Jan 23, 2026

Merge Queue Status

✅ The pull request has been merged at 4a3ca05

This pull request spent 6 seconds in the queue, with no time running CI.
The checks were run in-place.

Required conditions to merge

@mergify mergify bot deleted the otaviom/trustAccountIdentities-optional branch January 23, 2026 12:48
@github-actions
Copy link
Copy Markdown
Contributor

Comments on closed issues and PRs are hard for our team to see.
If you need help, please open a new issue that references this one.

@github-actions github-actions bot locked as resolved and limited conversation to collaborators Jan 23, 2026
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

contribution/core This is a PR that came from AWS. p2 pr/needs-further-review PR requires additional review from our team specialists due to the scope or complexity of changes. pr-linter/exempt-integ-test The PR linter will not require integ test changes pr-linter/exempt-readme The PR linter will not require README changes

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants