Problem
The DAS_KMS_REGION_NAME environment variable is documented in README.md but never used anywhere in the codebase.
| Variable |
Default |
Description |
DAS_KMS_REGION_NAME |
|
Region where the KMS key resides |
Searching main.go, the only env vars read are:
DAS_FILTER_NAME (line 69)
DAS_RDS_RESOURCE_ID (line 79)
DAS_KMS_REGION_NAME is not referenced. This means:
- If the KMS key is in a different region than the Lambda execution environment, decryption will fail — there is no way to configure a KMS client with a custom region.
- The README is misleading — operators may set this variable expecting it to work, but it has no effect.
Proposed Solution
Option A: Wire it up (preferred)
Use DAS_KMS_REGION_NAME to initialize the KMS client with a specific region:
kmsRegion := os.Getenv("DAS_KMS_REGION_NAME")
var kmsClient *kms.Client
if kmsRegion != "" {
kmsCfg, err := config.LoadDefaultConfig(ctx, config.WithRegion(kmsRegion))
// ...
kmsClient = kms.NewFromConfig(kmsCfg)
} else {
kmsClient = kms.NewFromConfig(cfg)
}
Option B: Remove it
If the KMS key is always in the same region as the Lambda, remove DAS_KMS_REGION_NAME from the README to avoid confusion.
Acceptance Criteria
Problem
The
DAS_KMS_REGION_NAMEenvironment variable is documented in README.md but never used anywhere in the codebase.DAS_KMS_REGION_NAMESearching main.go, the only env vars read are:
DAS_FILTER_NAME(line 69)DAS_RDS_RESOURCE_ID(line 79)DAS_KMS_REGION_NAMEis not referenced. This means:Proposed Solution
Option A: Wire it up (preferred)
Use
DAS_KMS_REGION_NAMEto initialize the KMS client with a specific region:Option B: Remove it
If the KMS key is always in the same region as the Lambda, remove
DAS_KMS_REGION_NAMEfrom the README to avoid confusion.Acceptance Criteria