Record SCP cross-review dispositions in org-governance

Root hardening must precede the OU move (deny-root-user blocks root MFA
enrollment), delegated-admin flows ride service-linked roles that SCPs
never evaluate, and the cdk exec-role exemption is accepted risk
mirroring the external-dev guardrails.
This commit is contained in:
Adam Moussa 2026-07-14 13:43:06 -04:00
parent 97f27bd8d7
commit 168cef2649
No known key found for this signature in database

View file

@ -33,6 +33,22 @@ import { Construct } from "constructs";
* Rollout discipline (Phase 2 canary): new SCPs attach to the NEW (empty) OUs
* only. Extending any of them to the external-dev OU is a separate, gated
* targetIds change made only after live access verification in 396287094661.
*
* Cross-review dispositions (GPT-4.1, 2026-07-14):
* - deny-root-user blocks root MFA enrollment (iam:EnableMFADevice as root).
* OPERATIONAL REQUIREMENT: create new accounts at the org ROOT, complete
* root hardening (MFA, contacts), THEN move-account into the target OU.
* - Delegated-admin ops (Phase 3) are unaffected by protect-security-baseline:
* org-managed GuardDuty/SecurityHub act on members via service-linked
* roles, which SCPs do not evaluate. If a legitimate admin action is ever
* denied, exemptions change only through the mandatory gates.
* - `arn:aws:iam::*:role/cdk-hnb659fds-*` exemption is ACCEPTED RISK (same
* decision as the external-dev guardrails): it is the only generic
* cross-account expression for CDK exec roles; member baselines protect
* those roles from takeover (ProtectPrivilegedRoles pattern).
* - Region-lock NotAction list deliberately matches battle-tested
* p-i59g24mz; regional services (s3, kms, logs, ssm...) stay region-locked
* BY DESIGN — do not add them to NotAction (that would exempt them).
*/
export class OrgGovernanceStack extends cdk.Stack {
constructor(scope: Construct, id: string, props?: cdk.StackProps) {