Route AWS notifications to dedicated mailboxes

Budget alerts and CIS alarm subscriptions now go to aws@seahaven.com
(management) and aws-external-dev@seahaven.com (external-dev) instead
of personal addresses (Adam, 2026-07-14; resolves security-review flag
SH-ORG-007). Owner tags are informational and stay decoupled.
This commit is contained in:
Adam Moussa 2026-07-14 14:34:04 -04:00
parent 10e66c92c0
commit 2e68071400
No known key found for this signature in database
2 changed files with 11 additions and 5 deletions

View file

@ -28,7 +28,10 @@ new AccountBaselineStack(app, "account-baseline", {
stackName: "seahaven-account-baseline",
env: { account: ACCOUNT, region: "us-east-1" },
monthlyBudgetUsd: 1200,
budgetAlertEmail: "adam@seahavenind.com",
// Dedicated AWS-notifications mailbox (Adam, 2026-07-14). Also feeds the CIS
// alarm SNS subscription — a changed endpoint must CONFIRM via the email
// link before alarm notifications flow again.
budgetAlertEmail: "aws@seahaven.com",
flowLogVpcIds: PROD_VPC_IDS,
});
@ -59,9 +62,10 @@ new MemberBaselineStack(app, "external-dev-baseline", {
env: { account: EXTERNAL_DEV_ACCOUNT, region: "us-east-1" },
namePrefix: "seahaven-extdev",
monthlyBudgetUsd: 200,
// NOTE: seahaven.com (not seahavenind.com) is deliberate-as-deployed; flagged
// in the 2026-07-14 security review (SH-ORG-007) for mailbox verification.
budgetAlertEmail: "adam@seahaven.com",
// Account-dedicated AWS-notifications mailbox (Adam, 2026-07-14 — resolves
// security-review flag SH-ORG-007).
budgetAlertEmail: "aws-external-dev@seahaven.com",
ownerEmail: "adam@seahaven.com",
flowLogVpcIds: EXTDEV_FLOW_LOG_VPC_IDS,
// Keeps the tag value the stack was deployed with (zero-diff merge). Update
// to the current repo name in a deliberate follow-up change if desired.

View file

@ -15,6 +15,8 @@ export interface MemberBaselineStackProps extends cdk.StackProps {
readonly monthlyBudgetUsd: number;
/** Sea Haven ops address that receives budget alerts (not the account's tenants). */
readonly budgetAlertEmail: string;
/** Value for the Owner tag (informational; decoupled from alert routing). */
readonly ownerEmail: string;
/** VPC ids to attach flow logs to (from cdk context; may be empty). */
readonly flowLogVpcIds: string[];
/** Value for the ManagedBy tag on every resource in the stack. */
@ -58,7 +60,7 @@ export class MemberBaselineStack extends cdk.Stack {
alertEmail: props.budgetAlertEmail,
});
cdk.Tags.of(this).add("Owner", props.budgetAlertEmail);
cdk.Tags.of(this).add("Owner", props.ownerEmail);
cdk.Tags.of(this).add("ManagedBy", props.managedByTag);
}
}