mirror of
https://github.com/Sea-Haven-Industries/seahaven-account-baseline.git
synced 2026-08-04 16:56:14 +00:00
Route AWS notifications to dedicated mailboxes
Budget alerts and CIS alarm subscriptions now go to aws@seahaven.com (management) and aws-external-dev@seahaven.com (external-dev) instead of personal addresses (Adam, 2026-07-14; resolves security-review flag SH-ORG-007). Owner tags are informational and stay decoupled.
This commit is contained in:
parent
10e66c92c0
commit
2e68071400
2 changed files with 11 additions and 5 deletions
12
bin/app.ts
12
bin/app.ts
|
|
@ -28,7 +28,10 @@ new AccountBaselineStack(app, "account-baseline", {
|
|||
stackName: "seahaven-account-baseline",
|
||||
env: { account: ACCOUNT, region: "us-east-1" },
|
||||
monthlyBudgetUsd: 1200,
|
||||
budgetAlertEmail: "adam@seahavenind.com",
|
||||
// Dedicated AWS-notifications mailbox (Adam, 2026-07-14). Also feeds the CIS
|
||||
// alarm SNS subscription — a changed endpoint must CONFIRM via the email
|
||||
// link before alarm notifications flow again.
|
||||
budgetAlertEmail: "aws@seahaven.com",
|
||||
flowLogVpcIds: PROD_VPC_IDS,
|
||||
});
|
||||
|
||||
|
|
@ -59,9 +62,10 @@ new MemberBaselineStack(app, "external-dev-baseline", {
|
|||
env: { account: EXTERNAL_DEV_ACCOUNT, region: "us-east-1" },
|
||||
namePrefix: "seahaven-extdev",
|
||||
monthlyBudgetUsd: 200,
|
||||
// NOTE: seahaven.com (not seahavenind.com) is deliberate-as-deployed; flagged
|
||||
// in the 2026-07-14 security review (SH-ORG-007) for mailbox verification.
|
||||
budgetAlertEmail: "adam@seahaven.com",
|
||||
// Account-dedicated AWS-notifications mailbox (Adam, 2026-07-14 — resolves
|
||||
// security-review flag SH-ORG-007).
|
||||
budgetAlertEmail: "aws-external-dev@seahaven.com",
|
||||
ownerEmail: "adam@seahaven.com",
|
||||
flowLogVpcIds: EXTDEV_FLOW_LOG_VPC_IDS,
|
||||
// Keeps the tag value the stack was deployed with (zero-diff merge). Update
|
||||
// to the current repo name in a deliberate follow-up change if desired.
|
||||
|
|
|
|||
|
|
@ -15,6 +15,8 @@ export interface MemberBaselineStackProps extends cdk.StackProps {
|
|||
readonly monthlyBudgetUsd: number;
|
||||
/** Sea Haven ops address that receives budget alerts (not the account's tenants). */
|
||||
readonly budgetAlertEmail: string;
|
||||
/** Value for the Owner tag (informational; decoupled from alert routing). */
|
||||
readonly ownerEmail: string;
|
||||
/** VPC ids to attach flow logs to (from cdk context; may be empty). */
|
||||
readonly flowLogVpcIds: string[];
|
||||
/** Value for the ManagedBy tag on every resource in the stack. */
|
||||
|
|
@ -58,7 +60,7 @@ export class MemberBaselineStack extends cdk.Stack {
|
|||
alertEmail: props.budgetAlertEmail,
|
||||
});
|
||||
|
||||
cdk.Tags.of(this).add("Owner", props.budgetAlertEmail);
|
||||
cdk.Tags.of(this).add("Owner", props.ownerEmail);
|
||||
cdk.Tags.of(this).add("ManagedBy", props.managedByTag);
|
||||
}
|
||||
}
|
||||
|
|
|
|||
Loading…
Add table
Reference in a new issue