From 2e68071400632e71376f07bc2ea8f6dd127d2d51 Mon Sep 17 00:00:00 2001 From: Adam Moussa Date: Tue, 14 Jul 2026 14:34:04 -0400 Subject: [PATCH] Route AWS notifications to dedicated mailboxes Budget alerts and CIS alarm subscriptions now go to aws@seahaven.com (management) and aws-external-dev@seahaven.com (external-dev) instead of personal addresses (Adam, 2026-07-14; resolves security-review flag SH-ORG-007). Owner tags are informational and stay decoupled. --- bin/app.ts | 12 ++++++++---- lib/member-baseline-stack.ts | 4 +++- 2 files changed, 11 insertions(+), 5 deletions(-) diff --git a/bin/app.ts b/bin/app.ts index 7c19d66..15e81a4 100644 --- a/bin/app.ts +++ b/bin/app.ts @@ -28,7 +28,10 @@ new AccountBaselineStack(app, "account-baseline", { stackName: "seahaven-account-baseline", env: { account: ACCOUNT, region: "us-east-1" }, monthlyBudgetUsd: 1200, - budgetAlertEmail: "adam@seahavenind.com", + // Dedicated AWS-notifications mailbox (Adam, 2026-07-14). Also feeds the CIS + // alarm SNS subscription — a changed endpoint must CONFIRM via the email + // link before alarm notifications flow again. + budgetAlertEmail: "aws@seahaven.com", flowLogVpcIds: PROD_VPC_IDS, }); @@ -59,9 +62,10 @@ new MemberBaselineStack(app, "external-dev-baseline", { env: { account: EXTERNAL_DEV_ACCOUNT, region: "us-east-1" }, namePrefix: "seahaven-extdev", monthlyBudgetUsd: 200, - // NOTE: seahaven.com (not seahavenind.com) is deliberate-as-deployed; flagged - // in the 2026-07-14 security review (SH-ORG-007) for mailbox verification. - budgetAlertEmail: "adam@seahaven.com", + // Account-dedicated AWS-notifications mailbox (Adam, 2026-07-14 — resolves + // security-review flag SH-ORG-007). + budgetAlertEmail: "aws-external-dev@seahaven.com", + ownerEmail: "adam@seahaven.com", flowLogVpcIds: EXTDEV_FLOW_LOG_VPC_IDS, // Keeps the tag value the stack was deployed with (zero-diff merge). Update // to the current repo name in a deliberate follow-up change if desired. diff --git a/lib/member-baseline-stack.ts b/lib/member-baseline-stack.ts index bec50ab..f6677a8 100644 --- a/lib/member-baseline-stack.ts +++ b/lib/member-baseline-stack.ts @@ -15,6 +15,8 @@ export interface MemberBaselineStackProps extends cdk.StackProps { readonly monthlyBudgetUsd: number; /** Sea Haven ops address that receives budget alerts (not the account's tenants). */ readonly budgetAlertEmail: string; + /** Value for the Owner tag (informational; decoupled from alert routing). */ + readonly ownerEmail: string; /** VPC ids to attach flow logs to (from cdk context; may be empty). */ readonly flowLogVpcIds: string[]; /** Value for the ManagedBy tag on every resource in the stack. */ @@ -58,7 +60,7 @@ export class MemberBaselineStack extends cdk.Stack { alertEmail: props.budgetAlertEmail, }); - cdk.Tags.of(this).add("Owner", props.budgetAlertEmail); + cdk.Tags.of(this).add("Owner", props.ownerEmail); cdk.Tags.of(this).add("ManagedBy", props.managedByTag); } }