diff --git a/.github/workflows/deploy.yaml b/.github/workflows/deploy.yaml index d21575a..7297f08 100644 --- a/.github/workflows/deploy.yaml +++ b/.github/workflows/deploy.yaml @@ -32,3 +32,11 @@ jobs: stacks: "external-dev-baseline" secrets: deploy-role-arn: ${{ secrets.AWS_DEPLOY_ROLE_ARN_EXTDEV }} + + deploy-security: + uses: Sea-Haven-Industries/.github/.github/workflows/cd-cdk.yaml@3cde673b9d05c0e68aac4d997d582f2543853d20 # main + with: + node-version: "24" + stacks: "security-baseline" + secrets: + deploy-role-arn: ${{ secrets.AWS_DEPLOY_ROLE_ARN_SECURITY }} diff --git a/README.md b/README.md index 21cd8ea..5e7742a 100644 --- a/README.md +++ b/README.md @@ -29,6 +29,7 @@ Stacks (deployed by the CD workflow — one job per target account): | `seahaven-backup` | 328440206208 | us-east-1 | Primary AWS Backup vault + plan + role (C-7) | | `seahaven-backup-offsite` | 328440206208 | us-west-2 | Governance-locked offsite copy vault (C-7) | | `seahaven-external-dev-baseline` | 396287094661 | us-east-1 | Member-account baseline: Config, GuardDuty, Security Hub (FSBP + CIS v3.0), Access Analyzer, flow logs, budget | +| `seahaven-security-baseline` | 001520130573 | us-east-1 | Member-account baseline for the delegated security-admin account (same construct set) | ## CDK app @@ -57,6 +58,7 @@ the TypeScript source — no separate compile step needed for `cdk synth` / | `backup-offsite` | `seahaven-backup-offsite` | 328440206208 | us-west-2 | `lib/backup-offsite-stack.ts` | | `backup` | `seahaven-backup` | 328440206208 | us-east-1 | `lib/backup-stack.ts` | | `external-dev-baseline` | `seahaven-external-dev-baseline` | 396287094661 | us-east-1 | `lib/member-baseline-stack.ts` | +| `security-baseline` | `seahaven-security-baseline` | 001520130573 | us-east-1 | `lib/member-baseline-stack.ts` | The member-account stack (`external-dev-baseline`) deploys with credentials for **396287094661** — the CD workflow runs it as a separate job assuming that diff --git a/bin/app.ts b/bin/app.ts index 15e81a4..3eb5aa8 100644 --- a/bin/app.ts +++ b/bin/app.ts @@ -11,6 +11,7 @@ import { OrgGovernanceStack } from "../lib/org-governance-stack"; const ACCOUNT = "328440206208"; const EXTERNAL_DEV_ACCOUNT = "396287094661"; +const SECURITY_ACCOUNT = "001520130573"; // All 5 VPCs in 328440206208 / us-east-1 (4 custom + default), audit Agent 7. // Index-derived logical IDs — append only, never reorder. @@ -72,6 +73,23 @@ new MemberBaselineStack(app, "external-dev-baseline", { managedByTag: "seahaven-external-dev-baseline", }); +// ── Member-account baseline: seahaven-security (Phase 3) ──────────────────── +// The org's delegated security administrator (GuardDuty / Security Hub / IAM +// Access Analyzer / Config aggregator / Inspector2 — delegation itself is CLI +// + README runbook, no CFN types). Created 2026-07-14 at org ROOT; moves into +// the security OU only after manual root hardening (deny-root-user invariant, +// see lib/org-governance-stack.ts). +new MemberBaselineStack(app, "security-baseline", { + stackName: "seahaven-security-baseline", + env: { account: SECURITY_ACCOUNT, region: "us-east-1" }, + namePrefix: "seahaven-security", + monthlyBudgetUsd: 50, + budgetAlertEmail: "aws@seahaven.com", + ownerEmail: "adam@seahaven.com", + flowLogVpcIds: [], + managedByTag: "seahaven-org-baseline", +}); + // ── Shared DynamoDB CMK (INFRA-95 / M-3) ───────────────────────────────────── // Dedicated, standalone stack so the customer-managed key for sensitive // finance/PII DynamoDB tables is an independent shared dependency for the owning