mirror of
https://github.com/Sea-Haven-Industries/seahaven-account-baseline.git
synced 2026-08-04 16:56:14 +00:00
Merge branch 'main' into dependabot/npm_and_yarn/minor-and-patch-417471e184
This commit is contained in:
commit
8dde1000ef
1 changed files with 52 additions and 2 deletions
54
README.md
54
README.md
|
|
@ -5,8 +5,9 @@
|
|||

|
||||
|
||||
Account-level security and governance baseline for Sea Haven Industries
|
||||
(AWS account **328440206208**), managed as a single CDK TypeScript app. Most
|
||||
resources are in **us-east-1**; the offsite backup vault is in **us-west-2**.
|
||||
(AWS account **328440206208**), managed as a single CDK TypeScript app. The
|
||||
primary baseline is in **us-east-1**, with secondary-region baselines in
|
||||
**us-east-2** and **us-west-2** and the offsite backup vault in **us-west-2**.
|
||||
This is where account-wide detective and recovery controls live, so they are
|
||||
versioned, reviewed, and drift-checked like any other stack.
|
||||
|
||||
|
|
@ -15,9 +16,58 @@ Stacks (all deployed by `cdk deploy --all` / the CD workflow):
|
|||
| Stack | Region | Purpose |
|
||||
|---|---|---|
|
||||
| `seahaven-account-baseline` | us-east-1 | CloudTrail + future detective controls (C-1) |
|
||||
| `seahaven-dynamodb-cmk` | us-east-1 | Shared customer-managed KMS key for finance/PII DynamoDB tables; ARN published to SSM `/seahaven/dynamodb/cmk-arn` (INFRA-95 / M-3) |
|
||||
| `seahaven-regional-baseline-us-west-2` | us-west-2 | Bedrock invocation logging (INFRA-91) |
|
||||
| `seahaven-regional-baseline-us-east-2` | us-east-2 | Bedrock invocation logging + AWS Config recorder + Security Hub (INFRA-91 / INFRA-16) |
|
||||
| `seahaven-backup` | us-east-1 | Primary AWS Backup vault + plan + role (C-7) |
|
||||
| `seahaven-backup-offsite` | us-west-2 | Governance-locked offsite copy vault (C-7) |
|
||||
|
||||
## CDK app
|
||||
|
||||
The repo is a single AWS CDK app written in TypeScript. `cdk.json` is the
|
||||
project config the `cdk` CLI reads on every command: its `app` key
|
||||
(`npx ts-node bin/app.ts`) tells CDK how to synthesize the app straight from
|
||||
the TypeScript source — no separate compile step needed for `cdk synth` /
|
||||
`diff` / `deploy` — and its `context` block carries the AWS CDK feature flags.
|
||||
|
||||
| Path | Role |
|
||||
|---|---|
|
||||
| `cdk.json` | CDK config: `app` synth command, `watch` includes/excludes, `context` feature flags |
|
||||
| `bin/app.ts` | App entry point — instantiates every stack with an explicit kebab-case `stackName` and its target `env` (account `328440206208`, per-region) |
|
||||
| `lib/*-stack.ts` | Stack definitions (one class per stack; larger stacks compose the constructs in `lib/*.ts`) |
|
||||
| `tsconfig.json` | TypeScript compiler options (`outDir: cdk.out`) |
|
||||
| `package.json` | Pinned `aws-cdk-lib`, CDK CLI, and the `build` / `synth` / `diff` / `deploy` npm scripts |
|
||||
|
||||
`bin/app.ts` synthesizes six stacks across three regions:
|
||||
|
||||
| Construct id | Stack name | Region | Source |
|
||||
|---|---|---|---|
|
||||
| `account-baseline` | `seahaven-account-baseline` | us-east-1 | `lib/account-baseline-stack.ts` |
|
||||
| `dynamodb-cmk` | `seahaven-dynamodb-cmk` | us-east-1 | `lib/dynamodb-cmk-stack.ts` |
|
||||
| `regional-baseline-us-west-2` | `seahaven-regional-baseline-us-west-2` | us-west-2 | `lib/regional-baseline-stack.ts` |
|
||||
| `regional-baseline-us-east-2` | `seahaven-regional-baseline-us-east-2` | us-east-2 | `lib/regional-baseline-stack.ts` |
|
||||
| `backup-offsite` | `seahaven-backup-offsite` | us-west-2 | `lib/backup-offsite-stack.ts` |
|
||||
| `backup` | `seahaven-backup` | us-east-1 | `lib/backup-stack.ts` |
|
||||
|
||||
`backup` declares an explicit dependency on `backup-offsite` so the offsite copy
|
||||
vault exists before the primary plan that copies into it. Stack names are set
|
||||
explicitly to enforce kebab-case (CDK defaults to PascalCase). Synthesized
|
||||
CloudFormation templates land in `cdk.out/` (git-ignored).
|
||||
|
||||
Common commands:
|
||||
|
||||
```
|
||||
npm ci # install pinned deps
|
||||
npm run build # tsc type-check (compiles to cdk.out/)
|
||||
npx cdk synth # synthesize CloudFormation for all stacks
|
||||
npx cdk diff # diff synthesized stacks against deployed state
|
||||
npx cdk deploy --all # deploy every stack
|
||||
npx cdk deploy <stack-name> # deploy a single stack
|
||||
```
|
||||
|
||||
The `--context <key>=<value>` flag overrides `cdk.json` context at the command
|
||||
line (e.g. the `encryptTrailLogGroup` toggle under *Monitoring + logging*).
|
||||
|
||||
## Documentation
|
||||
|
||||
The canonical map of Sea Haven's AWS infrastructure lives in Confluence. This project's `seahaven-account-baseline`, `seahaven-backup`, and `seahaven-backup-offsite` stacks are represented there as Mermaid subgraphs.
|
||||
|
|
|
|||
Loading…
Add table
Reference in a new issue