Commit extdev flow-log VPC ids in code, not -c context

Security review SH-ORG-004 (confirmed high): with the ids sourced from
ephemeral cdk context, any context-less deploy silently removes every
flow log in the isolated account. A committed list makes the attachment
set reviewable and immune to a forgotten -c flag. Empty list matches
the deployed stack (zero diff).
This commit is contained in:
Adam Moussa 2026-07-14 13:44:33 -04:00
parent e2bbf5ec75
commit add2eed127
No known key found for this signature in database

View file

@ -37,25 +37,23 @@ new AccountBaselineStack(app, "account-baseline", {
// renaming anything here replaces live resources). Deploys to the isolated
// external-dev member account via its own OIDC deploy role, NOT the mgmt role.
//
// Flow-log VPC ids come from context, NOT hardcoded — that account's VPCs
// change as the external dev team provisions infrastructure. Pass via:
// cdk deploy external-dev-baseline -c flowLogVpcIds=vpc-aaaa,vpc-bbbb
// Empty (default) keeps the hardened flow-logs bucket with no flow logs yet.
const vpcCtx = app.node.tryGetContext("flowLogVpcIds");
const flowLogVpcIds: string[] = vpcCtx
? String(vpcCtx)
.split(",")
.map((s) => s.trim())
.filter(Boolean)
: [];
// Flow-log VPC ids are COMMITTED here, not passed via -c context. The old
// repo's `-c flowLogVpcIds=...` pattern was a confirmed security-review trap
// (SH-ORG-004): once flow logs were attached via context, any context-less
// deploy (including CI) would silently REMOVE them all. Append ids via PR;
// never reorder (index-derived logical IDs). Empty = hardened bucket only,
// matching the currently deployed stack.
const EXTDEV_FLOW_LOG_VPC_IDS: string[] = [];
new MemberBaselineStack(app, "external-dev-baseline", {
stackName: "seahaven-external-dev-baseline",
env: { account: EXTERNAL_DEV_ACCOUNT, region: "us-east-1" },
namePrefix: "seahaven-extdev",
monthlyBudgetUsd: 200,
// NOTE: seahaven.com (not seahavenind.com) is deliberate-as-deployed; flagged
// in the 2026-07-14 security review (SH-ORG-007) for mailbox verification.
budgetAlertEmail: "adam@seahaven.com",
flowLogVpcIds,
flowLogVpcIds: EXTDEV_FLOW_LOG_VPC_IDS,
// Keeps the tag value the stack was deployed with (zero-diff merge). Update
// to the current repo name in a deliberate follow-up change if desired.
managedByTag: "seahaven-external-dev-baseline",