mirror of
https://github.com/Sea-Haven-Industries/seahaven-account-baseline.git
synced 2026-08-04 16:56:14 +00:00
Commit extdev flow-log VPC ids in code, not -c context
Security review SH-ORG-004 (confirmed high): with the ids sourced from ephemeral cdk context, any context-less deploy silently removes every flow log in the isolated account. A committed list makes the attachment set reviewable and immune to a forgotten -c flag. Empty list matches the deployed stack (zero diff).
This commit is contained in:
parent
e2bbf5ec75
commit
add2eed127
1 changed files with 10 additions and 12 deletions
22
bin/app.ts
22
bin/app.ts
|
|
@ -37,25 +37,23 @@ new AccountBaselineStack(app, "account-baseline", {
|
|||
// renaming anything here replaces live resources). Deploys to the isolated
|
||||
// external-dev member account via its own OIDC deploy role, NOT the mgmt role.
|
||||
//
|
||||
// Flow-log VPC ids come from context, NOT hardcoded — that account's VPCs
|
||||
// change as the external dev team provisions infrastructure. Pass via:
|
||||
// cdk deploy external-dev-baseline -c flowLogVpcIds=vpc-aaaa,vpc-bbbb
|
||||
// Empty (default) keeps the hardened flow-logs bucket with no flow logs yet.
|
||||
const vpcCtx = app.node.tryGetContext("flowLogVpcIds");
|
||||
const flowLogVpcIds: string[] = vpcCtx
|
||||
? String(vpcCtx)
|
||||
.split(",")
|
||||
.map((s) => s.trim())
|
||||
.filter(Boolean)
|
||||
: [];
|
||||
// Flow-log VPC ids are COMMITTED here, not passed via -c context. The old
|
||||
// repo's `-c flowLogVpcIds=...` pattern was a confirmed security-review trap
|
||||
// (SH-ORG-004): once flow logs were attached via context, any context-less
|
||||
// deploy (including CI) would silently REMOVE them all. Append ids via PR;
|
||||
// never reorder (index-derived logical IDs). Empty = hardened bucket only,
|
||||
// matching the currently deployed stack.
|
||||
const EXTDEV_FLOW_LOG_VPC_IDS: string[] = [];
|
||||
|
||||
new MemberBaselineStack(app, "external-dev-baseline", {
|
||||
stackName: "seahaven-external-dev-baseline",
|
||||
env: { account: EXTERNAL_DEV_ACCOUNT, region: "us-east-1" },
|
||||
namePrefix: "seahaven-extdev",
|
||||
monthlyBudgetUsd: 200,
|
||||
// NOTE: seahaven.com (not seahavenind.com) is deliberate-as-deployed; flagged
|
||||
// in the 2026-07-14 security review (SH-ORG-007) for mailbox verification.
|
||||
budgetAlertEmail: "adam@seahaven.com",
|
||||
flowLogVpcIds,
|
||||
flowLogVpcIds: EXTDEV_FLOW_LOG_VPC_IDS,
|
||||
// Keeps the tag value the stack was deployed with (zero-diff merge). Update
|
||||
// to the current repo name in a deliberate follow-up change if desired.
|
||||
managedByTag: "seahaven-external-dev-baseline",
|
||||
|
|
|
|||
Loading…
Add table
Reference in a new issue