From add2eed12727edc38aed8c4edcaee463df340433 Mon Sep 17 00:00:00 2001 From: Adam Moussa Date: Tue, 14 Jul 2026 13:44:33 -0400 Subject: [PATCH] Commit extdev flow-log VPC ids in code, not -c context Security review SH-ORG-004 (confirmed high): with the ids sourced from ephemeral cdk context, any context-less deploy silently removes every flow log in the isolated account. A committed list makes the attachment set reviewable and immune to a forgotten -c flag. Empty list matches the deployed stack (zero diff). --- bin/app.ts | 22 ++++++++++------------ 1 file changed, 10 insertions(+), 12 deletions(-) diff --git a/bin/app.ts b/bin/app.ts index af5ec11..1630a51 100644 --- a/bin/app.ts +++ b/bin/app.ts @@ -37,25 +37,23 @@ new AccountBaselineStack(app, "account-baseline", { // renaming anything here replaces live resources). Deploys to the isolated // external-dev member account via its own OIDC deploy role, NOT the mgmt role. // -// Flow-log VPC ids come from context, NOT hardcoded — that account's VPCs -// change as the external dev team provisions infrastructure. Pass via: -// cdk deploy external-dev-baseline -c flowLogVpcIds=vpc-aaaa,vpc-bbbb -// Empty (default) keeps the hardened flow-logs bucket with no flow logs yet. -const vpcCtx = app.node.tryGetContext("flowLogVpcIds"); -const flowLogVpcIds: string[] = vpcCtx - ? String(vpcCtx) - .split(",") - .map((s) => s.trim()) - .filter(Boolean) - : []; +// Flow-log VPC ids are COMMITTED here, not passed via -c context. The old +// repo's `-c flowLogVpcIds=...` pattern was a confirmed security-review trap +// (SH-ORG-004): once flow logs were attached via context, any context-less +// deploy (including CI) would silently REMOVE them all. Append ids via PR; +// never reorder (index-derived logical IDs). Empty = hardened bucket only, +// matching the currently deployed stack. +const EXTDEV_FLOW_LOG_VPC_IDS: string[] = []; new MemberBaselineStack(app, "external-dev-baseline", { stackName: "seahaven-external-dev-baseline", env: { account: EXTERNAL_DEV_ACCOUNT, region: "us-east-1" }, namePrefix: "seahaven-extdev", monthlyBudgetUsd: 200, + // NOTE: seahaven.com (not seahavenind.com) is deliberate-as-deployed; flagged + // in the 2026-07-14 security review (SH-ORG-007) for mailbox verification. budgetAlertEmail: "adam@seahaven.com", - flowLogVpcIds, + flowLogVpcIds: EXTDEV_FLOW_LOG_VPC_IDS, // Keeps the tag value the stack was deployed with (zero-diff merge). Update // to the current repo name in a deliberate follow-up change if desired. managedByTag: "seahaven-external-dev-baseline",