Add seahaven-prod member baseline (Phase 5)

Account 011934824531 is the target for all new production stacks; the
management account is frozen for new workloads. First proven exercise
of the automatic enrollment sweep (Enabled in 124s, no manual
create-members) and of AutoEnableStandards=NONE (no pre-enabled
standards, so CFN owns FSBP + CIS v3.0 cleanly). Default VPC deleted;
budget starts at $100 and resizes as tenants land.
This commit is contained in:
Adam Moussa 2026-07-14 17:00:09 -04:00
parent 0a7c1bc450
commit db71b0a75e
No known key found for this signature in database
3 changed files with 39 additions and 1 deletions

View file

@ -50,3 +50,12 @@ jobs:
stack-name: "seahaven-dev-baseline"
secrets:
deploy-role-arn: ${{ secrets.AWS_DEPLOY_ROLE_ARN_DEV }}
deploy-prod:
uses: Sea-Haven-Industries/.github/.github/workflows/cd-cdk.yaml@3cde673b9d05c0e68aac4d997d582f2543853d20 # main
with:
node-version: "24"
stacks: "prod-baseline"
stack-name: "seahaven-prod-baseline"
secrets:
deploy-role-arn: ${{ secrets.AWS_DEPLOY_ROLE_ARN_PROD }}

View file

@ -31,6 +31,7 @@ Stacks (deployed by the CD workflow — one job per target account):
| `seahaven-external-dev-baseline` | 396287094661 | us-east-1 | Member-account baseline: Config, GuardDuty, Security Hub (FSBP + CIS v3.0), Access Analyzer, flow logs, budget |
| `seahaven-security-baseline` | 001520130573 | us-east-1 | Member-account baseline for the delegated security-admin account (same construct set) |
| `seahaven-dev-baseline` | 710827005802 | us-east-1 | Member-account baseline for internal dev/staging (org-managed detection — no local GuardDuty/SecurityHub) |
| `seahaven-prod-baseline` | 011934824531 | us-east-1 | Member-account baseline for production workloads (org-managed detection; mgmt account frozen for new workloads) |
## CDK app
@ -48,7 +49,7 @@ the TypeScript source — no separate compile step needed for `cdk synth` /
| `tsconfig.json` | TypeScript compiler options (`outDir: cdk.out`) |
| `package.json` | Pinned `aws-cdk-lib`, CDK CLI, and the `build` / `synth` / `diff` / `deploy` npm scripts |
`bin/app.ts` synthesizes nine stacks across three regions and four accounts:
`bin/app.ts` synthesizes ten stacks across three regions and five accounts:
| Construct id | Stack name | Account | Region | Source |
|---|---|---|---|---|
@ -61,6 +62,7 @@ the TypeScript source — no separate compile step needed for `cdk synth` /
| `external-dev-baseline` | `seahaven-external-dev-baseline` | 396287094661 | us-east-1 | `lib/member-baseline-stack.ts` |
| `security-baseline` | `seahaven-security-baseline` | 001520130573 | us-east-1 | `lib/member-baseline-stack.ts` |
| `dev-baseline` | `seahaven-dev-baseline` | 710827005802 | us-east-1 | `lib/member-baseline-stack.ts` (orgManagedDetection) |
| `prod-baseline` | `seahaven-prod-baseline` | 011934824531 | us-east-1 | `lib/member-baseline-stack.ts` (orgManagedDetection) |
Member-account stacks deploy with per-account credentials — the CD workflow
runs one job per account, each assuming that account's OIDC deploy role. Local
@ -71,6 +73,7 @@ deploys/diffs assume `OrganizationAccountAccessRole` in the target account.
| 396287094661 (external-dev) | `githubdeploy-seahaven-external-dev-baseline` | `AWS_DEPLOY_ROLE_ARN_EXTDEV` |
| 001520130573 (security) | `githubdeploy-seahaven-org-baseline` | `AWS_DEPLOY_ROLE_ARN_SECURITY` |
| 710827005802 (dev) | `githubdeploy-seahaven-org-baseline` | `AWS_DEPLOY_ROLE_ARN_DEV` |
| 011934824531 (prod) | `githubdeploy-seahaven-org-baseline` | `AWS_DEPLOY_ROLE_ARN_PROD` |
Shared constructs (`DetectiveControls`, `FlowLogs`, `GovernanceToggles`) are
prefix-parameterized — construct ids and physical names must stay

View file

@ -13,6 +13,7 @@ const ACCOUNT = "328440206208";
const EXTERNAL_DEV_ACCOUNT = "396287094661";
const SECURITY_ACCOUNT = "001520130573";
const DEV_ACCOUNT = "710827005802";
const PROD_ACCOUNT = "011934824531";
// All 5 VPCs in 328440206208 / us-east-1 (4 custom + default), audit Agent 7.
// Index-derived logical IDs — append only, never reorder.
@ -128,6 +129,31 @@ new MemberBaselineStack(app, "dev-baseline", {
orgManagedDetection: true,
});
// ── Member-account baseline: seahaven-prod (Phase 5) ────────────────────────
// Target for ALL new production stacks (mgmt 328440206208 is frozen for new
// workloads). First tenant: proposal-system redeploy. Detection is org-managed
// (AUTO-enrolled by the sweep in 124s — first proven exercise, 2026-07-14 —
// and verified Enabled before this stack's first deploy); standards + account
// analyzer are CFN-owned per the Phase-4 review. Default VPC DELETED (prod
// workloads use purpose-built VPCs). Same lifecycle rule: root-harden at org
// ROOT, then move-account into the prod OU (ou-nbuj-5lc2wp6h) — NO WORKLOADS
// until the account is inside the OU. Budget starts at $100 and is resized as
// tenants land; AWS Backup vaults are added with the first stateful tenant
// (cross-account restore test = definition of done for that change).
new MemberBaselineStack(app, "prod-baseline", {
stackName: "seahaven-prod-baseline",
env: { account: PROD_ACCOUNT, region: "us-east-1" },
namePrefix: "seahaven-prod",
monthlyBudgetUsd: 100,
budgetAlertEmail: "aws@seahaven.com",
ownerEmail: "adam@seahaven.com",
// Append-only, never reorder (index-derived logical IDs). Empty: no VPCs
// exist yet; append ids via PR as purpose-built VPCs land.
flowLogVpcIds: [],
managedByTag: "seahaven-org-baseline",
orgManagedDetection: true,
});
// ── Shared DynamoDB CMK (INFRA-95 / M-3) ─────────────────────────────────────
// Dedicated, standalone stack so the customer-managed key for sensitive
// finance/PII DynamoDB tables is an independent shared dependency for the owning