mirror of
https://github.com/Sea-Haven-Industries/seahaven-account-baseline.git
synced 2026-08-04 16:56:14 +00:00
Rename package to seahaven-org-baseline
Prepares the repo rename: the app now spans the management account and org member accounts, so 'account-baseline' undersells the scope. README documents the two-account deploy topology and logical-ID constraints.
This commit is contained in:
parent
8f23c23a66
commit
e2bbf5ec75
2 changed files with 45 additions and 27 deletions
70
README.md
70
README.md
|
|
@ -1,26 +1,34 @@
|
|||
# seahaven-account-baseline
|
||||
# seahaven-org-baseline
|
||||
|
||||

|
||||

|
||||

|
||||

|
||||
|
||||
Account-level security and governance baseline for Sea Haven Industries
|
||||
(AWS account **328440206208**), managed as a single CDK TypeScript app. The
|
||||
primary baseline is in **us-east-1**, with secondary-region baselines in
|
||||
**us-east-2** and **us-west-2** and the offsite backup vault in **us-west-2**.
|
||||
This is where account-wide detective and recovery controls live, so they are
|
||||
versioned, reviewed, and drift-checked like any other stack.
|
||||
Organization-wide security and governance baseline for Sea Haven Industries,
|
||||
managed as a single CDK TypeScript app. Covers the management account
|
||||
(**328440206208**: primary baseline in **us-east-1**, secondary-region
|
||||
baselines in **us-east-2**/**us-west-2**, offsite backup vault in
|
||||
**us-west-2**) and org **member accounts** (first tenant:
|
||||
`seahaven-external-dev` **396287094661**, absorbed from the retired
|
||||
`seahaven-external-dev-baseline` repo). This is where account-wide detective
|
||||
and recovery controls live, so they are versioned, reviewed, and drift-checked
|
||||
like any other stack.
|
||||
|
||||
Stacks (all deployed by `cdk deploy --all` / the CD workflow):
|
||||
> **History:** this repo was `seahaven-account-baseline` (management account
|
||||
> only) until 2026-07-14, when the external-dev member baseline was merged in
|
||||
> and the repo renamed. Deployed CloudFormation stack names are unchanged.
|
||||
|
||||
| Stack | Region | Purpose |
|
||||
|---|---|---|
|
||||
| `seahaven-account-baseline` | us-east-1 | CloudTrail + future detective controls (C-1) |
|
||||
| `seahaven-dynamodb-cmk` | us-east-1 | Shared customer-managed KMS key for finance/PII DynamoDB tables; ARN published to SSM `/seahaven/dynamodb/cmk-arn` (INFRA-95 / M-3) |
|
||||
| `seahaven-regional-baseline-us-west-2` | us-west-2 | Bedrock invocation logging (INFRA-91) |
|
||||
| `seahaven-regional-baseline-us-east-2` | us-east-2 | Bedrock invocation logging + AWS Config recorder + Security Hub (INFRA-91 / INFRA-16) |
|
||||
| `seahaven-backup` | us-east-1 | Primary AWS Backup vault + plan + role (C-7) |
|
||||
| `seahaven-backup-offsite` | us-west-2 | Governance-locked offsite copy vault (C-7) |
|
||||
Stacks (deployed by the CD workflow — one job per target account):
|
||||
|
||||
| Stack | Account | Region | Purpose |
|
||||
|---|---|---|---|
|
||||
| `seahaven-account-baseline` | 328440206208 | us-east-1 | CloudTrail + detective controls (C-1) |
|
||||
| `seahaven-dynamodb-cmk` | 328440206208 | us-east-1 | Shared customer-managed KMS key for finance/PII DynamoDB tables; ARN published to SSM `/seahaven/dynamodb/cmk-arn` (INFRA-95 / M-3) |
|
||||
| `seahaven-regional-baseline-us-west-2` | 328440206208 | us-west-2 | Bedrock invocation logging (INFRA-91) |
|
||||
| `seahaven-regional-baseline-us-east-2` | 328440206208 | us-east-2 | Bedrock invocation logging + AWS Config recorder + Security Hub (INFRA-91 / INFRA-16) |
|
||||
| `seahaven-backup` | 328440206208 | us-east-1 | Primary AWS Backup vault + plan + role (C-7) |
|
||||
| `seahaven-backup-offsite` | 328440206208 | us-west-2 | Governance-locked offsite copy vault (C-7) |
|
||||
| `seahaven-external-dev-baseline` | 396287094661 | us-east-1 | Member-account baseline: Config, GuardDuty, Security Hub (FSBP + CIS v3.0), Access Analyzer, flow logs, budget |
|
||||
|
||||
## CDK app
|
||||
|
||||
|
|
@ -38,16 +46,26 @@ the TypeScript source — no separate compile step needed for `cdk synth` /
|
|||
| `tsconfig.json` | TypeScript compiler options (`outDir: cdk.out`) |
|
||||
| `package.json` | Pinned `aws-cdk-lib`, CDK CLI, and the `build` / `synth` / `diff` / `deploy` npm scripts |
|
||||
|
||||
`bin/app.ts` synthesizes six stacks across three regions:
|
||||
`bin/app.ts` synthesizes seven stacks across three regions and two accounts:
|
||||
|
||||
| Construct id | Stack name | Region | Source |
|
||||
|---|---|---|---|
|
||||
| `account-baseline` | `seahaven-account-baseline` | us-east-1 | `lib/account-baseline-stack.ts` |
|
||||
| `dynamodb-cmk` | `seahaven-dynamodb-cmk` | us-east-1 | `lib/dynamodb-cmk-stack.ts` |
|
||||
| `regional-baseline-us-west-2` | `seahaven-regional-baseline-us-west-2` | us-west-2 | `lib/regional-baseline-stack.ts` |
|
||||
| `regional-baseline-us-east-2` | `seahaven-regional-baseline-us-east-2` | us-east-2 | `lib/regional-baseline-stack.ts` |
|
||||
| `backup-offsite` | `seahaven-backup-offsite` | us-west-2 | `lib/backup-offsite-stack.ts` |
|
||||
| `backup` | `seahaven-backup` | us-east-1 | `lib/backup-stack.ts` |
|
||||
| Construct id | Stack name | Account | Region | Source |
|
||||
|---|---|---|---|---|
|
||||
| `account-baseline` | `seahaven-account-baseline` | 328440206208 | us-east-1 | `lib/account-baseline-stack.ts` |
|
||||
| `dynamodb-cmk` | `seahaven-dynamodb-cmk` | 328440206208 | us-east-1 | `lib/dynamodb-cmk-stack.ts` |
|
||||
| `regional-baseline-us-west-2` | `seahaven-regional-baseline-us-west-2` | 328440206208 | us-west-2 | `lib/regional-baseline-stack.ts` |
|
||||
| `regional-baseline-us-east-2` | `seahaven-regional-baseline-us-east-2` | 328440206208 | us-east-2 | `lib/regional-baseline-stack.ts` |
|
||||
| `backup-offsite` | `seahaven-backup-offsite` | 328440206208 | us-west-2 | `lib/backup-offsite-stack.ts` |
|
||||
| `backup` | `seahaven-backup` | 328440206208 | us-east-1 | `lib/backup-stack.ts` |
|
||||
| `external-dev-baseline` | `seahaven-external-dev-baseline` | 396287094661 | us-east-1 | `lib/member-baseline-stack.ts` |
|
||||
|
||||
The member-account stack (`external-dev-baseline`) deploys with credentials for
|
||||
**396287094661** — the CD workflow runs it as a separate job assuming that
|
||||
account's OIDC deploy role (`githubdeploy-seahaven-external-dev-baseline`,
|
||||
repo secret `AWS_DEPLOY_ROLE_ARN_EXTDEV`). Local deploys/diffs of that stack
|
||||
assume `OrganizationAccountAccessRole` in 396287094661. Its shared constructs
|
||||
(`DetectiveControls`, `FlowLogs`, `GovernanceToggles`) are prefix-parameterized
|
||||
(`seahaven` vs `seahaven-extdev`) — construct ids and physical names must stay
|
||||
byte-identical to the deployed stack (logical IDs are path-derived).
|
||||
|
||||
`backup` declares an explicit dependency on `backup-offsite` so the offsite copy
|
||||
vault exists before the primary plan that copies into it. Stack names are set
|
||||
|
|
|
|||
|
|
@ -1,5 +1,5 @@
|
|||
{
|
||||
"name": "seahaven-account-baseline",
|
||||
"name": "seahaven-org-baseline",
|
||||
"version": "1.0.0",
|
||||
"bin": {
|
||||
"app": "bin/app.js"
|
||||
|
|
|
|||
Loading…
Add table
Reference in a new issue