From e2bbf5ec758ea272bd8703c11a2f5e4a303f15bd Mon Sep 17 00:00:00 2001 From: Adam Moussa Date: Tue, 14 Jul 2026 13:27:38 -0400 Subject: [PATCH] Rename package to seahaven-org-baseline Prepares the repo rename: the app now spans the management account and org member accounts, so 'account-baseline' undersells the scope. README documents the two-account deploy topology and logical-ID constraints. --- README.md | 70 +++++++++++++++++++++++++++++++++------------------- package.json | 2 +- 2 files changed, 45 insertions(+), 27 deletions(-) diff --git a/README.md b/README.md index b5c7e7f..21cd8ea 100644 --- a/README.md +++ b/README.md @@ -1,26 +1,34 @@ -# seahaven-account-baseline +# seahaven-org-baseline ![TypeScript](https://img.shields.io/badge/TypeScript-3178C6?logo=typescript&logoColor=white) ![AWS CDK](https://img.shields.io/badge/AWS-CDK-FF9900?logo=amazonaws&logoColor=white) -![CI](https://github.com/Sea-Haven-Industries/seahaven-account-baseline/actions/workflows/ci.yaml/badge.svg) +![CI](https://github.com/Sea-Haven-Industries/seahaven-org-baseline/actions/workflows/ci.yaml/badge.svg) -Account-level security and governance baseline for Sea Haven Industries -(AWS account **328440206208**), managed as a single CDK TypeScript app. The -primary baseline is in **us-east-1**, with secondary-region baselines in -**us-east-2** and **us-west-2** and the offsite backup vault in **us-west-2**. -This is where account-wide detective and recovery controls live, so they are -versioned, reviewed, and drift-checked like any other stack. +Organization-wide security and governance baseline for Sea Haven Industries, +managed as a single CDK TypeScript app. Covers the management account +(**328440206208**: primary baseline in **us-east-1**, secondary-region +baselines in **us-east-2**/**us-west-2**, offsite backup vault in +**us-west-2**) and org **member accounts** (first tenant: +`seahaven-external-dev` **396287094661**, absorbed from the retired +`seahaven-external-dev-baseline` repo). This is where account-wide detective +and recovery controls live, so they are versioned, reviewed, and drift-checked +like any other stack. -Stacks (all deployed by `cdk deploy --all` / the CD workflow): +> **History:** this repo was `seahaven-account-baseline` (management account +> only) until 2026-07-14, when the external-dev member baseline was merged in +> and the repo renamed. Deployed CloudFormation stack names are unchanged. -| Stack | Region | Purpose | -|---|---|---| -| `seahaven-account-baseline` | us-east-1 | CloudTrail + future detective controls (C-1) | -| `seahaven-dynamodb-cmk` | us-east-1 | Shared customer-managed KMS key for finance/PII DynamoDB tables; ARN published to SSM `/seahaven/dynamodb/cmk-arn` (INFRA-95 / M-3) | -| `seahaven-regional-baseline-us-west-2` | us-west-2 | Bedrock invocation logging (INFRA-91) | -| `seahaven-regional-baseline-us-east-2` | us-east-2 | Bedrock invocation logging + AWS Config recorder + Security Hub (INFRA-91 / INFRA-16) | -| `seahaven-backup` | us-east-1 | Primary AWS Backup vault + plan + role (C-7) | -| `seahaven-backup-offsite` | us-west-2 | Governance-locked offsite copy vault (C-7) | +Stacks (deployed by the CD workflow — one job per target account): + +| Stack | Account | Region | Purpose | +|---|---|---|---| +| `seahaven-account-baseline` | 328440206208 | us-east-1 | CloudTrail + detective controls (C-1) | +| `seahaven-dynamodb-cmk` | 328440206208 | us-east-1 | Shared customer-managed KMS key for finance/PII DynamoDB tables; ARN published to SSM `/seahaven/dynamodb/cmk-arn` (INFRA-95 / M-3) | +| `seahaven-regional-baseline-us-west-2` | 328440206208 | us-west-2 | Bedrock invocation logging (INFRA-91) | +| `seahaven-regional-baseline-us-east-2` | 328440206208 | us-east-2 | Bedrock invocation logging + AWS Config recorder + Security Hub (INFRA-91 / INFRA-16) | +| `seahaven-backup` | 328440206208 | us-east-1 | Primary AWS Backup vault + plan + role (C-7) | +| `seahaven-backup-offsite` | 328440206208 | us-west-2 | Governance-locked offsite copy vault (C-7) | +| `seahaven-external-dev-baseline` | 396287094661 | us-east-1 | Member-account baseline: Config, GuardDuty, Security Hub (FSBP + CIS v3.0), Access Analyzer, flow logs, budget | ## CDK app @@ -38,16 +46,26 @@ the TypeScript source — no separate compile step needed for `cdk synth` / | `tsconfig.json` | TypeScript compiler options (`outDir: cdk.out`) | | `package.json` | Pinned `aws-cdk-lib`, CDK CLI, and the `build` / `synth` / `diff` / `deploy` npm scripts | -`bin/app.ts` synthesizes six stacks across three regions: +`bin/app.ts` synthesizes seven stacks across three regions and two accounts: -| Construct id | Stack name | Region | Source | -|---|---|---|---| -| `account-baseline` | `seahaven-account-baseline` | us-east-1 | `lib/account-baseline-stack.ts` | -| `dynamodb-cmk` | `seahaven-dynamodb-cmk` | us-east-1 | `lib/dynamodb-cmk-stack.ts` | -| `regional-baseline-us-west-2` | `seahaven-regional-baseline-us-west-2` | us-west-2 | `lib/regional-baseline-stack.ts` | -| `regional-baseline-us-east-2` | `seahaven-regional-baseline-us-east-2` | us-east-2 | `lib/regional-baseline-stack.ts` | -| `backup-offsite` | `seahaven-backup-offsite` | us-west-2 | `lib/backup-offsite-stack.ts` | -| `backup` | `seahaven-backup` | us-east-1 | `lib/backup-stack.ts` | +| Construct id | Stack name | Account | Region | Source | +|---|---|---|---|---| +| `account-baseline` | `seahaven-account-baseline` | 328440206208 | us-east-1 | `lib/account-baseline-stack.ts` | +| `dynamodb-cmk` | `seahaven-dynamodb-cmk` | 328440206208 | us-east-1 | `lib/dynamodb-cmk-stack.ts` | +| `regional-baseline-us-west-2` | `seahaven-regional-baseline-us-west-2` | 328440206208 | us-west-2 | `lib/regional-baseline-stack.ts` | +| `regional-baseline-us-east-2` | `seahaven-regional-baseline-us-east-2` | 328440206208 | us-east-2 | `lib/regional-baseline-stack.ts` | +| `backup-offsite` | `seahaven-backup-offsite` | 328440206208 | us-west-2 | `lib/backup-offsite-stack.ts` | +| `backup` | `seahaven-backup` | 328440206208 | us-east-1 | `lib/backup-stack.ts` | +| `external-dev-baseline` | `seahaven-external-dev-baseline` | 396287094661 | us-east-1 | `lib/member-baseline-stack.ts` | + +The member-account stack (`external-dev-baseline`) deploys with credentials for +**396287094661** — the CD workflow runs it as a separate job assuming that +account's OIDC deploy role (`githubdeploy-seahaven-external-dev-baseline`, +repo secret `AWS_DEPLOY_ROLE_ARN_EXTDEV`). Local deploys/diffs of that stack +assume `OrganizationAccountAccessRole` in 396287094661. Its shared constructs +(`DetectiveControls`, `FlowLogs`, `GovernanceToggles`) are prefix-parameterized +(`seahaven` vs `seahaven-extdev`) — construct ids and physical names must stay +byte-identical to the deployed stack (logical IDs are path-derived). `backup` declares an explicit dependency on `backup-offsite` so the offsite copy vault exists before the primary plan that copies into it. Stack names are set diff --git a/package.json b/package.json index 07f95e6..7ec5b7e 100644 --- a/package.json +++ b/package.json @@ -1,5 +1,5 @@ { - "name": "seahaven-account-baseline", + "name": "seahaven-org-baseline", "version": "1.0.0", "bin": { "app": "bin/app.js"