Complete stack table in README (#42)

The intro summary table listed only 3 of the 6 stacks that bin/app.ts
synthesizes, omitting seahaven-dynamodb-cmk and the two secondary-region
baselines. Bring it in line with the detailed CDK-app table and fix the
region summary sentence.
This commit is contained in:
Adam Moussa 2026-07-10 16:22:58 -04:00 • committed by GitHub
parent 3ee66ef63b
commit fd6fa5518b
No known key found for this signature in database
GPG key ID: B5690EEEBB952194

View file

@ -5,8 +5,9 @@
![CI](https://github.com/Sea-Haven-Industries/seahaven-account-baseline/actions/workflows/ci.yaml/badge.svg)
Account-level security and governance baseline for Sea Haven Industries
(AWS account **328440206208**), managed as a single CDK TypeScript app. Most
resources are in **us-east-1**; the offsite backup vault is in **us-west-2**.
(AWS account **328440206208**), managed as a single CDK TypeScript app. The
primary baseline is in **us-east-1**, with secondary-region baselines in
**us-east-2** and **us-west-2** and the offsite backup vault in **us-west-2**.
This is where account-wide detective and recovery controls live, so they are
versioned, reviewed, and drift-checked like any other stack.
@ -15,6 +16,9 @@ Stacks (all deployed by `cdk deploy --all` / the CD workflow):
| Stack | Region | Purpose |
|---|---|---|
| `seahaven-account-baseline` | us-east-1 | CloudTrail + future detective controls (C-1) |
| `seahaven-dynamodb-cmk` | us-east-1 | Shared customer-managed KMS key for finance/PII DynamoDB tables; ARN published to SSM `/seahaven/dynamodb/cmk-arn` (INFRA-95 / M-3) |
| `seahaven-regional-baseline-us-west-2` | us-west-2 | Bedrock invocation logging (INFRA-91) |
| `seahaven-regional-baseline-us-east-2` | us-east-2 | Bedrock invocation logging + AWS Config recorder + Security Hub (INFRA-91 / INFRA-16) |
| `seahaven-backup` | us-east-1 | Primary AWS Backup vault + plan + role (C-7) |
| `seahaven-backup-offsite` | us-west-2 | Governance-locked offsite copy vault (C-7) |