From fd6fa5518b2ec595f7ac6c18a12e89d02c548366 Mon Sep 17 00:00:00 2001 From: Adam Moussa <166072409+amoussa1229@users.noreply.github.com> Date: Fri, 10 Jul 2026 16:22:58 -0400 Subject: [PATCH] Complete stack table in README (#42) The intro summary table listed only 3 of the 6 stacks that bin/app.ts synthesizes, omitting seahaven-dynamodb-cmk and the two secondary-region baselines. Bring it in line with the detailed CDK-app table and fix the region summary sentence. --- README.md | 8 ++++++-- 1 file changed, 6 insertions(+), 2 deletions(-) diff --git a/README.md b/README.md index 83c73f2..b5c7e7f 100644 --- a/README.md +++ b/README.md @@ -5,8 +5,9 @@ ![CI](https://github.com/Sea-Haven-Industries/seahaven-account-baseline/actions/workflows/ci.yaml/badge.svg) Account-level security and governance baseline for Sea Haven Industries -(AWS account **328440206208**), managed as a single CDK TypeScript app. Most -resources are in **us-east-1**; the offsite backup vault is in **us-west-2**. +(AWS account **328440206208**), managed as a single CDK TypeScript app. The +primary baseline is in **us-east-1**, with secondary-region baselines in +**us-east-2** and **us-west-2** and the offsite backup vault in **us-west-2**. This is where account-wide detective and recovery controls live, so they are versioned, reviewed, and drift-checked like any other stack. @@ -15,6 +16,9 @@ Stacks (all deployed by `cdk deploy --all` / the CD workflow): | Stack | Region | Purpose | |---|---|---| | `seahaven-account-baseline` | us-east-1 | CloudTrail + future detective controls (C-1) | +| `seahaven-dynamodb-cmk` | us-east-1 | Shared customer-managed KMS key for finance/PII DynamoDB tables; ARN published to SSM `/seahaven/dynamodb/cmk-arn` (INFRA-95 / M-3) | +| `seahaven-regional-baseline-us-west-2` | us-west-2 | Bedrock invocation logging (INFRA-91) | +| `seahaven-regional-baseline-us-east-2` | us-east-2 | Bedrock invocation logging + AWS Config recorder + Security Hub (INFRA-91 / INFRA-16) | | `seahaven-backup` | us-east-1 | Primary AWS Backup vault + plan + role (C-7) | | `seahaven-backup-offsite` | us-west-2 | Governance-locked offsite copy vault (C-7) |