Commit graph

61 commits

Author SHA1 Message Date
Adam Moussa
9c1d083f3f
Merge pull request #63 from Sea-Haven-Industries/fix/deploy-substrate-deny-self-mutation
Some checks are pending
Deploy / deploy-management (push) Waiting to run
Deploy / deploy-external-dev (push) Waiting to run
Deploy / deploy-security (push) Waiting to run
Deploy / deploy-dev (push) Waiting to run
Deploy / deploy-prod (push) Waiting to run
fix(iam): port DenySelfMutation into the prod/dev deploy substrate
2026-07-27 19:09:08 -04:00
61a94da4fc
fix(iam): reconcile the remaining substrate divergences from the mgmt copy
Review of the DenySelfMutation port found the header's 'reconciled' claim
was not yet true: mgmt Phase A also added the CloudWatch Logs
metric-filter actions (afterhours-shift-manager creates an
AWS::Logs::MetricFilter through this role), and without them a migrating
SAM stack fails mid-deploy with AccessDenied. Ports those three actions
and corrects two stale header notes. Every IAM statement in the three
shared resources is now byte-identical across both files, verified
programmatically; the only delta left is the DependsOn ordering line.
2026-07-27 18:55:10 -04:00
62f6a76e6c
fix(iam): port DenySelfMutation self-protection into the prod/dev deploy substrate
The seahaven-cfn-exec-iam-management policy in prod and dev carried only
DenyBoundaryTampering + DenyBoundaryPolicyEdit: the mgmt Phase A review
later showed a Deny-in-a-managed-policy control is self-detachable
(iam:DetachRolePolicy on * is unconditioned), so without DenySelfMutation
the exec role can detach the very policy carrying the Denies and
reinstate the boundary-removal escalation. Latent today (no PassRole
grants, zero SAM stacks in prod/dev) but must be closed before the first
SAM workload migrates.

Ports verbatim from .github/oidc-deploy-roles.yaml (mgmt, PRs #95/#98):
- DenySelfMutation over role/github-cfn-execution-role + githubdeploy-*
- DenyBoundaryPolicyEdit widened to policy/seahaven-*

Statement set verified byte-identical to the mgmt copy (9 sids);
provenance header updated - the two copies are reconciled.
2026-07-27 18:37:39 -04:00
Adam Moussa
ea2224e326
Merge pull request #62 from Sea-Haven-Industries/fix/cfn-exec-role-policy-size
Some checks are pending
Deploy / deploy-management (push) Waiting to run
Deploy / deploy-external-dev (push) Waiting to run
Deploy / deploy-security (push) Waiting to run
Deploy / deploy-dev (push) Waiting to run
Deploy / deploy-prod (push) Waiting to run
fix(deploy-substrate): move boundary-gated IAM policy off the role's inline budget
2026-07-27 16:45:29 -04:00
2cfc122269
fix(deploy-substrate): move boundary-gated IAM policy off the role's inline budget
The first deploy of seahaven-deploy-substrate failed in both prod and dev
with ServiceLimitExceeded: 'Maximum policy size of 10240 bytes exceeded
for role github-cfn-execution-role'. The role's inline policies already
sat ~94 bytes under IAM's hard 10,240-byte per-role limit, so the two
Deny statements added to close the boundary-removal escalation did not
fit (10,656 total).

Moves the whole boundary-gated IAM block (6 Allow + 2 Deny statements)
into an attached managed policy, which carries its own separate
6,144-byte budget. Inline drops to 8,285 with ~1.9 KB of headroom;
the managed policy sits at 2,371.

Effective permissions are unchanged: the union of role statements
(inline + attached) is byte-identical as a sorted set before and after
the move (27 statements both sides), identity policies are unioned, and
an explicit Deny still wins. Boundary and trust policy untouched.

Both failed stacks rolled back cleanly with zero orphaned resources and
were deleted before this retry.
2026-07-27 16:43:15 -04:00
Adam Moussa
e898cb6342
Merge pull request #61 from Sea-Haven-Industries/feat/deploy-substrate-stacks
feat(deploy-substrate): per-account GitHub Actions deploy substrate for prod/dev
2026-07-27 16:35:00 -04:00
d6bea33436
feat(deploy-substrate): per-account GitHub Actions deploy substrate for prod/dev
SAM repos migrating off the frozen management account need the shared
deploy plumbing (permissions boundary + github-cfn-execution-role) in
their target account; none of it existed outside mgmt, so there was no
OIDC SAM deploy path into seahaven-prod or seahaven-dev at all.

Adds a templated, per-account substrate stack so onboarding a future
account is one bin/app.ts instance plus one CD job, not a hand-rolled
copy. Per-repo githubdeploy-* roles stay out by design: they are
provisioned per repo at migration time so an account never accumulates
trust for repos that do not deploy to it.

The template is a verbatim extraction of the reviewed mgmt substrate,
with deliberate, documented divergences — notably the removal of
iam:DeleteRolePermissionsBoundary plus explicit Deny backstops, which
closes a confirmed privilege-escalation path (see PR body).
2026-07-27 16:24:09 -04:00
dependabot[bot]
dd552bff4d
build(deps): bump the minor-and-patch group with 3 updates (#60)
Some checks failed
Deploy / deploy-management (push) Has been cancelled
Deploy / deploy-external-dev (push) Has been cancelled
Deploy / deploy-security (push) Has been cancelled
Deploy / deploy-dev (push) Has been cancelled
Deploy / deploy-prod (push) Has been cancelled
Bumps the minor-and-patch group with 3 updates: [aws-cdk-lib](https://github.com/aws/aws-cdk/tree/HEAD/packages/aws-cdk-lib), [constructs](https://github.com/aws/constructs) and [aws-cdk](https://github.com/aws/aws-cdk-cli/tree/HEAD/packages/aws-cdk).


Updates `aws-cdk-lib` from 2.262.0 to 2.262.1
- [Release notes](https://github.com/aws/aws-cdk/releases)
- [Changelog](https://github.com/aws/aws-cdk/blob/main/CHANGELOG.v2.alpha.md)
- [Commits](https://github.com/aws/aws-cdk/commits/v2.262.1/packages/aws-cdk-lib)

Updates `constructs` from 10.7.0 to 10.7.1
- [Release notes](https://github.com/aws/constructs/releases)
- [Commits](https://github.com/aws/constructs/compare/v10.7.0...v10.7.1)

Updates `aws-cdk` from 2.1132.0 to 2.1133.0
- [Release notes](https://github.com/aws/aws-cdk-cli/releases)
- [Commits](https://github.com/aws/aws-cdk-cli/commits/aws-cdk@v2.1133.0/packages/aws-cdk)

---
updated-dependencies:
- dependency-name: aws-cdk-lib
  dependency-version: 2.262.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: constructs
  dependency-version: 10.7.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: aws-cdk
  dependency-version: 2.1133.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-24 18:50:31 -04:00
Adam Moussa
7cce026f4a
chore: drop deleted tables from Phase2 backup selection (#59)
Some checks are pending
Deploy / deploy-management (push) Waiting to run
Deploy / deploy-external-dev (push) Waiting to run
Deploy / deploy-security (push) Waiting to run
Deploy / deploy-dev (push) Waiting to run
Deploy / deploy-prod (push) Waiting to run
seahaven-conversations + seahaven-unanswered-questions (seahaven-slack-bot
teardown 2026-07-23), exec-aide (decommissioned 2026-07-10), and
internal-portal-data (internal-portal decommission) no longer exist;
their backup selections would fail nightly.
2026-07-23 16:21:04 -04:00
Adam Moussa
5d7ca83097
fix(scp): exempt chatbot:* from workloads-region-lock (global service, us-east-2 control plane) (#58)
AWS Chatbot's control-plane API is homed in us-east-2, so every chatbot call
carries aws:RequestedRegion=us-east-2 and is denied by the workloads-region-lock
region deny (approved set = us-east-1/us-west-2). This blocked Slack
workspace/channel setup in seahaven-prod (chatbot:GetSlackOauthParameters
denied), which the prod site-alerts topic needs for Slack delivery. Adds
chatbot:* to the SCP's global-service NotAction exemption list alongside
iam/organizations/cloudfront/route53 — a region-agnostic full-prefix exemption,
the same shape as the other global services. targetIds unchanged (workloads OU);
regional services (s3/kms/logs) and the Bedrock carve-out untouched.

GPT-4.1 cross-review: SAFE TO MERGE. /sh-security-review: block=false (0 confirmed
critical/high). Security-OU region-lock deliberately NOT changed (runs no such
workloads, same asymmetry as its missing Bedrock carve-out).
2026-07-23 15:47:11 -04:00
Adam Moussa
4d3c846b88
feat(prod): seahaven-prod DynamoDB CMK + site-alerts alarm topic (procurement-ingest migration Phase 0a) (#57)
* feat(prod): add seahaven-prod DynamoDB CMK and site-alerts alarm-topic stacks

Provisions the two shared dependencies procurement-ingest imports by name,
ahead of its migration from mgmt to seahaven-prod:

- dynamodb-cmk-prod: second DynamoDbCmkStack instance (same stack name,
  prod account) creating alias/seahaven-dynamodb + the
  /seahaven/dynamodb/cmk-arn SSM param. Adds a cross-account key-policy
  statement so the mgmt seahaven-slack-bot roles can keep reading the
  CMK-encrypted purchase-orders table after it moves (ViaService +
  PrincipalArn-wildcard scoped; identity-policy half lands in the
  slack-bot repo's cutover PR).
- alarm-topic-prod: codified site-alerts SNS topic + seahaven-alarm-topics
  CMK with the cloudwatch.amazonaws.com publish grant (mirrors the working
  mgmt pattern; mgmt's topic remains CLI-managed debt).
- deploy.yaml: both appended to the deploy-prod job's explicit stack list
  (SH-ORG-005 rule: unlisted stacks silently never deploy).

* fix(scripts): account-id assertion in cfn-stack-decommission; complete the aws-cdk-lib 2.262.0 bump (patched brace-expansion); document CMK cutover trap

- cfn-stack-decommission.sh: --account-id is now REQUIRED and asserted
  against sts get-caller-identity before anything runs. Stack names are no
  longer org-unique (seahaven-dynamodb-cmk now exists in mgmt AND prod), so
  a name-only lookup under the wrong ambient profile could report or delete
  the wrong account's stack (security-review LOGIC-001).
- package.json/lock: PR #56's bump-for-patched-brace-expansion landed the
  commit title but not the pin; package.json still said 2.261.0 and the
  lockfile still resolved brace-expansion 5.0.6 (GHSA-3jxr-9vmj-r5cp HIGH,
  blocking the pre-commit scanner). Pin 2.262.0 and regenerate; npm audit
  now clean.
- bin/app.ts comments: slack-bot cutover MUST grant the PROD key ARN, never
  the account-local mgmt SSM param (LOGIC-005); failed-first-create orphan
  CMK recovery note (LOGIC-004).

* refactor(prod): drop cross-account CMK grant (slack-bot decommissioned 2026-07-23)

The AllowMgmtSlackBotReadViaDynamoDb key-policy statement targeted the
seahaven-slack-bot roles, which were decommissioned 2026-07-23. Its successor
sh-mcp is undeployed and uses same-account DynamoDB access, so no cross-account
reader of the CMK-encrypted purchase-orders table exists. The prod CMK + SSM
param + alarm-topic stacks remain (procurement-ingest still imports them). Add
a scoped cross-account grant if/when a real cross-account consumer deploys.
2026-07-23 15:29:55 -04:00
Adam Moussa
cc54b1e28b
chore(security): add explicit workflow permissions and bump aws-cdk-lib to 2.262.0 (#56)
Some checks are pending
Deploy / deploy-management (push) Waiting to run
Deploy / deploy-external-dev (push) Waiting to run
Deploy / deploy-security (push) Waiting to run
Deploy / deploy-dev (push) Waiting to run
Deploy / deploy-prod (push) Waiting to run
* docs: update aws profile specified in script (local renaming)

* ci: add least-privilege permissions blocks to workflow callers

Resolves code scanning alerts #3 and #4 (actions/missing-workflow-permissions). Both callable workflows only need contents: read; the dependency-review callable already declares it internally, this caps the caller token to match."

* chore(deps): bump aws-cdk-lib to 2.262.0 for patched brace-expansion

Resolves Dependabot alert #4 (CVE-2026-13149, exponential-time DoS in brace-expansion expand()). The vulnerable 5.0.6 is a bundled dependency inside the aws-cdk-lib tarball, so it cannot be updated independently; 2.262.0 bundles the patched 5.0.7.

Also migrates Stack#addDependency to addStackDependency (deprecated in this release) in bin/app.ts.
2026-07-23 17:38:17 +00:00
dependabot[bot]
6041abbd23
build(deps): bump the minor-and-patch group with 3 updates (#55)
Some checks failed
Deploy / deploy-management (push) Has been cancelled
Deploy / deploy-external-dev (push) Has been cancelled
Deploy / deploy-security (push) Has been cancelled
Deploy / deploy-dev (push) Has been cancelled
Deploy / deploy-prod (push) Has been cancelled
Bumps the minor-and-patch group with 3 updates: [constructs](https://github.com/aws/constructs), [aws-cdk](https://github.com/aws/aws-cdk-cli/tree/HEAD/packages/aws-cdk) and [tsx](https://github.com/privatenumber/tsx).


Updates `constructs` from 10.6.0 to 10.7.0
- [Release notes](https://github.com/aws/constructs/releases)
- [Commits](https://github.com/aws/constructs/compare/v10.6.0...v10.7.0)

Updates `aws-cdk` from 2.1130.0 to 2.1132.0
- [Release notes](https://github.com/aws/aws-cdk-cli/releases)
- [Commits](https://github.com/aws/aws-cdk-cli/commits/aws-cdk@v2.1132.0/packages/aws-cdk)

Updates `tsx` from 4.23.0 to 4.23.1
- [Release notes](https://github.com/privatenumber/tsx/releases)
- [Changelog](https://github.com/privatenumber/tsx/blob/master/release.config.cjs)
- [Commits](https://github.com/privatenumber/tsx/compare/v4.23.0...v4.23.1)

---
updated-dependencies:
- dependency-name: constructs
  dependency-version: 10.7.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: aws-cdk
  dependency-version: 2.1132.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: tsx
  dependency-version: 4.23.1
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-17 18:42:15 -04:00
seahaven-openswe[bot]
88fa5777d1
fix(scp): carve out Bedrock InvokeModel/Converse to us-east-2 for cross-region inference (#54)
Some checks failed
Deploy / deploy-management (push) Has been cancelled
Deploy / deploy-external-dev (push) Has been cancelled
Deploy / deploy-security (push) Has been cancelled
Deploy / deploy-dev (push) Has been cancelled
Deploy / deploy-prod (push) Has been cancelled
* fix(scp): carve out Bedrock InvokeModel/Converse to us-east-2 for cross-region inference

Add bedrock:InvokeModel, bedrock:InvokeModelWithResponseStream,
bedrock:Converse, and bedrock:ConverseStream to the existing
DenyRegionsOutsideApproved NotAction list so the us-east-1/us-west-2
region condition no longer denies them. Add a companion
DenyBedrockInvokeOutsideInference statement that re-denies those same
four actions outside {us-east-1, us-west-2, us-east-2}, bounding the
carve-out to us-east-2 only.

Without this, Anthropic cross-region inference profiles (us.anthropic.*)
that route InvokeModel to us-east-2 are denied, blocking all Claude
generation in workload accounts.

Refs: #53

* fix: add ACCEPTED RISK disposition, hoist Bedrock actions to shared const, mark security-asymmetry

- ACCEPTED RISK: Bedrock carve-out is resource-unscoped (NotAction
  can't be resource-scoped); us-east-2 window admits four actions
  against any Bedrock resource. Per-account IAM and model-access
  enablement gate actual access.
- Hoist the four Bedrock invoke actions into BEDROCK_INVOKE_ACTIONS
  shared const referenced by both NotAction and DenyBedrockInvoke
  statements to prevent future one-sided edit divergence.
- Mark asymmetry in security-guardrails DenyRegionsOutsideApproved:
  no Bedrock carve-out by design — security account runs no Bedrock
  workloads.

---------

Co-authored-by: amoussa1229 <166072409+amoussa1229@users.noreply.github.com>
2026-07-15 18:52:05 -04:00
Adam Moussa
ed26ff937d
Document centralized root access: README runbook + stack comment updates (#52)
Some checks are pending
Deploy / deploy-management (push) Waiting to run
Deploy / deploy-external-dev (push) Waiting to run
Deploy / deploy-security (push) Waiting to run
Deploy / deploy-dev (push) Waiting to run
Deploy / deploy-prod (push) Waiting to run
Comment/docs only, no template change (synth verified). Records the
2026-07-14 rollout: features enabled, member root credentials deleted,
recovery runbook (manual detach, inheritance + propagation gotchas),
new-account flow superseding root-harden-before-OU-move, extdev 5-SCP
quota saturation.
2026-07-14 18:32:40 -04:00
Adam Moussa
75888e045e
Extend deny-root-user SCP to the external-dev OU (#51)
Extdev root credentials were deleted 2026-07-14 via centralized root
management (four-surface verified), closing the deferred root-hardening
blocker. Root recovery is central (assume-root, drill-proven) plus a
temporary gated detach, so the OU now gets the same root lockout as the
other six.

Gates: GPT-4.1 cross-review APPROVE; /sh-security-review PASS (0 confirmed
critical/high). Note: this attach puts the extdev OU at the 5-SCP hard
quota - future guardrails attach at the account or consolidate.
2026-07-14 18:24:42 -04:00
Adam Moussa
2303a54ebc
seahaven-prod account baseline (Phase 5) (#50)
Some checks are pending
Deploy / deploy-management (push) Waiting to run
Deploy / deploy-external-dev (push) Waiting to run
Deploy / deploy-security (push) Waiting to run
Deploy / deploy-dev (push) Waiting to run
Deploy / deploy-prod (push) Waiting to run
* Add seahaven-prod member baseline (Phase 5)

Account 011934824531 is the target for all new production stacks; the
management account is frozen for new workloads. First proven exercise
of the automatic enrollment sweep (Enabled in 124s, no manual
create-members) and of AutoEnableStandards=NONE (no pre-enabled
standards, so CFN owns FSBP + CIS v3.0 cleanly). Default VPC deleted;
budget starts at $100 and resizes as tenants land.

* Apply Phase-5 review findings

Fleet gap closed: EBS encryption-by-default + IAM password policy were
management-account-only (the runbook's unscoped 'applied' claim hid
it); now applied and verified in all three member accounts, runbook
scoped per account. README stack inventory corrected (eleven stacks,
org-governance rows restored). Sweep comments reconciled: the
automatic enrollment sweep is proven (seahaven-prod, ~2min).
2026-07-14 17:17:55 -04:00
Adam Moussa
0a7c1bc450
seahaven-dev account baseline with org-managed detection (Phase 4) (#49)
* Add seahaven-dev member baseline with org-managed detection

Account 710827005802 (internal dev/staging) is the first account born
after delegation: GuardDuty/Security Hub enroll it via the org admin,
so DetectiveControls gains a localDetectiveServices flag (default true
— zero diff on the three deployed consumers, verified) and the dev
instance sets orgManagedDetection to skip the colliding local
detector/hub/analyzer. Default VPC kept and flow-logged (dev runs real
workloads). Enrollment verified Enabled in both services before this
commit.

* Fix Phase-4 review findings: standards + analyzer stay CFN-owned

SH-DEV-001: org AutoEnableStandards DEFAULT gave dev legacy CIS v1.2.0
and nothing owned CIS v3.0 — org config set to NONE, standards are now
unconditional in DetectiveControls (attach fine to an org-enabled hub),
legacy ruleset disabled in dev. SH-DEVBASE-002: the ORGANIZATION
analyzer treats the whole org as trusted so it cannot flag intra-org
exposure — account analyzer restored unconditionally (coexistence
verified live). Enrollment comments corrected: manual create-members,
the automatic sweep is still unexercised. Zero diff re-verified on all
three deployed baseline stacks.
2026-07-14 16:41:36 -04:00
Adam Moussa
2d3ba94140
Flip delegation runbook to applied with verification evidence (#48)
Some checks are pending
Deploy / deploy-management (push) Waiting to run
Deploy / deploy-external-dev (push) Waiting to run
Deploy / deploy-security (push) Waiting to run
All five services delegated to seahaven-security 2026-07-14 after the
hard preconditions verified (root MFA, OU placement, baseline live).
Member adoption and central findings flow verified end-to-end with a
sample finding; evidence recorded inline per SEC-BASE-A.
2026-07-14 15:53:42 -04:00
Adam Moussa
18f0f40e74
seahaven-security account baseline + security-OU guardrails (Phase 3) (#47)
* Add seahaven-security member baseline (Phase 3)

Account 001520130573 is the org's delegated security administrator.
Same member-baseline construct set as external-dev; own CD job under
its own OIDC role. Created at org root pending manual root hardening
before the OU move (deny-root-user invariant).

* Document delegated security administration runbook

Delegation to seahaven-security has no CloudFormation types; the CLI
sequence is the record, same pattern as the other account toggles.

* Apply Phase-3 security-review findings

Delegation runbook marked PENDING with hard preconditions (baseline
deployed, root MFA verified, account inside the security OU) — it had
read as applied before execution, the org's known claimed-done-but-NOT
failure mode (SEC-BASE-A/B). New security-guardrails SCP on the
security OU: region lock, IAM user/key lockout, privileged-role
protection, delegated-admin membership protection (SEC-BASE-C,
cross-reviewed APPROVE). deploy-security gains stack-name pre-flight
(SEC-BASE-D). Default VPC in 001520130573 deleted; empty flow-log list
and aws@ alert routing documented as deliberate (SEC-BASE-F/H).
2026-07-14 15:32:50 -04:00
Adam Moussa
57fd67324e
Route AWS notifications to dedicated mailboxes (#46)
Some checks are pending
Deploy / deploy-management (push) Waiting to run
Deploy / deploy-external-dev (push) Waiting to run
Budget alerts and CIS alarm subscriptions now go to aws@seahaven.com
(management) and aws-external-dev@seahaven.com (external-dev) instead
of personal addresses (Adam, 2026-07-14; resolves security-review flag
SH-ORG-007). Owner tags are informational and stay decoupled.
2026-07-14 14:41:42 -04:00
Adam Moussa
10e66c92c0
Adopt external-dev OU and its 3 SCPs via resource import (#45)
cdk import by Id (non-mutating), content byte-exact from
describe-policy, targetIds = exact live attachments. Post-import drift
detection: IN_SYNC, 0 drifted. All four Retain — the full org guardrail
set is now drift-checked IaC.
2026-07-14 14:10:10 -04:00
Adam Moussa
22b04c4e75
Org governance: OU skeleton + generalized SCPs (Phase 2) (#44)
Some checks are pending
Deploy / deploy-management (push) Waiting to run
Deploy / deploy-external-dev (push) Waiting to run
* Add org-governance stack: OU skeleton + generalized SCPs

Phase 2 of the multi-account segregation plan: codifies the OU tree
(workloads/prod/nonprod, security, sandbox, graveyard) and three
org-wide SCPs (workloads-region-lock, protect-security-baseline,
deny-root-user) generalized from the proven external-dev guardrails.
All resources Retain — CFN must never detach a live guardrail. New SCPs
attach only to the new empty OUs; extending to external-dev is a
separate gated targetIds change after live verification.

* Record SCP cross-review dispositions in org-governance

Root hardening must precede the OU move (deny-root-user blocks root MFA
enrollment), delegated-admin flows ride service-linked roles that SCPs
never evaluate, and the cdk exec-role exemption is accepted risk
mirroring the external-dev guardrails.

* Add org-governance to the management deploy job

Explicit stack selectors require every new stack to join exactly one
CD job (SH-ORG-005 discipline documented in this file).
2026-07-14 14:02:30 -04:00
Adam Moussa
3ab3bc773a
Merge external-dev member baseline; rename to seahaven-org-baseline (#43)
* Parameterize baseline constructs for multi-account reuse

DetectiveControls, FlowLogs, and GovernanceToggles were forked into
seahaven-external-dev-baseline with only physical-name and VPC-sourcing
differences. Prefix/name props let one implementation serve both
accounts; synthesized templates are unchanged (verified: empty cdk diff
against all deployed stacks).

* Absorb external-dev member baseline stack

Moves seahaven-external-dev-baseline's stack in as MemberBaselineStack,
construct ids and physical names byte-identical to the deployed stack
(logical IDs are path-derived; empty cdk diff verified via change set
against 396287094661). Retires the forked repo so member-account
baselines share one drift surface and one dependency pin.

* Rename package to seahaven-org-baseline

Prepares the repo rename: the app now spans the management account and
org member accounts, so 'account-baseline' undersells the scope. README
documents the two-account deploy topology and logical-ID constraints.

* Commit extdev flow-log VPC ids in code, not -c context

Security review SH-ORG-004 (confirmed high): with the ids sourced from
ephemeral cdk context, any context-less deploy silently removes every
flow log in the isolated account. A committed list makes the attachment
set reviewable and immune to a forgotten -c flag. Empty list matches
the deployed stack (zero diff).

* Split CD into per-account deploy jobs

The app now spans two AWS accounts; cdk deploy --all under one role
fails on the other account's stacks (security review IAC-01). Each job
passes explicit stack selectors and its own account's OIDC role via the
new cd-cdk stacks input.
2026-07-14 13:53:07 -04:00
dependabot[bot]
f3c37d5b20
build(deps-dev): bump the minor-and-patch group with 2 updates (#40)
Some checks failed
Deploy / deploy (push) Has been cancelled
Bumps the minor-and-patch group with 2 updates: [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node) and [aws-cdk](https://github.com/aws/aws-cdk-cli/tree/HEAD/packages/aws-cdk).


Updates `@types/node` from 24.13.2 to 24.13.3
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases)
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node)

Updates `aws-cdk` from 2.1129.0 to 2.1130.0
- [Release notes](https://github.com/aws/aws-cdk-cli/releases)
- [Commits](https://github.com/aws/aws-cdk-cli/commits/aws-cdk@v2.1130.0/packages/aws-cdk)

---
updated-dependencies:
- dependency-name: "@types/node"
  dependency-version: 24.13.3
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: aws-cdk
  dependency-version: 2.1130.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Adam Moussa <166072409+amoussa1229@users.noreply.github.com>
2026-07-10 20:23:49 +00:00
Adam Moussa
fd6fa5518b
Complete stack table in README (#42)
The intro summary table listed only 3 of the 6 stacks that bin/app.ts
synthesizes, omitting seahaven-dynamodb-cmk and the two secondary-region
baselines. Bring it in line with the detailed CDK-app table and fix the
region summary sentence.
2026-07-10 16:22:58 -04:00
Adam Moussa
3ee66ef63b
Document CDK app structure and cdk.json in README (#41)
The README covered what the stacks deploy but never documented the
CDK app itself — the cdk.json config, the bin/app.ts entry point, or
the full set of stacks it synthesizes (only three of six were listed).
Add a CDK app section mapping cdk.json, bin/, and lib/ to their roles,
listing all six stacks with their names/regions/source files, and the
common build/synth/deploy commands.
2026-07-10 16:07:20 -04:00
Adam Moussa
46394f7c75
build(deps): migrate CDK app ts-node->tsx, adopt typescript 7 (INFRA-183) (#39)
Some checks failed
Deploy / deploy (push) Has been cancelled
ts-node 10.x is incompatible with the TypeScript 7 compiler API (cdk synth
fails with "Cannot read properties of undefined (reading 'fileExists')").
Switch the cdk.json app runner to tsx (pinned 4.23.0, matching sh-mcp) and
bump typescript to ~7.0.2. Synthesized templates are byte-identical across
all six stacks; toolchain-only change.
2026-07-08 17:48:30 -04:00
seahaven-openswe[bot]
142e221c47
feat: harden CIS 4.1 detection depth with M-of-N alarm tuning and CloudTrail Insights (#38)
Some checks are pending
Deploy / deploy (push) Waiting to run
Switch UnauthorizedApiCalls alarm from 3/3 consecutive to 3/6 M-of-N
so a single quiet 5-min window can't reset detection. The 3/3 setting
pre-dates #36 and was sized to suppress CFN/Config noise that #36 now
removes at the filter level, making a wider M-of-N evaluation window
safe from flap risk.

Enable CloudTrail Insights (ApiCallRateInsight + ApiErrorRateInsight)
on seahaven-org-trail as a compensating control for the residual risk
accepted in #36 — the CFN/Config-proxied denials intentionally excluded
from CIS 4.1 — and as a backstop for low-and-slow patterns the 5-min
alarm may miss. Cost ≈$35–$53/month at current org trail volume.

Refs: #37

Co-authored-by: amoussa1229 <166072409+amoussa1229@users.noreply.github.com>
2026-07-07 15:47:41 -04:00
Adam Moussa
0d654edb35
fix: Fix noisy CIS 4.1 unauthorized-API alarm; drop redundant billing alarm (#36)
* Fix noisy CIS 4.1 unauthorized-API alarm; drop redundant billing alarm

CIS 4.1 (cis-UnauthorizedAPICalls) flapped OK<->ALARM 15 times in 30 days,
all from benign AWS-service AccessDenied noise (CloudFormation deploy/drift
describe-scans, AWS Config recorder). A single CFN run on 2026-07-07 emitted
100+ such denials in 15 min, tripping the alarm and burying the real CIS 4.1
security signal in email noise (alert fatigue).

- Group both error codes so the exclusions apply to the whole filter (the old
  pattern leaked the UnauthorizedOperation branch past the exclusions due to
  && binding tighter than ||).
- Exclude denials whose sourceIPAddress is an AWS service host (*.amazonaws.com)
  — AWS acting on our behalf, not a principal of concern. Real unauthorized
  calls from a console/CLI/attacker present a routable IP and are still counted.
  Validated against the trail log group: spike window 107 -> 4 matches, the 4
  remaining all from a routable admin IP (genuine activity CIS should retain).
- Keep the 3/3 evaluation as a backstop against one-off human fat-fingers.

Billing: deleted the manually-created AWS-MonthlyBilling CloudWatch alarm
($50 threshold on EstimatedCharges, routed to site-alerts). It was unmanaged
drift, permanently in ALARM, and fully redundant with the managed M-10 budget
(seahaven-monthly-cost). README updated with rationale + restore command.

* Address sh-security-review: scope CIS 4.1 exclusion to named benign sources

The high-recall security review (detector fan-out + proof-or-kill verifier)
confirmed a MEDIUM detection blind spot in the first revision: excluding all
`*.amazonaws.com` source hosts would hide denials driven through ANY AWS
service (SSM Automation, Step Functions, Lambda, etc.), which CloudTrail
records with that service's host as sourceIPAddress — i.e. service-proxied
privesc/recon attempts would evade CIS 4.1.

Remediation: scope the exclusion to the specific benign sources that actually
flap this account — `*cloudformation.amazonaws.com` (covers both
cloudformation. and hooks.cloudformation.) and `config.amazonaws.com` — plus
the pre-existing delivery.logs exclusion. Every other service-proxied denial
is now retained. Residual (accepted, documented inline): CloudFormation/Config-
proxied denials are still excluded — that path needs near-admin privilege
(CreateStack + PassRole), successful changes still trip the other CIS 4.x
alarms, and GuardDuty backstops.

Validated on the live trail log group: spike window still 107 -> 4 matches
(identical noise suppression), the 4 from a routable admin IP. tsc + synth clean.
2026-07-07 19:32:10 +00:00
Adam Moussa
6ce8b96b22
chore(ci): SHA-pin org reusable-workflow caller refs (INFRA-50) (#35)
Some checks are pending
Deploy / deploy (push) Waiting to run
2026-07-06 18:27:41 -04:00
Adam Moussa
4713172af1
docs: link Confluence AWS Architecture Map (INFRA-53) (#34)
Some checks are pending
Deploy / deploy (push) Waiting to run
2026-07-06 17:44:22 -04:00
dependabot[bot]
2d92fd4ddf
Bump the minor-and-patch group with 2 updates (#33)
Some checks failed
Deploy / deploy (push) Has been cancelled
2026-07-04 01:15:09 -04:00
dependabot[bot]
3065060b47
Bump aws-cdk from 2.1128.0 to 2.1128.1 in the minor-and-patch group (#32)
Some checks failed
Deploy / deploy (push) Has been cancelled
Bumps the minor-and-patch group with 1 update: [aws-cdk](https://github.com/aws/aws-cdk-cli/tree/HEAD/packages/aws-cdk).


Updates `aws-cdk` from 2.1128.0 to 2.1128.1
- [Release notes](https://github.com/aws/aws-cdk-cli/releases)
- [Commits](https://github.com/aws/aws-cdk-cli/commits/aws-cdk@v2.1128.1/packages/aws-cdk)

---
updated-dependencies:
- dependency-name: aws-cdk
  dependency-version: 2.1128.1
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-06-24 15:54:33 -04:00
Adam Moussa
749e5ce4e9
Ignore @types/node major bumps in Dependabot (#31)
Some checks are pending
Deploy / deploy (push) Waiting to run
This pure CDK app is built and synthed on Node 24 (no Lambdas), so
@types/node is pinned to ^24. A too-new types major still compiles, so a
major bump passes CI while describing APIs absent at the build Node.

Add a scoped Dependabot ignore for @types/node semver-major bumps so the
alignment can only be broken deliberately, alongside a Node upgrade.
Minor/patch within the major still flow. Sanctioned exception to the
no-blanket-ignore rule (engineering-handbook github-standards Pinning
Principle).
2026-06-24 15:01:32 -04:00
dependabot[bot]
797d1e83ff
Bump the minor-and-patch group with 2 updates (#29)
Some checks failed
Deploy / deploy (push) Has been cancelled
Bumps the minor-and-patch group with 2 updates: [aws-cdk-lib](https://github.com/aws/aws-cdk/tree/HEAD/packages/aws-cdk-lib) and [aws-cdk](https://github.com/aws/aws-cdk-cli/tree/HEAD/packages/aws-cdk).


Updates `aws-cdk-lib` from 2.259.0 to 2.260.0
- [Release notes](https://github.com/aws/aws-cdk/releases)
- [Changelog](https://github.com/aws/aws-cdk/blob/main/CHANGELOG.v2.alpha.md)
- [Commits](https://github.com/aws/aws-cdk/commits/v2.260.0/packages/aws-cdk-lib)

Updates `aws-cdk` from 2.1126.0 to 2.1128.0
- [Release notes](https://github.com/aws/aws-cdk-cli/releases)
- [Commits](https://github.com/aws/aws-cdk-cli/commits/aws-cdk@v2.1128.0/packages/aws-cdk)

---
updated-dependencies:
- dependency-name: aws-cdk-lib
  dependency-version: 2.260.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: aws-cdk
  dependency-version: 2.1128.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-06-22 13:13:57 -04:00
dependabot[bot]
b2f2f918a2
Bump aws-cdk-lib from 2.258.0 to 2.259.0 in the minor-and-patch group (#27)
Some checks failed
Deploy / deploy (push) Has been cancelled
Bumps the minor-and-patch group with 1 update: [aws-cdk-lib](https://github.com/aws/aws-cdk/tree/HEAD/packages/aws-cdk-lib).


Updates `aws-cdk-lib` from 2.258.0 to 2.259.0
- [Release notes](https://github.com/aws/aws-cdk/releases)
- [Changelog](https://github.com/aws/aws-cdk/blob/main/CHANGELOG.v2.alpha.md)
- [Commits](https://github.com/aws/aws-cdk/commits/v2.259.0/packages/aws-cdk-lib)

---
updated-dependencies:
- dependency-name: aws-cdk-lib
  dependency-version: 2.259.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-06-16 17:20:49 -04:00
Adam Moussa
6a63a4f9b0
Repo hygiene: PR labeler + README badges (INFRA-56/57) (#26)
Some checks failed
Deploy / deploy (push) Has been cancelled
2026-06-11 14:42:34 -04:00
Adam Moussa
67f4ca81d9
fix(cis): require 3-of-3 periods for UnauthorizedAPICalls alarm (INFRA-104) (#25)
Some checks are pending
Deploy / deploy (push) Waiting to run
The cis-UnauthorizedAPICalls alarm fired on a single breaching 5-min period
(1/1), so any CloudFormation/CDK deploy burst of benign describe-API denials or
a one-off console fat-finger paged and self-recovered, producing notification
storms (~17 flips on 2026-06-10). Require 3 consecutive breaching periods so
only sustained unauthorized activity alarms; CIS detection of a real persistent
problem is preserved (detection window up to ~15 min). Per-control override so
the other 14 CIS alarms keep their 1/1 sensitivity (templates untouched).

GPT-4.1 cross-review: no blockers (documentation FIX noted re: detection latency).
2026-06-10 19:32:03 -04:00
Adam Moussa
cbd98da049
chore(deps): pin @types/node to ^24 to match Node 24 runtime (#24)
Some checks are pending
Deploy / deploy (push) Waiting to run
CI and deploy both run on Node 24; @types/node was stale at ^22. Dependabot
proposed jumping to ^25 (#2), but Node 25 is a non-LTS, non-Lambda release
ahead of the runtime. Pinning to ^24 to match. Build + cdk synth verified clean.
2026-06-10 18:24:30 -04:00
dependabot[bot]
e172507621
Bump typescript from 5.7.3 to 6.0.3 (#1)
Bumps [typescript](https://github.com/microsoft/TypeScript) from 5.7.3 to 6.0.3.
- [Release notes](https://github.com/microsoft/TypeScript/releases)
- [Commits](https://github.com/microsoft/TypeScript/compare/v5.7.3...v6.0.3)

---
updated-dependencies:
- dependency-name: typescript
  dependency-version: 6.0.3
  dependency-type: direct:development
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-06-10 18:19:14 -04:00
Adam Moussa
cd82b49f17
Stabilize CloudTrail log group name to prevent filter detachment (#23)
Some checks are pending
Deploy / deploy (push) Waiting to run
Previously the L2 cloudtrail.Trail auto-created a log group with a
CDK-generated hash suffix in its name. The 15 CIS Section 4 metric
filters in CisMonitoring imported that group by the hardcoded generated
name. If the Trail or log group was ever recreated the suffix changes
and all 15 filters would silently detach with no error, leaving the
account unmonitored.

Replace with an explicit logs.LogGroup named
seahaven-account-baseline-trail-logs (stable, no hash suffix) with
RemovalPolicy.RETAIN. Pass the CDK object — not a name constant — to
the Trail via cloudWatchLogGroup and forward it to CisMonitoring via a
new trailLogGroup prop. All 15 filters now reference the CDK object so
they can never drift from the group the Trail actually delivers to.

The old auto-named log group is orphaned by this deploy (CloudFormation
loses track of it and does not delete it). Historical audit logs in the
old group remain accessible in CloudWatch under the old name; no audit
history is destroyed.

Refs: INFRA-19
2026-06-10 14:44:33 -04:00
Adam Moussa
e22c4ac005
Bring Config recorder + channel under IaC via AwsCustomResource (#22)
The L1 AWS::Config::ConfigurationRecorder deadlocks the CDK stack
(recorder can't complete without a delivery channel; channel can't be
created without a recorder — observed 2026-06-01).

Fix: three AwsCustomResource nodes call PutConfigurationRecorder →
PutDeliveryChannel → StartConfigurationRecorder in sequence. Put* is
an idempotent upsert, so the deploy adopts the existing CLI-created
recorder and channel without destroying or interrupting them. onDelete
stops recording rather than deleting the per-account singleton.

New IAM permissions on the custom-resource role (cross-reviewed,
GPT-4.1 APPROVE — no BLOCK):
  config:PutConfigurationRecorder
  config:PutDeliveryChannel
  config:StartConfigurationRecorder
  config:StopConfigurationRecorder
  iam:PassRole → seahaven-config-recorder-role (service=config)

cdk diff shows [+] adds only — no existing resources destroyed or
replaced. Removes README note that recorder/channel are CLI-only.

Refs: INFRA-17
2026-06-10 14:38:23 -04:00
Adam Moussa
ec620e4e79
[INFRA-95] Shared DynamoDB CMK for sensitive finance/PII tables (M-3) (#21)
Some checks failed
Deploy / deploy (push) Has been cancelled
2026-06-08 19:04:42 -04:00
Adam Moussa
77d9d6c574
[INFRA-96] CMK-encrypt sensitive CloudWatch log groups (M-24) (#20)
* [INFRA-96] CMK-encrypt sensitive CloudWatch log groups (M-24)

Add a dedicated customer-managed CMK (alias/seahaven-logs) for encrypting
the sensitive CloudWatch Logs groups (CloudTrail + finance/PII Lambdas).

- lib/logs-key.ts: LogsKey construct. Key policy grants the CloudWatch Logs
  service principal (logs.us-east-1.amazonaws.com) Encrypt*/Decrypt*/
  ReEncrypt*/GenerateDataKey*/DescribeKey, scoped by the
  kms:EncryptionContext:aws:logs:arn condition (REQUIRED per AWS docs or log
  delivery breaks). Cross-reviewed (GPT-4.1): tightened Describe* -> DescribeKey;
  CreateGrant omitted (not needed for plain log-group encryption).
- account-baseline-stack.ts: instantiate LogsKey and set KmsKeyId on the L2
  Trail's CloudWatch log group in place (escape hatch on the existing
  AWS::Logs::LogGroup) so it keeps the same logical id + physical name -
  additive, no replacement, CIS Section-4 metric filters (which import the
  group by name) keep working, live audit trail not disrupted. Gated by
  context `encryptTrailLogGroup` so the CMK can be smoke-tested on a low-risk
  Lambda group before the most-sensitive CloudTrail group.

Finance/PII Lambda log groups (exec-aide-*, payments-*, po-email-processor,
vendor-reply-processor) are owned by other stacks and associated to this CMK
via the CLI for now; codifying KmsKeyId in those repos is tracked as drift.

* [INFRA-96] Document sensitive-logs CMK (M-24) in README
2026-06-08 19:04:36 -04:00
Adam Moussa
5002ed86d8
[INFRA-94] Add Backup vault access policy on seahaven-primary (#19)
Some checks are pending
Deploy / deploy (push) Waiting to run
Reintroduce the scoped vault access policy that was split out of INFRA-89
after two lockout-class bugs. Adds a Deny on the destructive recovery-point
and vault-lifecycle actions (DeleteRecoveryPoint, UpdateRecoveryPointLifecycle,
DeleteBackupVault, DeleteBackupVaultAccessPolicy,
DeleteBackupVaultLockConfiguration, PutBackupVaultLockConfiguration) for every
principal except three exempted operational identities via StringNotLike on
aws:PrincipalArn:

  1. SSO AdministratorAccess role (break-glass human admin)
  2. seahaven-backup-service-role (AWS Backup lifecycle)
  3. cdk-hnb659fds-cfn-exec-role-* (CloudFormation manages the vault)

The CFN-exec-role exemption is the fix for the 2026-06-08 strand failure: without
it CloudFormation cannot re-assert the vault lock config and the deploy strands
the policy. Uses Deny + AnyPrincipal + StringNotLike (not NotPrincipal, which
rejects wildcard ARNs). aws:PrincipalArn normalizes assumed-role sessions to the
IAM role ARN, so the iam::role/ ARN forms are correct (AWS docs: "Do not specify
the assumed role session ARN as a value for this condition key").

Deployed and verified: deploy succeeded (proves exec role not locked out),
access policy present with all three exemptions, vault still Locked
(min1/max2555, LockDate null, 168 RPs), follow-up cdk diff clean (no drift).
2026-06-08 17:34:01 -04:00
Adam Moussa
e9a184cf96
[INFRA-91/89/16/88/73] Reconcile out-of-band baseline changes + add missing detective controls (#18)
* Codify primary vault lock + add backups (INFRA-89, INFRA-88)

INFRA-89: codify the GOVERNANCE Vault Lock applied out-of-band on the
seahaven-primary vault (MinRetention 1d, MaxRetention 2555d, no
changeableFor = admin-removable) so it lives in IaC. Values match the
live lock exactly, so the deploy is a no-op adoption.

Add a scoped vault access policy that denies manual recovery-point
deletion and lock/policy tampering to all principals except the AWS
Backup service role and the break-glass SSO AdministratorAccess role,
so automatic lifecycle expiry still works but humans cannot prune
recovery points by hand.

Cross-review (GPT-4.1) BLOCK: NotPrincipal does not support wildcard
ARN matching, so the SSO exemption is expressed as Effect DENY with
Principal * and a StringNotLike condition on aws:PrincipalArn, which
does support wildcards. This avoids an unrecoverable vault lockout.

INFRA-88: add 6 S3 buckets (kb-docs, payroll-emails [PII], amazon-po,
extracted-amazon-po, proposal-system uploads + generated) to the
phase2-offsite-everything selection. Versioning verified enabled on
all 6 against the live account (S3 backup requires versioning).

Refs: INFRA-89, INFRA-88

* Promote account trail to organization trail (INFRA-73)

INFRA-73: set isOrganizationTrail on seahaven-org-trail and pass orgId
(o-9kufuzz6b4) so the L2 Trail attaches the AWSLogs/<org-id>/* bucket
PutObject statement for member-account delivery. CloudTrail org
trusted-access is already enabled on the management account.

Broaden the KMS key policy with an org-scoped GenerateDataKey/DescribeKey
statement for member-account trail delivery, guarded by
aws:PrincipalOrgID. The existing single-account statements are
preserved so management-account delivery is unaffected.

Cross-review (GPT-4.1) BLOCK: the member KMS SourceArn and encryption
context must be wildcarded across accounts (org-trail shadow trails
present the member account id), not pinned to the management account,
or member delivery silently fails. Fixed before checkpoint.

CHECKPOINT: delicate org-trail KMS/bucket-policy change — code +
diff captured for review, NOT deployed.

Refs: INFRA-73

* Add secondary-region baseline stacks (INFRA-91, INFRA-16)

INFRA-91: codify the Bedrock model-invocation logging applied
out-of-band in us-west-2 and us-east-2 (per-region delivery role
seahaven-bedrock-invocation-logging-<region> + log group
/aws/bedrock/model-invocations 90d, CloudWatch-only). The account-level
logging config itself has no CFN resource type and is applied via CLI
(already live), same as us-east-1.

INFRA-16: add the still-missing us-east-2 detective controls — AWS
Config recorder role + delivery bucket (recorder/channel via CLI to
avoid the CFN stabilization deadlock seen in us-east-1) and Security
Hub with FSBP + CIS v3.0. GuardDuty + flow logs already live in
us-east-2 and are left for a follow-up adoption to keep this change
non-destructive.

The us-east-1 baseline stays region-pinned; these are separate
RegionalBaselineStack instances composed opt-in per region.

CHECKPOINT: new multi-region stacks. The live Bedrock role + log group
already exist (CLI-created), so a plain deploy would collide — these
need cdk import / changeset adoption, not cdk deploy. Code + diff
captured for review, NOT deployed.

Refs: INFRA-91, INFRA-16

* Drop vault access policy from this deploy; tracked in INFRA-94 (kept governance lock codify + selection)
2026-06-08 17:03:18 -04:00
dependabot[bot]
476578f0c3
Bump aws-cdk-lib from 2.257.0 to 2.258.0 in the minor-and-patch group (#16)
Some checks failed
Deploy / deploy (push) Has been cancelled
Bumps the minor-and-patch group with 1 update: [aws-cdk-lib](https://github.com/aws/aws-cdk/tree/HEAD/packages/aws-cdk-lib).


Updates `aws-cdk-lib` from 2.257.0 to 2.258.0
- [Release notes](https://github.com/aws/aws-cdk/releases)
- [Changelog](https://github.com/aws/aws-cdk/blob/main/CHANGELOG.v2.alpha.md)
- [Commits](https://github.com/aws/aws-cdk/commits/v2.258.0/packages/aws-cdk-lib)

---
updated-dependencies:
- dependency-name: aws-cdk-lib
  dependency-version: 2.258.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-06-05 14:57:24 -04:00
Adam Moussa
a9d9f12a40
fix(deps): bump aws-cdk-lib pin to 2.257.0 (#15)
Some checks are pending
Deploy / deploy (push) Waiting to run
2026-06-05 13:01:36 -04:00
Adam Moussa
05b0f95c4f
Add dependency-review caller workflow (#14)
* Add dependency-review caller workflow

Add a pull_request-triggered caller that invokes the org-level
callable-dependency-review workflow to scan dependency changes and
fail on high-severity advisories.

* chore: retrigger checks

* chore: retrigger dep review (post-fix)
2026-06-05 12:26:57 -04:00