seahaven-account-baseline/.github/workflows
Adam Moussa 22b04c4e75
Some checks are pending
Deploy / deploy-management (push) Waiting to run
Deploy / deploy-external-dev (push) Waiting to run
Org governance: OU skeleton + generalized SCPs (Phase 2) (#44)
* Add org-governance stack: OU skeleton + generalized SCPs

Phase 2 of the multi-account segregation plan: codifies the OU tree
(workloads/prod/nonprod, security, sandbox, graveyard) and three
org-wide SCPs (workloads-region-lock, protect-security-baseline,
deny-root-user) generalized from the proven external-dev guardrails.
All resources Retain — CFN must never detach a live guardrail. New SCPs
attach only to the new empty OUs; extending to external-dev is a
separate gated targetIds change after live verification.

* Record SCP cross-review dispositions in org-governance

Root hardening must precede the OU move (deny-root-user blocks root MFA
enrollment), delegated-admin flows ride service-linked roles that SCPs
never evaluate, and the cdk exec-role exemption is accepted risk
mirroring the external-dev guardrails.

* Add org-governance to the management deploy job

Explicit stack selectors require every new stack to join exactly one
CD job (SH-ORG-005 discipline documented in this file).
2026-07-14 14:02:30 -04:00
..
ci.yaml chore(ci): SHA-pin org reusable-workflow caller refs (INFRA-50) (#35) 2026-07-06 18:27:41 -04:00
dependency-review.yml chore(ci): SHA-pin org reusable-workflow caller refs (INFRA-50) (#35) 2026-07-06 18:27:41 -04:00
deploy.yaml Org governance: OU skeleton + generalized SCPs (Phase 2) (#44) 2026-07-14 14:02:30 -04:00
labeler.yml chore(ci): SHA-pin org reusable-workflow caller refs (INFRA-50) (#35) 2026-07-06 18:27:41 -04:00