seahaven-account-baseline/lib/bedrock-logging-regional.ts
Adam Moussa 5d2a3a46bb Add secondary-region baseline stacks (INFRA-91, INFRA-16)
INFRA-91: codify the Bedrock model-invocation logging applied
out-of-band in us-west-2 and us-east-2 (per-region delivery role
seahaven-bedrock-invocation-logging-<region> + log group
/aws/bedrock/model-invocations 90d, CloudWatch-only). The account-level
logging config itself has no CFN resource type and is applied via CLI
(already live), same as us-east-1.

INFRA-16: add the still-missing us-east-2 detective controls — AWS
Config recorder role + delivery bucket (recorder/channel via CLI to
avoid the CFN stabilization deadlock seen in us-east-1) and Security
Hub with FSBP + CIS v3.0. GuardDuty + flow logs already live in
us-east-2 and are left for a follow-up adoption to keep this change
non-destructive.

The us-east-1 baseline stays region-pinned; these are separate
RegionalBaselineStack instances composed opt-in per region.

CHECKPOINT: new multi-region stacks. The live Bedrock role + log group
already exist (CLI-created), so a plain deploy would collide — these
need cdk import / changeset adoption, not cdk deploy. Code + diff
captured for review, NOT deployed.

Refs: INFRA-91, INFRA-16
2026-06-08 16:17:50 -04:00

71 lines
2.7 KiB
TypeScript

import * as cdk from "aws-cdk-lib";
import * as iam from "aws-cdk-lib/aws-iam";
import * as logs from "aws-cdk-lib/aws-logs";
import { Construct } from "constructs";
/**
* Regional Bedrock model-invocation logging destination + delivery role
* (INFRA-91). Bedrock invocation logging is account-level *per region*, so
* extending the us-east-1 coverage (lib/bedrock-logging.ts) to the other
* regions where Bedrock is reachable (us-west-2, us-east-2) requires a separate
* regional stack with its own log group + delivery role per region.
*
* This codifies the out-of-band CLI state applied 2026-06 to MATCH exactly so
* the adoption diff is minimal:
* - IAM role seahaven-bedrock-invocation-logging-<region>
* - log group /aws/bedrock/model-invocations (90d)
* - CloudWatch-only delivery (no S3 leg — unlike us-east-1, these regions log
* to CloudWatch only; the large-payload S3 bucket is us-east-1 only).
*
* Like us-east-1, the account-level logging configuration itself has no CFN
* resource type (`PutModelInvocationLoggingConfiguration`); it is applied via
* CLI per region (already live — see README). This construct owns only the
* destinations + role the live config references.
*/
export class BedrockLoggingRegional extends Construct {
public readonly logGroup: logs.LogGroup;
public readonly deliveryRole: iam.Role;
constructor(scope: Construct, id: string) {
super(scope, id);
const stack = cdk.Stack.of(this);
this.logGroup = new logs.LogGroup(this, "InvocationLogGroup", {
logGroupName: "/aws/bedrock/model-invocations",
retention: logs.RetentionDays.THREE_MONTHS,
removalPolicy: cdk.RemovalPolicy.RETAIN,
});
// Region-suffixed role name matches the live CLI-created role so CFN can
// adopt it by import rather than creating a colliding new one.
this.deliveryRole = new iam.Role(this, "DeliveryRole", {
roleName: `seahaven-bedrock-invocation-logging-${stack.region}`,
assumedBy: new iam.ServicePrincipal("bedrock.amazonaws.com", {
conditions: {
StringEquals: { "aws:SourceAccount": stack.account },
ArnLike: {
"aws:SourceArn": `arn:aws:bedrock:${stack.region}:${stack.account}:*`,
},
},
}),
});
this.deliveryRole.addToPolicy(
new iam.PolicyStatement({
actions: ["logs:CreateLogStream", "logs:PutLogEvents"],
resources: [
this.logGroup.logGroupArn,
`${this.logGroup.logGroupArn}:log-stream:*`,
],
}),
);
new cdk.CfnOutput(this, "BedrockLogGroupName", {
value: this.logGroup.logGroupName,
});
new cdk.CfnOutput(this, "BedrockLoggingRoleArn", {
value: this.deliveryRole.roleArn,
});
}
}