Add account-local security baseline for seahaven-external-dev
Stripped fork of seahaven-account-baseline for the isolated external-dev
account (396287094661). Single stack: AWS Config, GuardDuty, Security Hub
(FSBP + CIS v3.0), IAM Access Analyzer, VPC flow logs (VPC ids via context),
and a $200/mo budget alerting adam@seahaven.com.
Drops all org-level / prod-specific controls (local CloudTrail, CIS metric
alarms, WAF, SES, Bedrock, DynamoDB CMK, Backup) per the isolated-account
design; the org trail already covers this account centrally. Inspector2 is a
documented post-deploy CLI step (no CloudFormation enable resource exists).
2026-06-15 11:26:23 -04:00
|
|
|
# seahaven-external-dev-baseline
|
|
|
|
|
|
2026-07-06 17:34:20 -04:00
|
|
|
[](https://github.com/Sea-Haven-Industries/seahaven-external-dev-baseline/actions/workflows/ci.yaml)
|
|
|
|
|

|
|
|
|
|

|
|
|
|
|
|
Add account-local security baseline for seahaven-external-dev
Stripped fork of seahaven-account-baseline for the isolated external-dev
account (396287094661). Single stack: AWS Config, GuardDuty, Security Hub
(FSBP + CIS v3.0), IAM Access Analyzer, VPC flow logs (VPC ids via context),
and a $200/mo budget alerting adam@seahaven.com.
Drops all org-level / prod-specific controls (local CloudTrail, CIS metric
alarms, WAF, SES, Bedrock, DynamoDB CMK, Backup) per the isolated-account
design; the org trail already covers this account centrally. Inspector2 is a
documented post-deploy CLI step (no CloudFormation enable resource exists).
2026-06-15 11:26:23 -04:00
|
|
|
Account-local security baseline (CDK, TypeScript) for **`seahaven-external-dev`**
|
|
|
|
|
(account `396287094661`, us-east-1), the isolated AWS account used by the
|
|
|
|
|
external web-app dev team. A stripped fork of
|
|
|
|
|
[`seahaven-account-baseline`](https://github.com/Sea-Haven-Industries/seahaven-account-baseline).
|
|
|
|
|
|
|
|
|
|
The external team works only in this account; they have no access to the
|
|
|
|
|
management/production account `328440206208`. This stack ensures the isolated
|
|
|
|
|
account is not a monitoring blind spot.
|
|
|
|
|
|
|
|
|
|
## Architecture
|
|
|
|
|
|
|
|
|
|
Single stack `seahaven-external-dev-baseline`:
|
|
|
|
|
|
|
|
|
|
| Control | Resource | Notes |
|
|
|
|
|
|---|---|---|
|
|
|
|
|
| AWS Config | recorder + delivery channel + `seahaven-extdev-config-<acct>` bucket | Records all supported resource types; foundation for Security Hub CIS |
|
|
|
|
|
| GuardDuty | detector (15-min findings) | Account-local threat detection |
|
|
|
|
|
| Security Hub | FSBP v1.0.0 + CIS AWS Foundations v3.0.0 | CIS evaluated against Config — no local trail required |
|
|
|
|
|
| IAM Access Analyzer | account-scoped external-access analyzer | |
|
|
|
|
|
| VPC flow logs | `seahaven-extdev-vpc-flow-logs-<acct>` bucket | ALL traffic; VPC ids passed via context |
|
|
|
|
|
| Budget | `seahaven-extdev-monthly-cost`, $200/mo | 80%/100% actual + 100% forecast → `adam@seahaven.com` (Sea Haven ops) |
|
|
|
|
|
|
|
|
|
|
## Deliberately excluded
|
|
|
|
|
|
|
|
|
|
- **No local CloudTrail.** The management-account organization trail
|
|
|
|
|
`seahaven-org-trail` already captures this account's management + data events
|
|
|
|
|
centrally. A second local trail would duplicate that at extra cost.
|
|
|
|
|
- **No CIS Section-4 metric-filter alarms.** Those bind to a local CloudTrail
|
|
|
|
|
CloudWatch Logs group, which does not exist here. The Security Hub CIS
|
|
|
|
|
standard evaluates the same controls against AWS Config instead.
|
|
|
|
|
- **No WAF, SES monitoring, Bedrock logging, DynamoDB CMK, or AWS Backup** —
|
|
|
|
|
all production-only concerns in the source baseline.
|
|
|
|
|
|
|
|
|
|
## Configuration
|
|
|
|
|
|
|
|
|
|
| Input | Where | Value |
|
|
|
|
|
|---|---|---|
|
|
|
|
|
| Target account | `bin/app.ts` | `396287094661` |
|
|
|
|
|
| Region | `bin/app.ts` | `us-east-1` (account is SCP region-locked) |
|
|
|
|
|
| Budget | `bin/app.ts` | $200/mo → `adam@seahaven.com` |
|
|
|
|
|
| Flow-log VPC ids | cdk context `flowLogVpcIds` | comma-separated; empty by default |
|
|
|
|
|
|
|
|
|
|
```bash
|
|
|
|
|
# Deploy attaching flow logs to specific VPCs:
|
|
|
|
|
npm ci
|
|
|
|
|
npx cdk deploy -c flowLogVpcIds=vpc-aaaa,vpc-bbbb
|
|
|
|
|
```
|
|
|
|
|
|
|
|
|
|
## Post-deploy runbook
|
|
|
|
|
|
|
|
|
|
**Enable Inspector2** (no CloudFormation enable resource exists):
|
|
|
|
|
|
|
|
|
|
```bash
|
|
|
|
|
aws inspector2 enable --resource-types EC2 ECR LAMBDA --account-ids 396287094661
|
|
|
|
|
```
|
|
|
|
|
|
|
|
|
|
This is a one-time per-account toggle; it persists across stack deploys.
|
|
|
|
|
|
|
|
|
|
## Deployment
|
|
|
|
|
|
|
|
|
|
CI/CD via the org reusable workflows (`ci-typescript-cdk.yaml`, `cd-cdk.yaml`,
|
|
|
|
|
node 24). Push to `main` deploys via GitHub OIDC into `396287094661` using the
|
|
|
|
|
`githubdeploy-seahaven-external-dev-baseline` role (repo secret
|
|
|
|
|
`AWS_DEPLOY_ROLE_ARN`).
|