52 lines
2 KiB
TypeScript
52 lines
2 KiB
TypeScript
|
|
import * as cdk from "aws-cdk-lib";
|
||
|
|
import { Construct } from "constructs";
|
||
|
|
import { DetectiveControls } from "./detective-controls";
|
||
|
|
import { FlowLogs } from "./flow-logs";
|
||
|
|
import { GovernanceToggles } from "./governance-toggles";
|
||
|
|
|
||
|
|
export interface ExternalDevBaselineStackProps extends cdk.StackProps {
|
||
|
|
/** Monthly cost budget ceiling in USD. */
|
||
|
|
readonly monthlyBudgetUsd: number;
|
||
|
|
/** Sea Haven ops address that receives budget alerts (not the dev team). */
|
||
|
|
readonly budgetAlertEmail: string;
|
||
|
|
/** VPC ids to attach flow logs to (from cdk context; may be empty). */
|
||
|
|
readonly flowLogVpcIds: string[];
|
||
|
|
}
|
||
|
|
|
||
|
|
/**
|
||
|
|
* Account-local security baseline for the isolated external-dev account
|
||
|
|
* (seahaven-external-dev). A stripped fork of seahaven-account-baseline.
|
||
|
|
*
|
||
|
|
* Deliberately excludes everything that is org-level or prod-specific:
|
||
|
|
* - No local CloudTrail — the management-account org trail (seahaven-org-trail)
|
||
|
|
* already captures this account's events centrally.
|
||
|
|
* - No CIS Section-4 metric-filter alarms — the Security Hub CIS standard
|
||
|
|
* evaluates those controls against Config without a local trail log group.
|
||
|
|
* - No WAF, SES monitoring, Bedrock logging, DynamoDB CMK, or AWS Backup —
|
||
|
|
* all prod-only concerns.
|
||
|
|
*
|
||
|
|
* Contains: AWS Config, GuardDuty, Security Hub (FSBP + CIS v3.0), IAM Access
|
||
|
|
* Analyzer, Inspector2, VPC flow logs, and a monthly cost Budget.
|
||
|
|
*/
|
||
|
|
export class ExternalDevBaselineStack extends cdk.Stack {
|
||
|
|
constructor(
|
||
|
|
scope: Construct,
|
||
|
|
id: string,
|
||
|
|
props: ExternalDevBaselineStackProps
|
||
|
|
) {
|
||
|
|
super(scope, id, props);
|
||
|
|
|
||
|
|
new DetectiveControls(this, "DetectiveControls");
|
||
|
|
|
||
|
|
new FlowLogs(this, "FlowLogs", { vpcIds: props.flowLogVpcIds });
|
||
|
|
|
||
|
|
new GovernanceToggles(this, "GovernanceToggles", {
|
||
|
|
monthlyLimitUsd: props.monthlyBudgetUsd,
|
||
|
|
alertEmail: props.budgetAlertEmail,
|
||
|
|
});
|
||
|
|
|
||
|
|
cdk.Tags.of(this).add("Owner", "adam@seahaven.com");
|
||
|
|
cdk.Tags.of(this).add("ManagedBy", "seahaven-external-dev-baseline");
|
||
|
|
}
|
||
|
|
}
|