diff --git a/README.md b/README.md index 8b87837..b3a59f9 100644 --- a/README.md +++ b/README.md @@ -1,100 +1,16 @@ -# seahaven-external-dev-baseline +# seahaven-external-dev-baseline — ARCHIVED -[![CI](https://github.com/Sea-Haven-Industries/seahaven-external-dev-baseline/actions/workflows/ci.yaml/badge.svg)](https://github.com/Sea-Haven-Industries/seahaven-external-dev-baseline/actions/workflows/ci.yaml) -![TypeScript](https://img.shields.io/badge/TypeScript-3178C6?logo=typescript&logoColor=white) -![AWS CDK](https://img.shields.io/badge/AWS%20CDK-2.261.0-FF9900?logo=amazonaws&logoColor=white) +**This repo was absorbed into +[seahaven-org-baseline](https://github.com/Sea-Haven-Industries/seahaven-org-baseline) +on 2026-07-14** (multi-account segregation plan Phase 1). -Account-local security baseline (CDK, TypeScript) for **`seahaven-external-dev`** -(account `396287094661`, us-east-1), the isolated AWS account used by the -external web-app dev team. A stripped fork of -[`seahaven-account-baseline`](https://github.com/Sea-Haven-Industries/seahaven-account-baseline). +- The deployed CloudFormation stack `seahaven-external-dev-baseline` + (account 396287094661) is unchanged and now managed from + `seahaven-org-baseline` (`lib/member-baseline-stack.ts`, CD job + `deploy-external-dev`). +- The OIDC deploy role `githubdeploy-seahaven-external-dev-baseline` now + trusts only `seahaven-org-baseline`. +- History of the original code lives in this repo's git history and continues + in the merged repo. -The external team works only in this account; they have no access to the -management/production account `328440206208`. This stack ensures the isolated -account is not a monitoring blind spot. - -## Architecture - -Single stack `seahaven-external-dev-baseline`: - -| Control | Resource | Notes | -|---|---|---| -| AWS Config | recorder + delivery channel + `seahaven-extdev-config-` bucket | Records all supported resource types; foundation for Security Hub CIS | -| GuardDuty | detector (15-min findings) | Account-local threat detection | -| Security Hub | FSBP v1.0.0 + CIS AWS Foundations v3.0.0 | CIS evaluated against Config — no local trail required | -| IAM Access Analyzer | account-scoped external-access analyzer | | -| VPC flow logs | `seahaven-extdev-vpc-flow-logs-` bucket | ALL traffic; VPC ids passed via context | -| Budget | `seahaven-extdev-monthly-cost`, $200/mo | 80%/100% actual + 100% forecast → `adam@seahaven.com` (Sea Haven ops) | - -## Deliberately excluded - -- **No local CloudTrail.** The management-account organization trail - `seahaven-org-trail` already captures this account's management + data events - centrally. A second local trail would duplicate that at extra cost. -- **No CIS Section-4 metric-filter alarms.** Those bind to a local CloudTrail - CloudWatch Logs group, which does not exist here. The Security Hub CIS - standard evaluates the same controls against AWS Config instead. -- **No WAF, SES monitoring, Bedrock logging, DynamoDB CMK, or AWS Backup** — - all production-only concerns in the source baseline. - -## CDK app - -This repo is an AWS CDK application (TypeScript). `cdk.json` is the CDK -entry point: it sets `app` to `tsx bin/app.ts`, so the CLI runs the -TypeScript source directly with no separate build step, and pins the CDK -feature flags / context the stack synthesizes against. - -Layout follows the standard CDK project structure: - -| Path | Purpose | -|---|---| -| `cdk.json` | CDK config — `app` command, `watch` globs, and feature-flag context | -| `bin/app.ts` | App entry point; instantiates the stack with explicit `stackName`, target account `396287094661`, and `us-east-1`, and reads `flowLogVpcIds` from context | -| `lib/external-dev-baseline-stack.ts` | The `seahaven-external-dev-baseline` stack; composes the constructs below | -| `lib/detective-controls.ts` | AWS Config, GuardDuty, Security Hub (FSBP + CIS v3.0), IAM Access Analyzer | -| `lib/flow-logs.ts` | VPC flow-logs bucket and (when VPC ids are supplied) flow logs | -| `lib/governance-toggles.ts` | Monthly cost Budget and alert subscriptions | - -Local workflow (from the repo root): - -```bash -npm ci -npx cdk synth # synthesize CloudFormation (also `npm run synth`) -npx cdk diff # diff against the deployed stack (`npm run diff`) -npx cdk deploy # deploy (`npm run deploy`) -``` - -`cdk.json` is committed; `cdk.out/` (synth output) and compiled `*.js` / -`*.d.ts` artifacts are git-ignored. - -## Configuration - -| Input | Where | Value | -|---|---|---| -| Target account | `bin/app.ts` | `396287094661` | -| Region | `bin/app.ts` | `us-east-1` (account is SCP region-locked) | -| Budget | `bin/app.ts` | $200/mo → `adam@seahaven.com` | -| Flow-log VPC ids | cdk context `flowLogVpcIds` | comma-separated; empty by default | - -```bash -# Deploy attaching flow logs to specific VPCs: -npm ci -npx cdk deploy -c flowLogVpcIds=vpc-aaaa,vpc-bbbb -``` - -## Post-deploy runbook - -**Enable Inspector2** (no CloudFormation enable resource exists): - -```bash -aws inspector2 enable --resource-types EC2 ECR LAMBDA --account-ids 396287094661 -``` - -This is a one-time per-account toggle; it persists across stack deploys. - -## Deployment - -CI/CD via the org reusable workflows (`ci-typescript-cdk.yaml`, `cd-cdk.yaml`, -node 24). Push to `main` deploys via GitHub OIDC into `396287094661` using the -`githubdeploy-seahaven-external-dev-baseline` role (repo secret -`AWS_DEPLOY_ROLE_ARN`). +Do not reopen development here.