Archive: absorbed into seahaven-org-baseline
Stack and deploy role live on, managed from the merged repo. Repo is archived read-only.
This commit is contained in:
parent
e510a8777d
commit
5d60d01e54
1 changed files with 13 additions and 97 deletions
110
README.md
110
README.md
|
|
@ -1,100 +1,16 @@
|
|||
# seahaven-external-dev-baseline
|
||||
# seahaven-external-dev-baseline — ARCHIVED
|
||||
|
||||
[](https://github.com/Sea-Haven-Industries/seahaven-external-dev-baseline/actions/workflows/ci.yaml)
|
||||

|
||||

|
||||
**This repo was absorbed into
|
||||
[seahaven-org-baseline](https://github.com/Sea-Haven-Industries/seahaven-org-baseline)
|
||||
on 2026-07-14** (multi-account segregation plan Phase 1).
|
||||
|
||||
Account-local security baseline (CDK, TypeScript) for **`seahaven-external-dev`**
|
||||
(account `396287094661`, us-east-1), the isolated AWS account used by the
|
||||
external web-app dev team. A stripped fork of
|
||||
[`seahaven-account-baseline`](https://github.com/Sea-Haven-Industries/seahaven-account-baseline).
|
||||
- The deployed CloudFormation stack `seahaven-external-dev-baseline`
|
||||
(account 396287094661) is unchanged and now managed from
|
||||
`seahaven-org-baseline` (`lib/member-baseline-stack.ts`, CD job
|
||||
`deploy-external-dev`).
|
||||
- The OIDC deploy role `githubdeploy-seahaven-external-dev-baseline` now
|
||||
trusts only `seahaven-org-baseline`.
|
||||
- History of the original code lives in this repo's git history and continues
|
||||
in the merged repo.
|
||||
|
||||
The external team works only in this account; they have no access to the
|
||||
management/production account `328440206208`. This stack ensures the isolated
|
||||
account is not a monitoring blind spot.
|
||||
|
||||
## Architecture
|
||||
|
||||
Single stack `seahaven-external-dev-baseline`:
|
||||
|
||||
| Control | Resource | Notes |
|
||||
|---|---|---|
|
||||
| AWS Config | recorder + delivery channel + `seahaven-extdev-config-<acct>` bucket | Records all supported resource types; foundation for Security Hub CIS |
|
||||
| GuardDuty | detector (15-min findings) | Account-local threat detection |
|
||||
| Security Hub | FSBP v1.0.0 + CIS AWS Foundations v3.0.0 | CIS evaluated against Config — no local trail required |
|
||||
| IAM Access Analyzer | account-scoped external-access analyzer | |
|
||||
| VPC flow logs | `seahaven-extdev-vpc-flow-logs-<acct>` bucket | ALL traffic; VPC ids passed via context |
|
||||
| Budget | `seahaven-extdev-monthly-cost`, $200/mo | 80%/100% actual + 100% forecast → `adam@seahaven.com` (Sea Haven ops) |
|
||||
|
||||
## Deliberately excluded
|
||||
|
||||
- **No local CloudTrail.** The management-account organization trail
|
||||
`seahaven-org-trail` already captures this account's management + data events
|
||||
centrally. A second local trail would duplicate that at extra cost.
|
||||
- **No CIS Section-4 metric-filter alarms.** Those bind to a local CloudTrail
|
||||
CloudWatch Logs group, which does not exist here. The Security Hub CIS
|
||||
standard evaluates the same controls against AWS Config instead.
|
||||
- **No WAF, SES monitoring, Bedrock logging, DynamoDB CMK, or AWS Backup** —
|
||||
all production-only concerns in the source baseline.
|
||||
|
||||
## CDK app
|
||||
|
||||
This repo is an AWS CDK application (TypeScript). `cdk.json` is the CDK
|
||||
entry point: it sets `app` to `tsx bin/app.ts`, so the CLI runs the
|
||||
TypeScript source directly with no separate build step, and pins the CDK
|
||||
feature flags / context the stack synthesizes against.
|
||||
|
||||
Layout follows the standard CDK project structure:
|
||||
|
||||
| Path | Purpose |
|
||||
|---|---|
|
||||
| `cdk.json` | CDK config — `app` command, `watch` globs, and feature-flag context |
|
||||
| `bin/app.ts` | App entry point; instantiates the stack with explicit `stackName`, target account `396287094661`, and `us-east-1`, and reads `flowLogVpcIds` from context |
|
||||
| `lib/external-dev-baseline-stack.ts` | The `seahaven-external-dev-baseline` stack; composes the constructs below |
|
||||
| `lib/detective-controls.ts` | AWS Config, GuardDuty, Security Hub (FSBP + CIS v3.0), IAM Access Analyzer |
|
||||
| `lib/flow-logs.ts` | VPC flow-logs bucket and (when VPC ids are supplied) flow logs |
|
||||
| `lib/governance-toggles.ts` | Monthly cost Budget and alert subscriptions |
|
||||
|
||||
Local workflow (from the repo root):
|
||||
|
||||
```bash
|
||||
npm ci
|
||||
npx cdk synth # synthesize CloudFormation (also `npm run synth`)
|
||||
npx cdk diff # diff against the deployed stack (`npm run diff`)
|
||||
npx cdk deploy # deploy (`npm run deploy`)
|
||||
```
|
||||
|
||||
`cdk.json` is committed; `cdk.out/` (synth output) and compiled `*.js` /
|
||||
`*.d.ts` artifacts are git-ignored.
|
||||
|
||||
## Configuration
|
||||
|
||||
| Input | Where | Value |
|
||||
|---|---|---|
|
||||
| Target account | `bin/app.ts` | `396287094661` |
|
||||
| Region | `bin/app.ts` | `us-east-1` (account is SCP region-locked) |
|
||||
| Budget | `bin/app.ts` | $200/mo → `adam@seahaven.com` |
|
||||
| Flow-log VPC ids | cdk context `flowLogVpcIds` | comma-separated; empty by default |
|
||||
|
||||
```bash
|
||||
# Deploy attaching flow logs to specific VPCs:
|
||||
npm ci
|
||||
npx cdk deploy -c flowLogVpcIds=vpc-aaaa,vpc-bbbb
|
||||
```
|
||||
|
||||
## Post-deploy runbook
|
||||
|
||||
**Enable Inspector2** (no CloudFormation enable resource exists):
|
||||
|
||||
```bash
|
||||
aws inspector2 enable --resource-types EC2 ECR LAMBDA --account-ids 396287094661
|
||||
```
|
||||
|
||||
This is a one-time per-account toggle; it persists across stack deploys.
|
||||
|
||||
## Deployment
|
||||
|
||||
CI/CD via the org reusable workflows (`ci-typescript-cdk.yaml`, `cd-cdk.yaml`,
|
||||
node 24). Push to `main` deploys via GitHub OIDC into `396287094661` using the
|
||||
`githubdeploy-seahaven-external-dev-baseline` role (repo secret
|
||||
`AWS_DEPLOY_ROLE_ARN`).
|
||||
Do not reopen development here.
|
||||
|
|
|
|||
Reference in a new issue