The README covered the deployed controls, config inputs, and CI/CD but
never explained that the repo is a CDK app or what cdk.json does. Add a
CDK app section describing the cdk.json entry point, project layout
(bin/app.ts and the lib/ constructs), and the local synth/diff/deploy
workflow so contributors can orient without reading the source.
Stripped fork of seahaven-account-baseline for the isolated external-dev
account (396287094661). Single stack: AWS Config, GuardDuty, Security Hub
(FSBP + CIS v3.0), IAM Access Analyzer, VPC flow logs (VPC ids via context),
and a $200/mo budget alerting adam@seahaven.com.
Drops all org-level / prod-specific controls (local CloudTrail, CIS metric
alarms, WAF, SES, Bedrock, DynamoDB CMK, Backup) per the isolated-account
design; the org trail already covers this account centrally. Inspector2 is a
documented post-deploy CLI step (no CloudFormation enable resource exists).