# seahaven-external-dev-baseline [![CI](https://github.com/Sea-Haven-Industries/seahaven-external-dev-baseline/actions/workflows/ci.yaml/badge.svg)](https://github.com/Sea-Haven-Industries/seahaven-external-dev-baseline/actions/workflows/ci.yaml) ![TypeScript](https://img.shields.io/badge/TypeScript-3178C6?logo=typescript&logoColor=white) ![AWS CDK](https://img.shields.io/badge/AWS%20CDK-2.261.0-FF9900?logo=amazonaws&logoColor=white) Account-local security baseline (CDK, TypeScript) for **`seahaven-external-dev`** (account `396287094661`, us-east-1), the isolated AWS account used by the external web-app dev team. A stripped fork of [`seahaven-account-baseline`](https://github.com/Sea-Haven-Industries/seahaven-account-baseline). The external team works only in this account; they have no access to the management/production account `328440206208`. This stack ensures the isolated account is not a monitoring blind spot. ## Architecture Single stack `seahaven-external-dev-baseline`: | Control | Resource | Notes | |---|---|---| | AWS Config | recorder + delivery channel + `seahaven-extdev-config-` bucket | Records all supported resource types; foundation for Security Hub CIS | | GuardDuty | detector (15-min findings) | Account-local threat detection | | Security Hub | FSBP v1.0.0 + CIS AWS Foundations v3.0.0 | CIS evaluated against Config — no local trail required | | IAM Access Analyzer | account-scoped external-access analyzer | | | VPC flow logs | `seahaven-extdev-vpc-flow-logs-` bucket | ALL traffic; VPC ids passed via context | | Budget | `seahaven-extdev-monthly-cost`, $200/mo | 80%/100% actual + 100% forecast → `adam@seahaven.com` (Sea Haven ops) | ## Deliberately excluded - **No local CloudTrail.** The management-account organization trail `seahaven-org-trail` already captures this account's management + data events centrally. A second local trail would duplicate that at extra cost. - **No CIS Section-4 metric-filter alarms.** Those bind to a local CloudTrail CloudWatch Logs group, which does not exist here. The Security Hub CIS standard evaluates the same controls against AWS Config instead. - **No WAF, SES monitoring, Bedrock logging, DynamoDB CMK, or AWS Backup** — all production-only concerns in the source baseline. ## Configuration | Input | Where | Value | |---|---|---| | Target account | `bin/app.ts` | `396287094661` | | Region | `bin/app.ts` | `us-east-1` (account is SCP region-locked) | | Budget | `bin/app.ts` | $200/mo → `adam@seahaven.com` | | Flow-log VPC ids | cdk context `flowLogVpcIds` | comma-separated; empty by default | ```bash # Deploy attaching flow logs to specific VPCs: npm ci npx cdk deploy -c flowLogVpcIds=vpc-aaaa,vpc-bbbb ``` ## Post-deploy runbook **Enable Inspector2** (no CloudFormation enable resource exists): ```bash aws inspector2 enable --resource-types EC2 ECR LAMBDA --account-ids 396287094661 ``` This is a one-time per-account toggle; it persists across stack deploys. ## Deployment CI/CD via the org reusable workflows (`ci-typescript-cdk.yaml`, `cd-cdk.yaml`, node 24). Push to `main` deploys via GitHub OIDC into `396287094661` using the `githubdeploy-seahaven-external-dev-baseline` role (repo secret `AWS_DEPLOY_ROLE_ARN`).