* chore(deps-dev): bump typescript from 6.0.3 to 7.0.2 Bumps [typescript](https://github.com/microsoft/TypeScript) from 6.0.3 to 7.0.2. - [Release notes](https://github.com/microsoft/TypeScript/releases) - [Commits](https://github.com/microsoft/TypeScript/commits) --- updated-dependencies: - dependency-name: typescript dependency-version: 7.0.2 dependency-type: direct:development update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com> * chore: swap ts-node to tsx to bump with typescript 7.0.2 bump --------- Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: Adam Moussa <adam@seahavenind.com> |
||
|---|---|---|
| .github | ||
| bin | ||
| lib | ||
| .gitignore | ||
| cdk.json | ||
| package-lock.json | ||
| package.json | ||
| README.md | ||
| tsconfig.json | ||
seahaven-external-dev-baseline
Account-local security baseline (CDK, TypeScript) for seahaven-external-dev
(account 396287094661, us-east-1), the isolated AWS account used by the
external web-app dev team. A stripped fork of
seahaven-account-baseline.
The external team works only in this account; they have no access to the
management/production account 328440206208. This stack ensures the isolated
account is not a monitoring blind spot.
Architecture
Single stack seahaven-external-dev-baseline:
| Control | Resource | Notes |
|---|---|---|
| AWS Config | recorder + delivery channel + seahaven-extdev-config-<acct> bucket |
Records all supported resource types; foundation for Security Hub CIS |
| GuardDuty | detector (15-min findings) | Account-local threat detection |
| Security Hub | FSBP v1.0.0 + CIS AWS Foundations v3.0.0 | CIS evaluated against Config — no local trail required |
| IAM Access Analyzer | account-scoped external-access analyzer | |
| VPC flow logs | seahaven-extdev-vpc-flow-logs-<acct> bucket |
ALL traffic; VPC ids passed via context |
| Budget | seahaven-extdev-monthly-cost, $200/mo |
80%/100% actual + 100% forecast → adam@seahaven.com (Sea Haven ops) |
Deliberately excluded
- No local CloudTrail. The management-account organization trail
seahaven-org-trailalready captures this account's management + data events centrally. A second local trail would duplicate that at extra cost. - No CIS Section-4 metric-filter alarms. Those bind to a local CloudTrail CloudWatch Logs group, which does not exist here. The Security Hub CIS standard evaluates the same controls against AWS Config instead.
- No WAF, SES monitoring, Bedrock logging, DynamoDB CMK, or AWS Backup — all production-only concerns in the source baseline.
CDK app
This repo is an AWS CDK application (TypeScript). cdk.json is the CDK
entry point: it sets app to tsx bin/app.ts, so the CLI runs the
TypeScript source directly with no separate build step, and pins the CDK
feature flags / context the stack synthesizes against.
Layout follows the standard CDK project structure:
| Path | Purpose |
|---|---|
cdk.json |
CDK config — app command, watch globs, and feature-flag context |
bin/app.ts |
App entry point; instantiates the stack with explicit stackName, target account 396287094661, and us-east-1, and reads flowLogVpcIds from context |
lib/external-dev-baseline-stack.ts |
The seahaven-external-dev-baseline stack; composes the constructs below |
lib/detective-controls.ts |
AWS Config, GuardDuty, Security Hub (FSBP + CIS v3.0), IAM Access Analyzer |
lib/flow-logs.ts |
VPC flow-logs bucket and (when VPC ids are supplied) flow logs |
lib/governance-toggles.ts |
Monthly cost Budget and alert subscriptions |
Local workflow (from the repo root):
npm ci
npx cdk synth # synthesize CloudFormation (also `npm run synth`)
npx cdk diff # diff against the deployed stack (`npm run diff`)
npx cdk deploy # deploy (`npm run deploy`)
cdk.json is committed; cdk.out/ (synth output) and compiled *.js /
*.d.ts artifacts are git-ignored.
Configuration
| Input | Where | Value |
|---|---|---|
| Target account | bin/app.ts |
396287094661 |
| Region | bin/app.ts |
us-east-1 (account is SCP region-locked) |
| Budget | bin/app.ts |
$200/mo → adam@seahaven.com |
| Flow-log VPC ids | cdk context flowLogVpcIds |
comma-separated; empty by default |
# Deploy attaching flow logs to specific VPCs:
npm ci
npx cdk deploy -c flowLogVpcIds=vpc-aaaa,vpc-bbbb
Post-deploy runbook
Enable Inspector2 (no CloudFormation enable resource exists):
aws inspector2 enable --resource-types EC2 ECR LAMBDA --account-ids 396287094661
This is a one-time per-account toggle; it persists across stack deploys.
Deployment
CI/CD via the org reusable workflows (ci-typescript-cdk.yaml, cd-cdk.yaml,
node 24). Push to main deploys via GitHub OIDC into 396287094661 using the
githubdeploy-seahaven-external-dev-baseline role (repo secret
AWS_DEPLOY_ROLE_ARN).