Stripped fork of seahaven-account-baseline for the isolated external-dev account (396287094661). Single stack: AWS Config, GuardDuty, Security Hub (FSBP + CIS v3.0), IAM Access Analyzer, VPC flow logs (VPC ids via context), and a $200/mo budget alerting adam@seahaven.com. Drops all org-level / prod-specific controls (local CloudTrail, CIS metric alarms, WAF, SES, Bedrock, DynamoDB CMK, Backup) per the isolated-account design; the org trail already covers this account centrally. Inspector2 is a documented post-deploy CLI step (no CloudFormation enable resource exists).
29 lines
1 KiB
JavaScript
29 lines
1 KiB
JavaScript
#!/usr/bin/env node
|
|
import "source-map-support/register";
|
|
import * as cdk from "aws-cdk-lib";
|
|
import { ExternalDevBaselineStack } from "../lib/external-dev-baseline-stack";
|
|
|
|
// Isolated external-dev member account (seahaven-external-dev), us-east-1 only.
|
|
const ACCOUNT = "396287094661";
|
|
|
|
const app = new cdk.App();
|
|
|
|
// Flow-log VPC ids come from context, NOT hardcoded — this account's VPCs change
|
|
// as the external dev team provisions their own infrastructure. Pass via:
|
|
// cdk deploy -c flowLogVpcIds=vpc-aaaa,vpc-bbbb
|
|
// Empty (default) creates the hardened flow-logs bucket with no flow logs yet.
|
|
const vpcCtx = app.node.tryGetContext("flowLogVpcIds");
|
|
const flowLogVpcIds: string[] = vpcCtx
|
|
? String(vpcCtx)
|
|
.split(",")
|
|
.map((s) => s.trim())
|
|
.filter(Boolean)
|
|
: [];
|
|
|
|
new ExternalDevBaselineStack(app, "external-dev-baseline", {
|
|
stackName: "seahaven-external-dev-baseline",
|
|
env: { account: ACCOUNT, region: "us-east-1" },
|
|
monthlyBudgetUsd: 200,
|
|
budgetAlertEmail: "adam@seahaven.com",
|
|
flowLogVpcIds,
|
|
});
|