This repository has been archived on 2026-08-04. You can view files and clone it, but cannot push or open issues or pull requests.
seahaven-external-dev-baseline/lib/governance-toggles.ts
Adam Moussa 10555af9e2 Add account-local security baseline for seahaven-external-dev
Stripped fork of seahaven-account-baseline for the isolated external-dev
account (396287094661). Single stack: AWS Config, GuardDuty, Security Hub
(FSBP + CIS v3.0), IAM Access Analyzer, VPC flow logs (VPC ids via context),
and a $200/mo budget alerting adam@seahaven.com.

Drops all org-level / prod-specific controls (local CloudTrail, CIS metric
alarms, WAF, SES, Bedrock, DynamoDB CMK, Backup) per the isolated-account
design; the org trail already covers this account centrally. Inspector2 is a
documented post-deploy CLI step (no CloudFormation enable resource exists).
2026-06-15 11:26:23 -04:00

79 lines
2.2 KiB
TypeScript

import * as cdk from "aws-cdk-lib";
import * as budgets from "aws-cdk-lib/aws-budgets";
import { Construct } from "constructs";
export interface GovernanceTogglesProps {
/** Monthly cost budget ceiling in USD. */
readonly monthlyLimitUsd: number;
/** Email that receives the budget threshold alerts. */
readonly alertEmail: string;
}
/**
* Account-level governance toggles expressible as CloudFormation. Adapted from
* seahaven-account-baseline/lib/governance-toggles.ts.
*
* Provides a monthly AWS Budget with 80% / 100% actual + 100% forecast alerts.
* Alerts go to a Sea Haven ops address (NOT the external dev team) so cost
* surprises surface to the account owner.
*/
export class GovernanceToggles extends Construct {
constructor(scope: Construct, id: string, props: GovernanceTogglesProps) {
super(scope, id);
const subscriber = [
{
subscriptionType: "EMAIL",
address: props.alertEmail,
},
];
new budgets.CfnBudget(this, "MonthlyCostBudget", {
budget: {
budgetName: "seahaven-extdev-monthly-cost",
budgetType: "COST",
timeUnit: "MONTHLY",
budgetLimit: {
amount: props.monthlyLimitUsd,
unit: "USD",
},
},
notificationsWithSubscribers: [
{
notification: {
notificationType: "ACTUAL",
comparisonOperator: "GREATER_THAN",
threshold: 80,
thresholdType: "PERCENTAGE",
},
subscribers: subscriber,
},
{
notification: {
notificationType: "ACTUAL",
comparisonOperator: "GREATER_THAN",
threshold: 100,
thresholdType: "PERCENTAGE",
},
subscribers: subscriber,
},
{
notification: {
notificationType: "FORECASTED",
comparisonOperator: "GREATER_THAN",
threshold: 100,
thresholdType: "PERCENTAGE",
},
subscribers: subscriber,
},
],
});
cdk.Annotations.of(this).addInfo(
"Budget alerts: 80%/100% actual + 100% forecast of $" +
props.monthlyLimitUsd +
" to " +
props.alertEmail
);
}
}