Stripped fork of seahaven-account-baseline for the isolated external-dev account (396287094661). Single stack: AWS Config, GuardDuty, Security Hub (FSBP + CIS v3.0), IAM Access Analyzer, VPC flow logs (VPC ids via context), and a $200/mo budget alerting adam@seahaven.com. Drops all org-level / prod-specific controls (local CloudTrail, CIS metric alarms, WAF, SES, Bedrock, DynamoDB CMK, Backup) per the isolated-account design; the org trail already covers this account centrally. Inspector2 is a documented post-deploy CLI step (no CloudFormation enable resource exists).
22 lines
440 B
JSON
22 lines
440 B
JSON
{
|
|
"app": "npx ts-node bin/app.ts",
|
|
"watch": {
|
|
"include": ["**"],
|
|
"exclude": [
|
|
"README.md",
|
|
"cdk*.json",
|
|
"**/*.d.ts",
|
|
"**/*.js",
|
|
"tsconfig.json",
|
|
"package*.json",
|
|
"node_modules",
|
|
"test",
|
|
"cdk.out"
|
|
]
|
|
},
|
|
"context": {
|
|
"@aws-cdk/aws-lambda:recognizeLayerVersion": true,
|
|
"@aws-cdk/core:checkSecretUsage": true,
|
|
"@aws-cdk/core:target-partitions": ["aws"]
|
|
}
|
|
}
|