This repository has been archived on 2026-08-04. You can view files and clone it, but cannot push or open issues or pull requests.
seahaven-external-dev-baseline/lib/external-dev-baseline-stack.ts
Adam Moussa 10555af9e2 Add account-local security baseline for seahaven-external-dev
Stripped fork of seahaven-account-baseline for the isolated external-dev
account (396287094661). Single stack: AWS Config, GuardDuty, Security Hub
(FSBP + CIS v3.0), IAM Access Analyzer, VPC flow logs (VPC ids via context),
and a $200/mo budget alerting adam@seahaven.com.

Drops all org-level / prod-specific controls (local CloudTrail, CIS metric
alarms, WAF, SES, Bedrock, DynamoDB CMK, Backup) per the isolated-account
design; the org trail already covers this account centrally. Inspector2 is a
documented post-deploy CLI step (no CloudFormation enable resource exists).
2026-06-15 11:26:23 -04:00

51 lines
2 KiB
TypeScript

import * as cdk from "aws-cdk-lib";
import { Construct } from "constructs";
import { DetectiveControls } from "./detective-controls";
import { FlowLogs } from "./flow-logs";
import { GovernanceToggles } from "./governance-toggles";
export interface ExternalDevBaselineStackProps extends cdk.StackProps {
/** Monthly cost budget ceiling in USD. */
readonly monthlyBudgetUsd: number;
/** Sea Haven ops address that receives budget alerts (not the dev team). */
readonly budgetAlertEmail: string;
/** VPC ids to attach flow logs to (from cdk context; may be empty). */
readonly flowLogVpcIds: string[];
}
/**
* Account-local security baseline for the isolated external-dev account
* (seahaven-external-dev). A stripped fork of seahaven-account-baseline.
*
* Deliberately excludes everything that is org-level or prod-specific:
* - No local CloudTrail — the management-account org trail (seahaven-org-trail)
* already captures this account's events centrally.
* - No CIS Section-4 metric-filter alarms — the Security Hub CIS standard
* evaluates those controls against Config without a local trail log group.
* - No WAF, SES monitoring, Bedrock logging, DynamoDB CMK, or AWS Backup —
* all prod-only concerns.
*
* Contains: AWS Config, GuardDuty, Security Hub (FSBP + CIS v3.0), IAM Access
* Analyzer, Inspector2, VPC flow logs, and a monthly cost Budget.
*/
export class ExternalDevBaselineStack extends cdk.Stack {
constructor(
scope: Construct,
id: string,
props: ExternalDevBaselineStackProps
) {
super(scope, id, props);
new DetectiveControls(this, "DetectiveControls");
new FlowLogs(this, "FlowLogs", { vpcIds: props.flowLogVpcIds });
new GovernanceToggles(this, "GovernanceToggles", {
monthlyLimitUsd: props.monthlyBudgetUsd,
alertEmail: props.budgetAlertEmail,
});
cdk.Tags.of(this).add("Owner", "adam@seahaven.com");
cdk.Tags.of(this).add("ManagedBy", "seahaven-external-dev-baseline");
}
}