Stripped fork of seahaven-account-baseline for the isolated external-dev account (396287094661). Single stack: AWS Config, GuardDuty, Security Hub (FSBP + CIS v3.0), IAM Access Analyzer, VPC flow logs (VPC ids via context), and a $200/mo budget alerting adam@seahaven.com. Drops all org-level / prod-specific controls (local CloudTrail, CIS metric alarms, WAF, SES, Bedrock, DynamoDB CMK, Backup) per the isolated-account design; the org trail already covers this account centrally. Inspector2 is a documented post-deploy CLI step (no CloudFormation enable resource exists).
79 lines
2.2 KiB
TypeScript
79 lines
2.2 KiB
TypeScript
import * as cdk from "aws-cdk-lib";
|
|
import * as budgets from "aws-cdk-lib/aws-budgets";
|
|
import { Construct } from "constructs";
|
|
|
|
export interface GovernanceTogglesProps {
|
|
/** Monthly cost budget ceiling in USD. */
|
|
readonly monthlyLimitUsd: number;
|
|
/** Email that receives the budget threshold alerts. */
|
|
readonly alertEmail: string;
|
|
}
|
|
|
|
/**
|
|
* Account-level governance toggles expressible as CloudFormation. Adapted from
|
|
* seahaven-account-baseline/lib/governance-toggles.ts.
|
|
*
|
|
* Provides a monthly AWS Budget with 80% / 100% actual + 100% forecast alerts.
|
|
* Alerts go to a Sea Haven ops address (NOT the external dev team) so cost
|
|
* surprises surface to the account owner.
|
|
*/
|
|
export class GovernanceToggles extends Construct {
|
|
constructor(scope: Construct, id: string, props: GovernanceTogglesProps) {
|
|
super(scope, id);
|
|
|
|
const subscriber = [
|
|
{
|
|
subscriptionType: "EMAIL",
|
|
address: props.alertEmail,
|
|
},
|
|
];
|
|
|
|
new budgets.CfnBudget(this, "MonthlyCostBudget", {
|
|
budget: {
|
|
budgetName: "seahaven-extdev-monthly-cost",
|
|
budgetType: "COST",
|
|
timeUnit: "MONTHLY",
|
|
budgetLimit: {
|
|
amount: props.monthlyLimitUsd,
|
|
unit: "USD",
|
|
},
|
|
},
|
|
notificationsWithSubscribers: [
|
|
{
|
|
notification: {
|
|
notificationType: "ACTUAL",
|
|
comparisonOperator: "GREATER_THAN",
|
|
threshold: 80,
|
|
thresholdType: "PERCENTAGE",
|
|
},
|
|
subscribers: subscriber,
|
|
},
|
|
{
|
|
notification: {
|
|
notificationType: "ACTUAL",
|
|
comparisonOperator: "GREATER_THAN",
|
|
threshold: 100,
|
|
thresholdType: "PERCENTAGE",
|
|
},
|
|
subscribers: subscriber,
|
|
},
|
|
{
|
|
notification: {
|
|
notificationType: "FORECASTED",
|
|
comparisonOperator: "GREATER_THAN",
|
|
threshold: 100,
|
|
thresholdType: "PERCENTAGE",
|
|
},
|
|
subscribers: subscriber,
|
|
},
|
|
],
|
|
});
|
|
|
|
cdk.Annotations.of(this).addInfo(
|
|
"Budget alerts: 80%/100% actual + 100% forecast of $" +
|
|
props.monthlyLimitUsd +
|
|
" to " +
|
|
props.alertEmail
|
|
);
|
|
}
|
|
}
|