This repository has been archived on 2026-08-04. You can view files and clone it, but cannot push or open issues or pull requests.
seahaven-external-dev-baseline/.github/workflows/deploy.yaml
Adam Moussa 10555af9e2 Add account-local security baseline for seahaven-external-dev
Stripped fork of seahaven-account-baseline for the isolated external-dev
account (396287094661). Single stack: AWS Config, GuardDuty, Security Hub
(FSBP + CIS v3.0), IAM Access Analyzer, VPC flow logs (VPC ids via context),
and a $200/mo budget alerting adam@seahaven.com.

Drops all org-level / prod-specific controls (local CloudTrail, CIS metric
alarms, WAF, SES, Bedrock, DynamoDB CMK, Backup) per the isolated-account
design; the org trail already covers this account centrally. Inspector2 is a
documented post-deploy CLI step (no CloudFormation enable resource exists).
2026-06-15 11:26:23 -04:00

20 lines
350 B
YAML

name: Deploy
on:
push:
branches: [main]
permissions:
id-token: write
contents: read
concurrency:
group: deploy
cancel-in-progress: false
jobs:
deploy:
uses: Sea-Haven-Industries/.github/.github/workflows/cd-cdk.yaml@main
with:
node-version: "24"
secrets:
deploy-role-arn: ${{ secrets.AWS_DEPLOY_ROLE_ARN }}