Account-local security baseline (CDK) for the isolated external-dev AWS account 396287094661
This repository has been archived on 2026-08-04. You can view files and clone it, but cannot push or open issues or pull requests.
Find a file
dependabot[bot] e4fdfecc5e
Bump aws-cdk-lib from 2.258.0 to 2.259.0 in the minor-and-patch group
Bumps the minor-and-patch group with 1 update: [aws-cdk-lib](https://github.com/aws/aws-cdk/tree/HEAD/packages/aws-cdk-lib).


Updates `aws-cdk-lib` from 2.258.0 to 2.259.0
- [Release notes](https://github.com/aws/aws-cdk/releases)
- [Changelog](https://github.com/aws/aws-cdk/blob/main/CHANGELOG.v2.alpha.md)
- [Commits](https://github.com/aws/aws-cdk/commits/v2.259.0/packages/aws-cdk-lib)

---
updated-dependencies:
- dependency-name: aws-cdk-lib
  dependency-version: 2.259.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-06-15 15:29:49 +00:00
.github Add account-local security baseline for seahaven-external-dev 2026-06-15 11:26:23 -04:00
bin Add account-local security baseline for seahaven-external-dev 2026-06-15 11:26:23 -04:00
lib Add account-local security baseline for seahaven-external-dev 2026-06-15 11:26:23 -04:00
.gitignore Add account-local security baseline for seahaven-external-dev 2026-06-15 11:26:23 -04:00
cdk.json Add account-local security baseline for seahaven-external-dev 2026-06-15 11:26:23 -04:00
package-lock.json Bump aws-cdk-lib from 2.258.0 to 2.259.0 in the minor-and-patch group 2026-06-15 15:29:49 +00:00
package.json Bump aws-cdk-lib from 2.258.0 to 2.259.0 in the minor-and-patch group 2026-06-15 15:29:49 +00:00
README.md Add account-local security baseline for seahaven-external-dev 2026-06-15 11:26:23 -04:00
tsconfig.json Add account-local security baseline for seahaven-external-dev 2026-06-15 11:26:23 -04:00

seahaven-external-dev-baseline

Account-local security baseline (CDK, TypeScript) for seahaven-external-dev (account 396287094661, us-east-1), the isolated AWS account used by the external web-app dev team. A stripped fork of seahaven-account-baseline.

The external team works only in this account; they have no access to the management/production account 328440206208. This stack ensures the isolated account is not a monitoring blind spot.

Architecture

Single stack seahaven-external-dev-baseline:

Control Resource Notes
AWS Config recorder + delivery channel + seahaven-extdev-config-<acct> bucket Records all supported resource types; foundation for Security Hub CIS
GuardDuty detector (15-min findings) Account-local threat detection
Security Hub FSBP v1.0.0 + CIS AWS Foundations v3.0.0 CIS evaluated against Config — no local trail required
IAM Access Analyzer account-scoped external-access analyzer
VPC flow logs seahaven-extdev-vpc-flow-logs-<acct> bucket ALL traffic; VPC ids passed via context
Budget seahaven-extdev-monthly-cost, $200/mo 80%/100% actual + 100% forecast → adam@seahaven.com (Sea Haven ops)

Deliberately excluded

  • No local CloudTrail. The management-account organization trail seahaven-org-trail already captures this account's management + data events centrally. A second local trail would duplicate that at extra cost.
  • No CIS Section-4 metric-filter alarms. Those bind to a local CloudTrail CloudWatch Logs group, which does not exist here. The Security Hub CIS standard evaluates the same controls against AWS Config instead.
  • No WAF, SES monitoring, Bedrock logging, DynamoDB CMK, or AWS Backup — all production-only concerns in the source baseline.

Configuration

Input Where Value
Target account bin/app.ts 396287094661
Region bin/app.ts us-east-1 (account is SCP region-locked)
Budget bin/app.ts $200/mo → adam@seahaven.com
Flow-log VPC ids cdk context flowLogVpcIds comma-separated; empty by default
# Deploy attaching flow logs to specific VPCs:
npm ci
npx cdk deploy -c flowLogVpcIds=vpc-aaaa,vpc-bbbb

Post-deploy runbook

Enable Inspector2 (no CloudFormation enable resource exists):

aws inspector2 enable --resource-types EC2 ECR LAMBDA --account-ids 396287094661

This is a one-time per-account toggle; it persists across stack deploys.

Deployment

CI/CD via the org reusable workflows (ci-typescript-cdk.yaml, cd-cdk.yaml, node 24). Push to main deploys via GitHub OIDC into 396287094661 using the githubdeploy-seahaven-external-dev-baseline role (repo secret AWS_DEPLOY_ROLE_ARN).