2026-05-29 17:44:55 -04:00
|
|
|
#!/usr/bin/env node
|
|
|
|
|
import "source-map-support/register";
|
|
|
|
|
import * as cdk from "aws-cdk-lib";
|
|
|
|
|
import { AccountBaselineStack } from "../lib/account-baseline-stack";
|
Add AWS Backup with offsite vault (audit C-7) (#3)
* Add AWS Backup with offsite vault (audit C-7)
The account had zero AWS Backup vaults/plans, so 22 of 23 data stores
had no immutable, cross-region recovery path (audit finding C-7). One
ransomware event or rogue delete would erase primary plus same-region
snapshots/PITR.
Phase 1 ("critical data first") protects the seven highest-risk stores
with no offsite leg today (2 RDS, 2 DynamoDB, 3 S3) via a daily plan in
a new us-east-1 vault, copied cross-region into a governance-locked
us-west-2 vault. Governance (not compliance) mode first so the plan can
be validated before committing to irreversible immutability.
The backup service role is backup-only (no restore policies) to stay
least-privilege; restores get a separate audited path later. Resources
are selected by explicit ARN to avoid drifting the stacks that own them.
Deploys via the shared cdk deploy --all alongside the C-1 CloudTrail
stack. See the README pre-deploy gates (S3 versioning, database-1
unencrypted copy smoke-test, DynamoDB PITR) before the first run.
* Grant AWS Backup service use of vault CMKs
The L2 BackupVault does not grant the backup service principal use of a
customer-managed key; the synthesized key policy only delegated to
account IAM. Cross-region copy of encrypted RDS/EBS recovery points uses
KMS grants on the destination key, so without an explicit grant those
copy jobs fail — and silently, since the account has no CloudTrail yet.
Add backup.amazonaws.com crypto + CreateGrant statements to both vault
keys, scoped by aws:SourceAccount (cross-review BLOCK 2; mirrors the
discipline used on the C-1 CloudTrail key). Same class of bug the C-1
cross-review caught on the CloudTrail CMK.
2026-05-29 18:06:17 -04:00
|
|
|
import { BackupOffsiteStack } from "../lib/backup-offsite-stack";
|
|
|
|
|
import { BackupStack } from "../lib/backup-stack";
|
[INFRA-91/89/16/88/73] Reconcile out-of-band baseline changes + add missing detective controls (#18)
* Codify primary vault lock + add backups (INFRA-89, INFRA-88)
INFRA-89: codify the GOVERNANCE Vault Lock applied out-of-band on the
seahaven-primary vault (MinRetention 1d, MaxRetention 2555d, no
changeableFor = admin-removable) so it lives in IaC. Values match the
live lock exactly, so the deploy is a no-op adoption.
Add a scoped vault access policy that denies manual recovery-point
deletion and lock/policy tampering to all principals except the AWS
Backup service role and the break-glass SSO AdministratorAccess role,
so automatic lifecycle expiry still works but humans cannot prune
recovery points by hand.
Cross-review (GPT-4.1) BLOCK: NotPrincipal does not support wildcard
ARN matching, so the SSO exemption is expressed as Effect DENY with
Principal * and a StringNotLike condition on aws:PrincipalArn, which
does support wildcards. This avoids an unrecoverable vault lockout.
INFRA-88: add 6 S3 buckets (kb-docs, payroll-emails [PII], amazon-po,
extracted-amazon-po, proposal-system uploads + generated) to the
phase2-offsite-everything selection. Versioning verified enabled on
all 6 against the live account (S3 backup requires versioning).
Refs: INFRA-89, INFRA-88
* Promote account trail to organization trail (INFRA-73)
INFRA-73: set isOrganizationTrail on seahaven-org-trail and pass orgId
(o-9kufuzz6b4) so the L2 Trail attaches the AWSLogs/<org-id>/* bucket
PutObject statement for member-account delivery. CloudTrail org
trusted-access is already enabled on the management account.
Broaden the KMS key policy with an org-scoped GenerateDataKey/DescribeKey
statement for member-account trail delivery, guarded by
aws:PrincipalOrgID. The existing single-account statements are
preserved so management-account delivery is unaffected.
Cross-review (GPT-4.1) BLOCK: the member KMS SourceArn and encryption
context must be wildcarded across accounts (org-trail shadow trails
present the member account id), not pinned to the management account,
or member delivery silently fails. Fixed before checkpoint.
CHECKPOINT: delicate org-trail KMS/bucket-policy change — code +
diff captured for review, NOT deployed.
Refs: INFRA-73
* Add secondary-region baseline stacks (INFRA-91, INFRA-16)
INFRA-91: codify the Bedrock model-invocation logging applied
out-of-band in us-west-2 and us-east-2 (per-region delivery role
seahaven-bedrock-invocation-logging-<region> + log group
/aws/bedrock/model-invocations 90d, CloudWatch-only). The account-level
logging config itself has no CFN resource type and is applied via CLI
(already live), same as us-east-1.
INFRA-16: add the still-missing us-east-2 detective controls — AWS
Config recorder role + delivery bucket (recorder/channel via CLI to
avoid the CFN stabilization deadlock seen in us-east-1) and Security
Hub with FSBP + CIS v3.0. GuardDuty + flow logs already live in
us-east-2 and are left for a follow-up adoption to keep this change
non-destructive.
The us-east-1 baseline stays region-pinned; these are separate
RegionalBaselineStack instances composed opt-in per region.
CHECKPOINT: new multi-region stacks. The live Bedrock role + log group
already exist (CLI-created), so a plain deploy would collide — these
need cdk import / changeset adoption, not cdk deploy. Code + diff
captured for review, NOT deployed.
Refs: INFRA-91, INFRA-16
* Drop vault access policy from this deploy; tracked in INFRA-94 (kept governance lock codify + selection)
2026-06-08 17:03:18 -04:00
|
|
|
import { RegionalBaselineStack } from "../lib/regional-baseline-stack";
|
2026-06-08 19:04:42 -04:00
|
|
|
import { DynamoDbCmkStack } from "../lib/dynamodb-cmk-stack";
|
2026-07-14 13:53:07 -04:00
|
|
|
import { MemberBaselineStack } from "../lib/member-baseline-stack";
|
2026-07-14 14:02:30 -04:00
|
|
|
import { OrgGovernanceStack } from "../lib/org-governance-stack";
|
[INFRA-91/89/16/88/73] Reconcile out-of-band baseline changes + add missing detective controls (#18)
* Codify primary vault lock + add backups (INFRA-89, INFRA-88)
INFRA-89: codify the GOVERNANCE Vault Lock applied out-of-band on the
seahaven-primary vault (MinRetention 1d, MaxRetention 2555d, no
changeableFor = admin-removable) so it lives in IaC. Values match the
live lock exactly, so the deploy is a no-op adoption.
Add a scoped vault access policy that denies manual recovery-point
deletion and lock/policy tampering to all principals except the AWS
Backup service role and the break-glass SSO AdministratorAccess role,
so automatic lifecycle expiry still works but humans cannot prune
recovery points by hand.
Cross-review (GPT-4.1) BLOCK: NotPrincipal does not support wildcard
ARN matching, so the SSO exemption is expressed as Effect DENY with
Principal * and a StringNotLike condition on aws:PrincipalArn, which
does support wildcards. This avoids an unrecoverable vault lockout.
INFRA-88: add 6 S3 buckets (kb-docs, payroll-emails [PII], amazon-po,
extracted-amazon-po, proposal-system uploads + generated) to the
phase2-offsite-everything selection. Versioning verified enabled on
all 6 against the live account (S3 backup requires versioning).
Refs: INFRA-89, INFRA-88
* Promote account trail to organization trail (INFRA-73)
INFRA-73: set isOrganizationTrail on seahaven-org-trail and pass orgId
(o-9kufuzz6b4) so the L2 Trail attaches the AWSLogs/<org-id>/* bucket
PutObject statement for member-account delivery. CloudTrail org
trusted-access is already enabled on the management account.
Broaden the KMS key policy with an org-scoped GenerateDataKey/DescribeKey
statement for member-account trail delivery, guarded by
aws:PrincipalOrgID. The existing single-account statements are
preserved so management-account delivery is unaffected.
Cross-review (GPT-4.1) BLOCK: the member KMS SourceArn and encryption
context must be wildcarded across accounts (org-trail shadow trails
present the member account id), not pinned to the management account,
or member delivery silently fails. Fixed before checkpoint.
CHECKPOINT: delicate org-trail KMS/bucket-policy change — code +
diff captured for review, NOT deployed.
Refs: INFRA-73
* Add secondary-region baseline stacks (INFRA-91, INFRA-16)
INFRA-91: codify the Bedrock model-invocation logging applied
out-of-band in us-west-2 and us-east-2 (per-region delivery role
seahaven-bedrock-invocation-logging-<region> + log group
/aws/bedrock/model-invocations 90d, CloudWatch-only). The account-level
logging config itself has no CFN resource type and is applied via CLI
(already live), same as us-east-1.
INFRA-16: add the still-missing us-east-2 detective controls — AWS
Config recorder role + delivery bucket (recorder/channel via CLI to
avoid the CFN stabilization deadlock seen in us-east-1) and Security
Hub with FSBP + CIS v3.0. GuardDuty + flow logs already live in
us-east-2 and are left for a follow-up adoption to keep this change
non-destructive.
The us-east-1 baseline stays region-pinned; these are separate
RegionalBaselineStack instances composed opt-in per region.
CHECKPOINT: new multi-region stacks. The live Bedrock role + log group
already exist (CLI-created), so a plain deploy would collide — these
need cdk import / changeset adoption, not cdk deploy. Code + diff
captured for review, NOT deployed.
Refs: INFRA-91, INFRA-16
* Drop vault access policy from this deploy; tracked in INFRA-94 (kept governance lock codify + selection)
2026-06-08 17:03:18 -04:00
|
|
|
|
|
|
|
|
const ACCOUNT = "328440206208";
|
2026-07-14 13:53:07 -04:00
|
|
|
const EXTERNAL_DEV_ACCOUNT = "396287094661";
|
2026-07-14 15:32:50 -04:00
|
|
|
const SECURITY_ACCOUNT = "001520130573";
|
2026-07-14 16:41:36 -04:00
|
|
|
const DEV_ACCOUNT = "710827005802";
|
2026-07-14 17:17:55 -04:00
|
|
|
const PROD_ACCOUNT = "011934824531";
|
2026-07-14 13:53:07 -04:00
|
|
|
|
|
|
|
|
// All 5 VPCs in 328440206208 / us-east-1 (4 custom + default), audit Agent 7.
|
|
|
|
|
// Index-derived logical IDs — append only, never reorder.
|
|
|
|
|
const PROD_VPC_IDS = [
|
|
|
|
|
"vpc-061d66990b6a4d1fb",
|
|
|
|
|
"vpc-0542a9e934b417d23",
|
|
|
|
|
"vpc-062d200c68bd4ca0e",
|
|
|
|
|
"vpc-0d3d4b67bd0cf8a68",
|
|
|
|
|
"vpc-02c10a89d66f6f9b8",
|
|
|
|
|
];
|
2026-05-29 17:44:55 -04:00
|
|
|
|
|
|
|
|
const app = new cdk.App();
|
|
|
|
|
|
|
|
|
|
new AccountBaselineStack(app, "account-baseline", {
|
|
|
|
|
stackName: "seahaven-account-baseline",
|
[INFRA-91/89/16/88/73] Reconcile out-of-band baseline changes + add missing detective controls (#18)
* Codify primary vault lock + add backups (INFRA-89, INFRA-88)
INFRA-89: codify the GOVERNANCE Vault Lock applied out-of-band on the
seahaven-primary vault (MinRetention 1d, MaxRetention 2555d, no
changeableFor = admin-removable) so it lives in IaC. Values match the
live lock exactly, so the deploy is a no-op adoption.
Add a scoped vault access policy that denies manual recovery-point
deletion and lock/policy tampering to all principals except the AWS
Backup service role and the break-glass SSO AdministratorAccess role,
so automatic lifecycle expiry still works but humans cannot prune
recovery points by hand.
Cross-review (GPT-4.1) BLOCK: NotPrincipal does not support wildcard
ARN matching, so the SSO exemption is expressed as Effect DENY with
Principal * and a StringNotLike condition on aws:PrincipalArn, which
does support wildcards. This avoids an unrecoverable vault lockout.
INFRA-88: add 6 S3 buckets (kb-docs, payroll-emails [PII], amazon-po,
extracted-amazon-po, proposal-system uploads + generated) to the
phase2-offsite-everything selection. Versioning verified enabled on
all 6 against the live account (S3 backup requires versioning).
Refs: INFRA-89, INFRA-88
* Promote account trail to organization trail (INFRA-73)
INFRA-73: set isOrganizationTrail on seahaven-org-trail and pass orgId
(o-9kufuzz6b4) so the L2 Trail attaches the AWSLogs/<org-id>/* bucket
PutObject statement for member-account delivery. CloudTrail org
trusted-access is already enabled on the management account.
Broaden the KMS key policy with an org-scoped GenerateDataKey/DescribeKey
statement for member-account trail delivery, guarded by
aws:PrincipalOrgID. The existing single-account statements are
preserved so management-account delivery is unaffected.
Cross-review (GPT-4.1) BLOCK: the member KMS SourceArn and encryption
context must be wildcarded across accounts (org-trail shadow trails
present the member account id), not pinned to the management account,
or member delivery silently fails. Fixed before checkpoint.
CHECKPOINT: delicate org-trail KMS/bucket-policy change — code +
diff captured for review, NOT deployed.
Refs: INFRA-73
* Add secondary-region baseline stacks (INFRA-91, INFRA-16)
INFRA-91: codify the Bedrock model-invocation logging applied
out-of-band in us-west-2 and us-east-2 (per-region delivery role
seahaven-bedrock-invocation-logging-<region> + log group
/aws/bedrock/model-invocations 90d, CloudWatch-only). The account-level
logging config itself has no CFN resource type and is applied via CLI
(already live), same as us-east-1.
INFRA-16: add the still-missing us-east-2 detective controls — AWS
Config recorder role + delivery bucket (recorder/channel via CLI to
avoid the CFN stabilization deadlock seen in us-east-1) and Security
Hub with FSBP + CIS v3.0. GuardDuty + flow logs already live in
us-east-2 and are left for a follow-up adoption to keep this change
non-destructive.
The us-east-1 baseline stays region-pinned; these are separate
RegionalBaselineStack instances composed opt-in per region.
CHECKPOINT: new multi-region stacks. The live Bedrock role + log group
already exist (CLI-created), so a plain deploy would collide — these
need cdk import / changeset adoption, not cdk deploy. Code + diff
captured for review, NOT deployed.
Refs: INFRA-91, INFRA-16
* Drop vault access policy from this deploy; tracked in INFRA-94 (kept governance lock codify + selection)
2026-06-08 17:03:18 -04:00
|
|
|
env: { account: ACCOUNT, region: "us-east-1" },
|
2026-06-01 17:56:12 -04:00
|
|
|
monthlyBudgetUsd: 1200,
|
2026-07-14 14:41:42 -04:00
|
|
|
// Dedicated AWS-notifications mailbox (Adam, 2026-07-14). Also feeds the CIS
|
|
|
|
|
// alarm SNS subscription — a changed endpoint must CONFIRM via the email
|
|
|
|
|
// link before alarm notifications flow again.
|
|
|
|
|
budgetAlertEmail: "aws@seahaven.com",
|
2026-07-14 13:53:07 -04:00
|
|
|
flowLogVpcIds: PROD_VPC_IDS,
|
|
|
|
|
});
|
|
|
|
|
|
|
|
|
|
// ── Member-account baseline: seahaven-external-dev ───────────────────────────
|
|
|
|
|
// Absorbed from the retired seahaven-external-dev-baseline repo. Stack name and
|
|
|
|
|
// every construct id preserved byte-identically (logical IDs are path-derived —
|
|
|
|
|
// renaming anything here replaces live resources). Deploys to the isolated
|
|
|
|
|
// external-dev member account via its own OIDC deploy role, NOT the mgmt role.
|
|
|
|
|
//
|
|
|
|
|
// Flow-log VPC ids are COMMITTED here, not passed via -c context. The old
|
|
|
|
|
// repo's `-c flowLogVpcIds=...` pattern was a confirmed security-review trap
|
|
|
|
|
// (SH-ORG-004): once flow logs were attached via context, any context-less
|
|
|
|
|
// deploy (including CI) would silently REMOVE them all. Append ids via PR;
|
|
|
|
|
// never reorder (index-derived logical IDs). Empty = hardened bucket only,
|
|
|
|
|
// matching the currently deployed stack.
|
|
|
|
|
const EXTDEV_FLOW_LOG_VPC_IDS: string[] = [];
|
|
|
|
|
|
2026-07-14 14:02:30 -04:00
|
|
|
// ── Org structure: OUs + generalized SCPs (management account only) ─────────
|
|
|
|
|
// Existing external-dev OU + its 3 SCPs are adopted into this stack via
|
|
|
|
|
// `cdk import` post-deploy — see lib/org-governance-stack.ts header + README.
|
|
|
|
|
new OrgGovernanceStack(app, "org-governance", {
|
|
|
|
|
stackName: "seahaven-org-governance",
|
|
|
|
|
env: { account: ACCOUNT, region: "us-east-1" },
|
|
|
|
|
});
|
|
|
|
|
|
2026-07-14 13:53:07 -04:00
|
|
|
new MemberBaselineStack(app, "external-dev-baseline", {
|
|
|
|
|
stackName: "seahaven-external-dev-baseline",
|
|
|
|
|
env: { account: EXTERNAL_DEV_ACCOUNT, region: "us-east-1" },
|
|
|
|
|
namePrefix: "seahaven-extdev",
|
|
|
|
|
monthlyBudgetUsd: 200,
|
2026-07-14 14:41:42 -04:00
|
|
|
// Account-dedicated AWS-notifications mailbox (Adam, 2026-07-14 — resolves
|
|
|
|
|
// security-review flag SH-ORG-007).
|
|
|
|
|
budgetAlertEmail: "aws-external-dev@seahaven.com",
|
|
|
|
|
ownerEmail: "adam@seahaven.com",
|
2026-07-14 13:53:07 -04:00
|
|
|
flowLogVpcIds: EXTDEV_FLOW_LOG_VPC_IDS,
|
|
|
|
|
// Keeps the tag value the stack was deployed with (zero-diff merge). Update
|
|
|
|
|
// to the current repo name in a deliberate follow-up change if desired.
|
|
|
|
|
managedByTag: "seahaven-external-dev-baseline",
|
2026-05-29 17:44:55 -04:00
|
|
|
});
|
Add AWS Backup with offsite vault (audit C-7) (#3)
* Add AWS Backup with offsite vault (audit C-7)
The account had zero AWS Backup vaults/plans, so 22 of 23 data stores
had no immutable, cross-region recovery path (audit finding C-7). One
ransomware event or rogue delete would erase primary plus same-region
snapshots/PITR.
Phase 1 ("critical data first") protects the seven highest-risk stores
with no offsite leg today (2 RDS, 2 DynamoDB, 3 S3) via a daily plan in
a new us-east-1 vault, copied cross-region into a governance-locked
us-west-2 vault. Governance (not compliance) mode first so the plan can
be validated before committing to irreversible immutability.
The backup service role is backup-only (no restore policies) to stay
least-privilege; restores get a separate audited path later. Resources
are selected by explicit ARN to avoid drifting the stacks that own them.
Deploys via the shared cdk deploy --all alongside the C-1 CloudTrail
stack. See the README pre-deploy gates (S3 versioning, database-1
unencrypted copy smoke-test, DynamoDB PITR) before the first run.
* Grant AWS Backup service use of vault CMKs
The L2 BackupVault does not grant the backup service principal use of a
customer-managed key; the synthesized key policy only delegated to
account IAM. Cross-region copy of encrypted RDS/EBS recovery points uses
KMS grants on the destination key, so without an explicit grant those
copy jobs fail — and silently, since the account has no CloudTrail yet.
Add backup.amazonaws.com crypto + CreateGrant statements to both vault
keys, scoped by aws:SourceAccount (cross-review BLOCK 2; mirrors the
discipline used on the C-1 CloudTrail key). Same class of bug the C-1
cross-review caught on the CloudTrail CMK.
2026-05-29 18:06:17 -04:00
|
|
|
|
2026-07-14 15:32:50 -04:00
|
|
|
// ── Member-account baseline: seahaven-security (Phase 3) ────────────────────
|
|
|
|
|
// The org's delegated security administrator-to-be (GuardDuty / Security Hub /
|
|
|
|
|
// IAM Access Analyzer / Config aggregator / Inspector2 — delegation is CLI +
|
|
|
|
|
// README runbook with HARD preconditions, no CFN types). Created 2026-07-14 at
|
|
|
|
|
// org ROOT; moves into the security OU only after manual root hardening
|
|
|
|
|
// (deny-root-user invariant, see lib/org-governance-stack.ts). Delegation runs
|
|
|
|
|
// ONLY after the OU move (SEC-BASE-B).
|
|
|
|
|
// LIFECYCLE (SEC-BASE-E): once delegation is live, this stack's GuardDuty
|
|
|
|
|
// detector + Security Hub hub are co-managed by the org admin config — never
|
|
|
|
|
// rename/remove those constructs via CFN while the account is delegated admin.
|
|
|
|
|
new MemberBaselineStack(app, "security-baseline", {
|
|
|
|
|
stackName: "seahaven-security-baseline",
|
|
|
|
|
env: { account: SECURITY_ACCOUNT, region: "us-east-1" },
|
|
|
|
|
namePrefix: "seahaven-security",
|
|
|
|
|
monthlyBudgetUsd: 50,
|
|
|
|
|
// aws@ (not a per-account mailbox) is deliberate: Adam's 2026-07-14
|
|
|
|
|
// direction routes all AWS notifications to aws@seahaven.com; extdev's
|
|
|
|
|
// dedicated mailbox predates that direction.
|
|
|
|
|
budgetAlertEmail: "aws@seahaven.com",
|
|
|
|
|
ownerEmail: "adam@seahaven.com",
|
|
|
|
|
// Empty is deliberate: the account's default VPC is DELETED (a delegated
|
|
|
|
|
// security-admin account runs no workloads — SEC-BASE-F; also clears the
|
|
|
|
|
// default-VPC CIS/FSBP controls). Any future VPC id gets appended via PR.
|
|
|
|
|
flowLogVpcIds: [],
|
|
|
|
|
managedByTag: "seahaven-org-baseline",
|
|
|
|
|
});
|
|
|
|
|
|
2026-07-14 16:41:36 -04:00
|
|
|
// ── Member-account baseline: seahaven-dev (Phase 4) ─────────────────────────
|
|
|
|
|
// Internal dev/staging workloads (NOT the external-dev engagement account).
|
|
|
|
|
// Created 2026-07-14 AFTER org delegation went live: GuardDuty detector +
|
|
|
|
|
// Security Hub hub are org-managed — enrolled via delegated-admin
|
2026-07-14 17:17:55 -04:00
|
|
|
// create-members and verified Enabled (the AUTOMATIC sweep was later proven
|
|
|
|
|
// on seahaven-prod, ~2min; still verify enrollment before any org-managed
|
|
|
|
|
// stack's first deploy). Standards and
|
2026-07-14 16:41:36 -04:00
|
|
|
// the account analyzer stay CFN-owned (SH-DEV-001/SH-DEVBASE-002). Same
|
|
|
|
|
// lifecycle rule as the other new accounts: root-harden at org ROOT, then
|
|
|
|
|
// move-account into the nonprod OU (ou-nbuj-zpt5ka98) — NO WORKLOADS until
|
|
|
|
|
// the account is inside the OU (SH-DEV-002: until then no region lock, no
|
|
|
|
|
// baseline-tamper SCP, usable root).
|
|
|
|
|
new MemberBaselineStack(app, "dev-baseline", {
|
|
|
|
|
stackName: "seahaven-dev-baseline",
|
|
|
|
|
env: { account: DEV_ACCOUNT, region: "us-east-1" },
|
|
|
|
|
namePrefix: "seahaven-dev",
|
|
|
|
|
monthlyBudgetUsd: 150,
|
|
|
|
|
budgetAlertEmail: "aws@seahaven.com",
|
|
|
|
|
ownerEmail: "adam@seahaven.com",
|
|
|
|
|
// Default VPC kept (dev runs real workloads); flow-logged from this stack's
|
|
|
|
|
// first deploy. Index-derived logical IDs — append only, never reorder
|
|
|
|
|
// (replacing the default VPC later = append the new id, keep this entry
|
|
|
|
|
// until its flow log is deliberately retired).
|
|
|
|
|
flowLogVpcIds: ["vpc-08f07dc5edeea621f"],
|
|
|
|
|
managedByTag: "seahaven-org-baseline",
|
|
|
|
|
orgManagedDetection: true,
|
|
|
|
|
});
|
|
|
|
|
|
2026-07-14 17:17:55 -04:00
|
|
|
// ── Member-account baseline: seahaven-prod (Phase 5) ────────────────────────
|
|
|
|
|
// Target for ALL new production stacks (mgmt 328440206208 is frozen for new
|
|
|
|
|
// workloads). First tenant: proposal-system redeploy. Detection is org-managed
|
|
|
|
|
// (AUTO-enrolled by the sweep in 124s — first proven exercise, 2026-07-14 —
|
|
|
|
|
// and verified Enabled before this stack's first deploy); standards + account
|
|
|
|
|
// analyzer are CFN-owned per the Phase-4 review. Default VPC DELETED (prod
|
|
|
|
|
// workloads use purpose-built VPCs). Same lifecycle rule: root-harden at org
|
|
|
|
|
// ROOT, then move-account into the prod OU (ou-nbuj-5lc2wp6h) — NO WORKLOADS
|
|
|
|
|
// until the account is inside the OU. Budget starts at $100 and is resized as
|
|
|
|
|
// tenants land; AWS Backup vaults are added with the first stateful tenant
|
|
|
|
|
// (cross-account restore test = definition of done for that change).
|
|
|
|
|
new MemberBaselineStack(app, "prod-baseline", {
|
|
|
|
|
stackName: "seahaven-prod-baseline",
|
|
|
|
|
env: { account: PROD_ACCOUNT, region: "us-east-1" },
|
|
|
|
|
namePrefix: "seahaven-prod",
|
|
|
|
|
monthlyBudgetUsd: 100,
|
|
|
|
|
budgetAlertEmail: "aws@seahaven.com",
|
|
|
|
|
ownerEmail: "adam@seahaven.com",
|
|
|
|
|
// Append-only, never reorder (index-derived logical IDs). Empty: no VPCs
|
|
|
|
|
// exist yet; append ids via PR as purpose-built VPCs land.
|
|
|
|
|
flowLogVpcIds: [],
|
|
|
|
|
managedByTag: "seahaven-org-baseline",
|
|
|
|
|
orgManagedDetection: true,
|
|
|
|
|
});
|
|
|
|
|
|
2026-06-08 19:04:42 -04:00
|
|
|
// ── Shared DynamoDB CMK (INFRA-95 / M-3) ─────────────────────────────────────
|
|
|
|
|
// Dedicated, standalone stack so the customer-managed key for sensitive
|
|
|
|
|
// finance/PII DynamoDB tables is an independent shared dependency for the owning
|
|
|
|
|
// app repos (payments-dashboard, procurement-ingest, exec-aide). Its ARN is
|
|
|
|
|
// published to SSM (/seahaven/dynamodb/cmk-arn) for those stacks to consume.
|
|
|
|
|
new DynamoDbCmkStack(app, "dynamodb-cmk", {
|
|
|
|
|
stackName: "seahaven-dynamodb-cmk",
|
|
|
|
|
env: { account: ACCOUNT, region: "us-east-1" },
|
|
|
|
|
});
|
|
|
|
|
|
[INFRA-91/89/16/88/73] Reconcile out-of-band baseline changes + add missing detective controls (#18)
* Codify primary vault lock + add backups (INFRA-89, INFRA-88)
INFRA-89: codify the GOVERNANCE Vault Lock applied out-of-band on the
seahaven-primary vault (MinRetention 1d, MaxRetention 2555d, no
changeableFor = admin-removable) so it lives in IaC. Values match the
live lock exactly, so the deploy is a no-op adoption.
Add a scoped vault access policy that denies manual recovery-point
deletion and lock/policy tampering to all principals except the AWS
Backup service role and the break-glass SSO AdministratorAccess role,
so automatic lifecycle expiry still works but humans cannot prune
recovery points by hand.
Cross-review (GPT-4.1) BLOCK: NotPrincipal does not support wildcard
ARN matching, so the SSO exemption is expressed as Effect DENY with
Principal * and a StringNotLike condition on aws:PrincipalArn, which
does support wildcards. This avoids an unrecoverable vault lockout.
INFRA-88: add 6 S3 buckets (kb-docs, payroll-emails [PII], amazon-po,
extracted-amazon-po, proposal-system uploads + generated) to the
phase2-offsite-everything selection. Versioning verified enabled on
all 6 against the live account (S3 backup requires versioning).
Refs: INFRA-89, INFRA-88
* Promote account trail to organization trail (INFRA-73)
INFRA-73: set isOrganizationTrail on seahaven-org-trail and pass orgId
(o-9kufuzz6b4) so the L2 Trail attaches the AWSLogs/<org-id>/* bucket
PutObject statement for member-account delivery. CloudTrail org
trusted-access is already enabled on the management account.
Broaden the KMS key policy with an org-scoped GenerateDataKey/DescribeKey
statement for member-account trail delivery, guarded by
aws:PrincipalOrgID. The existing single-account statements are
preserved so management-account delivery is unaffected.
Cross-review (GPT-4.1) BLOCK: the member KMS SourceArn and encryption
context must be wildcarded across accounts (org-trail shadow trails
present the member account id), not pinned to the management account,
or member delivery silently fails. Fixed before checkpoint.
CHECKPOINT: delicate org-trail KMS/bucket-policy change — code +
diff captured for review, NOT deployed.
Refs: INFRA-73
* Add secondary-region baseline stacks (INFRA-91, INFRA-16)
INFRA-91: codify the Bedrock model-invocation logging applied
out-of-band in us-west-2 and us-east-2 (per-region delivery role
seahaven-bedrock-invocation-logging-<region> + log group
/aws/bedrock/model-invocations 90d, CloudWatch-only). The account-level
logging config itself has no CFN resource type and is applied via CLI
(already live), same as us-east-1.
INFRA-16: add the still-missing us-east-2 detective controls — AWS
Config recorder role + delivery bucket (recorder/channel via CLI to
avoid the CFN stabilization deadlock seen in us-east-1) and Security
Hub with FSBP + CIS v3.0. GuardDuty + flow logs already live in
us-east-2 and are left for a follow-up adoption to keep this change
non-destructive.
The us-east-1 baseline stays region-pinned; these are separate
RegionalBaselineStack instances composed opt-in per region.
CHECKPOINT: new multi-region stacks. The live Bedrock role + log group
already exist (CLI-created), so a plain deploy would collide — these
need cdk import / changeset adoption, not cdk deploy. Code + diff
captured for review, NOT deployed.
Refs: INFRA-91, INFRA-16
* Drop vault access policy from this deploy; tracked in INFRA-94 (kept governance lock codify + selection)
2026-06-08 17:03:18 -04:00
|
|
|
// ── Secondary-region baselines (INFRA-16, INFRA-91) ──────────────────────────
|
|
|
|
|
// The us-east-1 baseline above is region-pinned by design. These stacks extend
|
|
|
|
|
// a minimal detective/logging footprint into the secondary regions, codifying
|
|
|
|
|
// state applied out-of-band this week so it lives in IaC.
|
|
|
|
|
|
|
|
|
|
// us-west-2: Bedrock invocation logging only (INFRA-91). Shares the region with
|
|
|
|
|
// the offsite backup vault but is an independent concern (separate stack).
|
|
|
|
|
new RegionalBaselineStack(app, "regional-baseline-us-west-2", {
|
|
|
|
|
stackName: "seahaven-regional-baseline-us-west-2",
|
|
|
|
|
env: { account: ACCOUNT, region: "us-west-2" },
|
|
|
|
|
bedrockLogging: true,
|
|
|
|
|
});
|
|
|
|
|
|
|
|
|
|
// us-east-2: Bedrock invocation logging (INFRA-91) + the still-missing AWS
|
|
|
|
|
// Config recorder and Security Hub (INFRA-16). GuardDuty + flow logs already
|
|
|
|
|
// live here (adopted as a follow-up, see lib/regional-baseline-stack.ts).
|
|
|
|
|
new RegionalBaselineStack(app, "regional-baseline-us-east-2", {
|
|
|
|
|
stackName: "seahaven-regional-baseline-us-east-2",
|
|
|
|
|
env: { account: ACCOUNT, region: "us-east-2" },
|
|
|
|
|
bedrockLogging: true,
|
|
|
|
|
configRecorder: true,
|
|
|
|
|
securityHub: true,
|
|
|
|
|
});
|
|
|
|
|
|
Add AWS Backup with offsite vault (audit C-7) (#3)
* Add AWS Backup with offsite vault (audit C-7)
The account had zero AWS Backup vaults/plans, so 22 of 23 data stores
had no immutable, cross-region recovery path (audit finding C-7). One
ransomware event or rogue delete would erase primary plus same-region
snapshots/PITR.
Phase 1 ("critical data first") protects the seven highest-risk stores
with no offsite leg today (2 RDS, 2 DynamoDB, 3 S3) via a daily plan in
a new us-east-1 vault, copied cross-region into a governance-locked
us-west-2 vault. Governance (not compliance) mode first so the plan can
be validated before committing to irreversible immutability.
The backup service role is backup-only (no restore policies) to stay
least-privilege; restores get a separate audited path later. Resources
are selected by explicit ARN to avoid drifting the stacks that own them.
Deploys via the shared cdk deploy --all alongside the C-1 CloudTrail
stack. See the README pre-deploy gates (S3 versioning, database-1
unencrypted copy smoke-test, DynamoDB PITR) before the first run.
* Grant AWS Backup service use of vault CMKs
The L2 BackupVault does not grant the backup service principal use of a
customer-managed key; the synthesized key policy only delegated to
account IAM. Cross-region copy of encrypted RDS/EBS recovery points uses
KMS grants on the destination key, so without an explicit grant those
copy jobs fail — and silently, since the account has no CloudTrail yet.
Add backup.amazonaws.com crypto + CreateGrant statements to both vault
keys, scoped by aws:SourceAccount (cross-review BLOCK 2; mirrors the
discipline used on the C-1 CloudTrail key). Same class of bug the C-1
cross-review caught on the CloudTrail CMK.
2026-05-29 18:06:17 -04:00
|
|
|
// AWS Backup (audit C-7). Offsite vault (us-west-2) must exist before the
|
|
|
|
|
// primary plan that copies to it, hence the explicit dependency.
|
|
|
|
|
const backupOffsite = new BackupOffsiteStack(app, "backup-offsite", {
|
|
|
|
|
stackName: "seahaven-backup-offsite",
|
|
|
|
|
env: { account: "328440206208", region: "us-west-2" },
|
|
|
|
|
});
|
|
|
|
|
|
|
|
|
|
const backupPrimary = new BackupStack(app, "backup", {
|
|
|
|
|
stackName: "seahaven-backup",
|
|
|
|
|
env: { account: "328440206208", region: "us-east-1" },
|
|
|
|
|
});
|
|
|
|
|
|
2026-07-23 13:38:17 -04:00
|
|
|
backupPrimary.addStackDependency(backupOffsite);
|