Commit graph

5 commits

Author SHA1 Message Date
Adam Moussa
3ab3bc773a
Merge external-dev member baseline; rename to seahaven-org-baseline (#43)
* Parameterize baseline constructs for multi-account reuse

DetectiveControls, FlowLogs, and GovernanceToggles were forked into
seahaven-external-dev-baseline with only physical-name and VPC-sourcing
differences. Prefix/name props let one implementation serve both
accounts; synthesized templates are unchanged (verified: empty cdk diff
against all deployed stacks).

* Absorb external-dev member baseline stack

Moves seahaven-external-dev-baseline's stack in as MemberBaselineStack,
construct ids and physical names byte-identical to the deployed stack
(logical IDs are path-derived; empty cdk diff verified via change set
against 396287094661). Retires the forked repo so member-account
baselines share one drift surface and one dependency pin.

* Rename package to seahaven-org-baseline

Prepares the repo rename: the app now spans the management account and
org member accounts, so 'account-baseline' undersells the scope. README
documents the two-account deploy topology and logical-ID constraints.

* Commit extdev flow-log VPC ids in code, not -c context

Security review SH-ORG-004 (confirmed high): with the ids sourced from
ephemeral cdk context, any context-less deploy silently removes every
flow log in the isolated account. A committed list makes the attachment
set reviewable and immune to a forgotten -c flag. Empty list matches
the deployed stack (zero diff).

* Split CD into per-account deploy jobs

The app now spans two AWS accounts; cdk deploy --all under one role
fails on the other account's stacks (security review IAC-01). Each job
passes explicit stack selectors and its own account's OIDC role via the
new cd-cdk stacks input.
2026-07-14 13:53:07 -04:00
Adam Moussa
6ce8b96b22
chore(ci): SHA-pin org reusable-workflow caller refs (INFRA-50) (#35) 2026-07-06 18:27:41 -04:00
Adam Moussa
6a63a4f9b0
Repo hygiene: PR labeler + README badges (INFRA-56/57) (#26) 2026-06-11 14:42:34 -04:00
Adam Moussa
05b0f95c4f
Add dependency-review caller workflow (#14)
* Add dependency-review caller workflow

Add a pull_request-triggered caller that invokes the org-level
callable-dependency-review workflow to scan dependency changes and
fail on high-severity advisories.

* chore: retrigger checks

* chore: retrigger dep review (post-fix)
2026-06-05 12:26:57 -04:00
Adam Moussa
dc079edb93 Initial account-baseline stack with CloudTrail (audit C-1)
Multi-region CloudTrail with log-file validation, a rotating KMS CMK, an
Object-Lock'd S3 log bucket, and CloudWatch Logs delivery. First resident of
the account-level security baseline; AWS Backup / 3-2-1 (C-7) lands alongside.

IAM/KMS/S3 policies cross-reviewed; review caught a missing CloudTrail KMS
grant, now added (SourceArn + encryption-context scoped).
2026-05-29 17:44:55 -04:00