* fix(iam): allow frontend HCP apply to write deploy SSM and githubdeploy trust (PLAT-212)
* fix(iam): grant frontend HCP plan named SSM describe and tag reads (PLAT-212)
* fix(iam): allow frontend githubdeploy to read deploy SSM (PLAT-212)
HCP apply already writes /shoc-frontend-new/<env>/deploy/*, but the
githubdeploy ceiling omitted GetParameter so Deploy Web cannot resolve
bucket and distribution after origin moves to the bucket root.
* fix(iam): allow staging HCP apply to update the SHOC backend EB stack (PLAT-213)
* fix(iam): allow staging HCP apply to use the Elastic Beanstalk bucket (PLAT-213)
* fix(iam): allow staging HCP apply to copy the current release zip (PLAT-213)
* fix(iam): allow staging HCP apply versioned ACLs on EB env objects (PLAT-213)
* fix(iam): give staging HCP apply the proven Elastic Beanstalk bucket grants (PLAT-213)
* fix(iam): allow staging HCP apply to write CloudFormation template buckets (PLAT-213)
* fix(iam): let staging HCP apply read Elastic Beanstalk service templates (PLAT-213)
* feat(iam): lock app-owned HCP IAM and add bootstrap SCP (PLAT-143)
* fix(iam): pin HCP boundary ARNs and bootstrap trust window (PLAT-143)
Null on iam:PermissionsBoundary accepted any ceiling, including AdministratorAccess. Import apply cannot self-mutate hcptf-* while bootstrap trust is iam-bootstrap only; add a time-boxed exact StringEquals workspace grant instead of StringLike.
AWS Chatbot's control-plane API is homed in us-east-2, so every chatbot call
carries aws:RequestedRegion=us-east-2 and is denied by the workloads-region-lock
region deny (approved set = us-east-1/us-west-2). This blocked Slack
workspace/channel setup in seahaven-prod (chatbot:GetSlackOauthParameters
denied), which the prod site-alerts topic needs for Slack delivery. Adds
chatbot:* to the SCP's global-service NotAction exemption list alongside
iam/organizations/cloudfront/route53 — a region-agnostic full-prefix exemption,
the same shape as the other global services. targetIds unchanged (workloads OU);
regional services (s3/kms/logs) and the Bedrock carve-out untouched.
GPT-4.1 cross-review: SAFE TO MERGE. /sh-security-review: block=false (0 confirmed
critical/high). Security-OU region-lock deliberately NOT changed (runs no such
workloads, same asymmetry as its missing Bedrock carve-out).
* fix(scp): carve out Bedrock InvokeModel/Converse to us-east-2 for cross-region inference
Add bedrock:InvokeModel, bedrock:InvokeModelWithResponseStream,
bedrock:Converse, and bedrock:ConverseStream to the existing
DenyRegionsOutsideApproved NotAction list so the us-east-1/us-west-2
region condition no longer denies them. Add a companion
DenyBedrockInvokeOutsideInference statement that re-denies those same
four actions outside {us-east-1, us-west-2, us-east-2}, bounding the
carve-out to us-east-2 only.
Without this, Anthropic cross-region inference profiles (us.anthropic.*)
that route InvokeModel to us-east-2 are denied, blocking all Claude
generation in workload accounts.
Refs: #53
* fix: add ACCEPTED RISK disposition, hoist Bedrock actions to shared const, mark security-asymmetry
- ACCEPTED RISK: Bedrock carve-out is resource-unscoped (NotAction
can't be resource-scoped); us-east-2 window admits four actions
against any Bedrock resource. Per-account IAM and model-access
enablement gate actual access.
- Hoist the four Bedrock invoke actions into BEDROCK_INVOKE_ACTIONS
shared const referenced by both NotAction and DenyBedrockInvoke
statements to prevent future one-sided edit divergence.
- Mark asymmetry in security-guardrails DenyRegionsOutsideApproved:
no Bedrock carve-out by design — security account runs no Bedrock
workloads.
---------
Co-authored-by: amoussa1229 <166072409+amoussa1229@users.noreply.github.com>
Extdev root credentials were deleted 2026-07-14 via centralized root
management (four-surface verified), closing the deferred root-hardening
blocker. Root recovery is central (assume-root, drill-proven) plus a
temporary gated detach, so the OU now gets the same root lockout as the
other six.
Gates: GPT-4.1 cross-review APPROVE; /sh-security-review PASS (0 confirmed
critical/high). Note: this attach puts the extdev OU at the 5-SCP hard
quota - future guardrails attach at the account or consolidate.
* Add seahaven-security member baseline (Phase 3)
Account 001520130573 is the org's delegated security administrator.
Same member-baseline construct set as external-dev; own CD job under
its own OIDC role. Created at org root pending manual root hardening
before the OU move (deny-root-user invariant).
* Document delegated security administration runbook
Delegation to seahaven-security has no CloudFormation types; the CLI
sequence is the record, same pattern as the other account toggles.
* Apply Phase-3 security-review findings
Delegation runbook marked PENDING with hard preconditions (baseline
deployed, root MFA verified, account inside the security OU) — it had
read as applied before execution, the org's known claimed-done-but-NOT
failure mode (SEC-BASE-A/B). New security-guardrails SCP on the
security OU: region lock, IAM user/key lockout, privileged-role
protection, delegated-admin membership protection (SEC-BASE-C,
cross-reviewed APPROVE). deploy-security gains stack-name pre-flight
(SEC-BASE-D). Default VPC in 001520130573 deleted; empty flow-log list
and aws@ alert routing documented as deliberate (SEC-BASE-F/H).
cdk import by Id (non-mutating), content byte-exact from
describe-policy, targetIds = exact live attachments. Post-import drift
detection: IN_SYNC, 0 drifted. All four Retain — the full org guardrail
set is now drift-checked IaC.
* Add org-governance stack: OU skeleton + generalized SCPs
Phase 2 of the multi-account segregation plan: codifies the OU tree
(workloads/prod/nonprod, security, sandbox, graveyard) and three
org-wide SCPs (workloads-region-lock, protect-security-baseline,
deny-root-user) generalized from the proven external-dev guardrails.
All resources Retain — CFN must never detach a live guardrail. New SCPs
attach only to the new empty OUs; extending to external-dev is a
separate gated targetIds change after live verification.
* Record SCP cross-review dispositions in org-governance
Root hardening must precede the OU move (deny-root-user blocks root MFA
enrollment), delegated-admin flows ride service-linked roles that SCPs
never evaluate, and the cdk exec-role exemption is accepted risk
mirroring the external-dev guardrails.
* Add org-governance to the management deploy job
Explicit stack selectors require every new stack to join exactly one
CD job (SH-ORG-005 discipline documented in this file).