#!/usr/bin/env node import "source-map-support/register"; import * as cdk from "aws-cdk-lib"; import { AccountBaselineStack } from "../lib/account-baseline-stack"; import { BackupOffsiteStack } from "../lib/backup-offsite-stack"; import { BackupStack } from "../lib/backup-stack"; import { RegionalBaselineStack } from "../lib/regional-baseline-stack"; import { DynamoDbCmkStack } from "../lib/dynamodb-cmk-stack"; import { MemberBaselineStack } from "../lib/member-baseline-stack"; const ACCOUNT = "328440206208"; const EXTERNAL_DEV_ACCOUNT = "396287094661"; // All 5 VPCs in 328440206208 / us-east-1 (4 custom + default), audit Agent 7. // Index-derived logical IDs — append only, never reorder. const PROD_VPC_IDS = [ "vpc-061d66990b6a4d1fb", "vpc-0542a9e934b417d23", "vpc-062d200c68bd4ca0e", "vpc-0d3d4b67bd0cf8a68", "vpc-02c10a89d66f6f9b8", ]; const app = new cdk.App(); new AccountBaselineStack(app, "account-baseline", { stackName: "seahaven-account-baseline", env: { account: ACCOUNT, region: "us-east-1" }, monthlyBudgetUsd: 1200, budgetAlertEmail: "adam@seahavenind.com", flowLogVpcIds: PROD_VPC_IDS, }); // ── Member-account baseline: seahaven-external-dev ─────────────────────────── // Absorbed from the retired seahaven-external-dev-baseline repo. Stack name and // every construct id preserved byte-identically (logical IDs are path-derived — // renaming anything here replaces live resources). Deploys to the isolated // external-dev member account via its own OIDC deploy role, NOT the mgmt role. // // Flow-log VPC ids are COMMITTED here, not passed via -c context. The old // repo's `-c flowLogVpcIds=...` pattern was a confirmed security-review trap // (SH-ORG-004): once flow logs were attached via context, any context-less // deploy (including CI) would silently REMOVE them all. Append ids via PR; // never reorder (index-derived logical IDs). Empty = hardened bucket only, // matching the currently deployed stack. const EXTDEV_FLOW_LOG_VPC_IDS: string[] = []; new MemberBaselineStack(app, "external-dev-baseline", { stackName: "seahaven-external-dev-baseline", env: { account: EXTERNAL_DEV_ACCOUNT, region: "us-east-1" }, namePrefix: "seahaven-extdev", monthlyBudgetUsd: 200, // NOTE: seahaven.com (not seahavenind.com) is deliberate-as-deployed; flagged // in the 2026-07-14 security review (SH-ORG-007) for mailbox verification. budgetAlertEmail: "adam@seahaven.com", flowLogVpcIds: EXTDEV_FLOW_LOG_VPC_IDS, // Keeps the tag value the stack was deployed with (zero-diff merge). Update // to the current repo name in a deliberate follow-up change if desired. managedByTag: "seahaven-external-dev-baseline", }); // ── Shared DynamoDB CMK (INFRA-95 / M-3) ───────────────────────────────────── // Dedicated, standalone stack so the customer-managed key for sensitive // finance/PII DynamoDB tables is an independent shared dependency for the owning // app repos (payments-dashboard, procurement-ingest, exec-aide). Its ARN is // published to SSM (/seahaven/dynamodb/cmk-arn) for those stacks to consume. new DynamoDbCmkStack(app, "dynamodb-cmk", { stackName: "seahaven-dynamodb-cmk", env: { account: ACCOUNT, region: "us-east-1" }, }); // ── Secondary-region baselines (INFRA-16, INFRA-91) ────────────────────────── // The us-east-1 baseline above is region-pinned by design. These stacks extend // a minimal detective/logging footprint into the secondary regions, codifying // state applied out-of-band this week so it lives in IaC. // us-west-2: Bedrock invocation logging only (INFRA-91). Shares the region with // the offsite backup vault but is an independent concern (separate stack). new RegionalBaselineStack(app, "regional-baseline-us-west-2", { stackName: "seahaven-regional-baseline-us-west-2", env: { account: ACCOUNT, region: "us-west-2" }, bedrockLogging: true, }); // us-east-2: Bedrock invocation logging (INFRA-91) + the still-missing AWS // Config recorder and Security Hub (INFRA-16). GuardDuty + flow logs already // live here (adopted as a follow-up, see lib/regional-baseline-stack.ts). new RegionalBaselineStack(app, "regional-baseline-us-east-2", { stackName: "seahaven-regional-baseline-us-east-2", env: { account: ACCOUNT, region: "us-east-2" }, bedrockLogging: true, configRecorder: true, securityHub: true, }); // AWS Backup (audit C-7). Offsite vault (us-west-2) must exist before the // primary plan that copies to it, hence the explicit dependency. const backupOffsite = new BackupOffsiteStack(app, "backup-offsite", { stackName: "seahaven-backup-offsite", env: { account: "328440206208", region: "us-west-2" }, }); const backupPrimary = new BackupStack(app, "backup", { stackName: "seahaven-backup", env: { account: "328440206208", region: "us-east-1" }, }); backupPrimary.addDependency(backupOffsite);