#!/usr/bin/env node import "source-map-support/register"; import * as cdk from "aws-cdk-lib"; import { AccountBaselineStack } from "../lib/account-baseline-stack"; import { AlarmTopicStack } from "../lib/alarm-topic-stack"; import { BackupOffsiteStack } from "../lib/backup-offsite-stack"; import { BackupStack } from "../lib/backup-stack"; import { RegionalBaselineStack } from "../lib/regional-baseline-stack"; import { DeploySubstrateStack } from "../lib/deploy-substrate-stack"; import { TerraformSubstrateStack } from "../lib/terraform-substrate-stack"; import { DynamoDbCmkStack } from "../lib/dynamodb-cmk-stack"; import { AppWebAclStack } from "../lib/app-web-acl-stack"; import { MemberBaselineStack } from "../lib/member-baseline-stack"; import { OrgGovernanceStack } from "../lib/org-governance-stack"; const ACCOUNT = "328440206208"; const EXTERNAL_DEV_ACCOUNT = "396287094661"; const SECURITY_ACCOUNT = "001520130573"; const DEV_ACCOUNT = "710827005802"; const PROD_ACCOUNT = "011934824531"; // All 5 VPCs in 328440206208 / us-east-1 (4 custom + default), audit Agent 7. // Index-derived logical IDs — append only, never reorder. const PROD_VPC_IDS = [ "vpc-061d66990b6a4d1fb", "vpc-0542a9e934b417d23", "vpc-062d200c68bd4ca0e", "vpc-0d3d4b67bd0cf8a68", "vpc-02c10a89d66f6f9b8", ]; const app = new cdk.App(); const contextBoolean = (key: string): boolean => { const value = app.node.tryGetContext(key); if (value === true || value === "true") return true; if (value === false || value === "false" || value === undefined) return false; throw new Error(`${key} must be true or false`); }; const contextString = (key: string): string => { const value = app.node.tryGetContext(key); if (value === undefined) return ""; if (typeof value === "string") return value; throw new Error(`${key} must be a string`); }; new AccountBaselineStack(app, "account-baseline", { stackName: "seahaven-account-baseline", env: { account: ACCOUNT, region: "us-east-1" }, monthlyBudgetUsd: 1200, // Dedicated AWS-notifications mailbox (Adam, 2026-07-14). Also feeds the CIS // alarm SNS subscription — a changed endpoint must CONFIRM via the email // link before alarm notifications flow again. budgetAlertEmail: "aws@seahaven.com", flowLogVpcIds: PROD_VPC_IDS, }); // ── Member-account baseline: seahaven-external-dev ─────────────────────────── // Absorbed from the retired seahaven-external-dev-baseline repo. Stack name and // every construct id preserved byte-identically (logical IDs are path-derived — // renaming anything here replaces live resources). Deploys to the isolated // external-dev member account via its own OIDC deploy role, NOT the mgmt role. // // Flow-log VPC ids are COMMITTED here, not passed via -c context. The old // repo's `-c flowLogVpcIds=...` pattern was a confirmed security-review trap // (SH-ORG-004): once flow logs were attached via context, any context-less // deploy (including CI) would silently REMOVE them all. Append ids via PR; // never reorder (index-derived logical IDs). Empty = hardened bucket only, // matching the currently deployed stack. const EXTDEV_FLOW_LOG_VPC_IDS: string[] = []; // ── Org structure: OUs + generalized SCPs (management account only) ───────── // Existing external-dev OU + its 3 SCPs are adopted into this stack via // `cdk import` post-deploy — see lib/org-governance-stack.ts header + README. new OrgGovernanceStack(app, "org-governance", { stackName: "seahaven-org-governance", env: { account: ACCOUNT, region: "us-east-1" }, }); new MemberBaselineStack(app, "external-dev-baseline", { stackName: "seahaven-external-dev-baseline", env: { account: EXTERNAL_DEV_ACCOUNT, region: "us-east-1" }, namePrefix: "seahaven-extdev", monthlyBudgetUsd: 200, // Account-dedicated AWS-notifications mailbox (Adam, 2026-07-14 — resolves // security-review flag SH-ORG-007). budgetAlertEmail: "aws-external-dev@seahaven.com", ownerEmail: "adam@seahaven.com", flowLogVpcIds: EXTDEV_FLOW_LOG_VPC_IDS, // Keeps the tag value the stack was deployed with (zero-diff merge). Update // to the current repo name in a deliberate follow-up change if desired. managedByTag: "seahaven-external-dev-baseline", }); // ── Member-account baseline: seahaven-security (Phase 3) ──────────────────── // The org's delegated security administrator-to-be (GuardDuty / Security Hub / // IAM Access Analyzer / Config aggregator / Inspector2 — delegation is CLI + // README runbook with HARD preconditions, no CFN types). Created 2026-07-14 at // org ROOT; moves into the security OU only after manual root hardening // (deny-root-user invariant, see lib/org-governance-stack.ts). Delegation runs // ONLY after the OU move (SEC-BASE-B). // LIFECYCLE (SEC-BASE-E): once delegation is live, this stack's GuardDuty // detector + Security Hub hub are co-managed by the org admin config — never // rename/remove those constructs via CFN while the account is delegated admin. new MemberBaselineStack(app, "security-baseline", { stackName: "seahaven-security-baseline", env: { account: SECURITY_ACCOUNT, region: "us-east-1" }, namePrefix: "seahaven-security", monthlyBudgetUsd: 50, // aws@ (not a per-account mailbox) is deliberate: Adam's 2026-07-14 // direction routes all AWS notifications to aws@seahaven.com; extdev's // dedicated mailbox predates that direction. budgetAlertEmail: "aws@seahaven.com", ownerEmail: "adam@seahaven.com", // Empty is deliberate: the account's default VPC is DELETED (a delegated // security-admin account runs no workloads — SEC-BASE-F; also clears the // default-VPC CIS/FSBP controls). Any future VPC id gets appended via PR. flowLogVpcIds: [], managedByTag: "seahaven-org-baseline", }); // ── Member-account baseline: seahaven-dev (Phase 4) ───────────────────────── // Internal dev/staging workloads (NOT the external-dev engagement account). // Created 2026-07-14 AFTER org delegation went live: GuardDuty detector + // Security Hub hub are org-managed — enrolled via delegated-admin // create-members and verified Enabled (the AUTOMATIC sweep was later proven // on seahaven-prod, ~2min; still verify enrollment before any org-managed // stack's first deploy). Standards and // the account analyzer stay CFN-owned (SH-DEV-001/SH-DEVBASE-002). Same // lifecycle rule as the other new accounts: root-harden at org ROOT, then // move-account into the nonprod OU (ou-nbuj-zpt5ka98) — NO WORKLOADS until // the account is inside the OU (SH-DEV-002: until then no region lock, no // baseline-tamper SCP, usable root). new MemberBaselineStack(app, "dev-baseline", { stackName: "seahaven-dev-baseline", env: { account: DEV_ACCOUNT, region: "us-east-1" }, namePrefix: "seahaven-dev", monthlyBudgetUsd: 150, budgetAlertEmail: "aws@seahaven.com", ownerEmail: "adam@seahaven.com", // Default VPC kept (dev runs real workloads); flow-logged from this stack's // first deploy. Index-derived logical IDs — append only, never reorder // (replacing the default VPC later = append the new id, keep this entry // until its flow log is deliberately retired). flowLogVpcIds: ["vpc-08f07dc5edeea621f"], managedByTag: "seahaven-org-baseline", orgManagedDetection: true, }); // ── Member-account baseline: seahaven-prod (Phase 5) ──────────────────────── // Target for ALL new production stacks (mgmt 328440206208 is frozen for new // workloads). First tenant: proposal-system redeploy. Detection is org-managed // (AUTO-enrolled by the sweep in 124s — first proven exercise, 2026-07-14 — // and verified Enabled before this stack's first deploy); standards + account // analyzer are CFN-owned per the Phase-4 review. Default VPC DELETED (prod // workloads use purpose-built VPCs). Same lifecycle rule: root-harden at org // ROOT, then move-account into the prod OU (ou-nbuj-5lc2wp6h) — NO WORKLOADS // until the account is inside the OU. Budget starts at $100 and is resized as // tenants land; AWS Backup vaults are added with the first stateful tenant // (cross-account restore test = definition of done for that change). new MemberBaselineStack(app, "prod-baseline", { stackName: "seahaven-prod-baseline", env: { account: PROD_ACCOUNT, region: "us-east-1" }, namePrefix: "seahaven-prod", monthlyBudgetUsd: 100, budgetAlertEmail: "aws@seahaven.com", ownerEmail: "adam@seahaven.com", // Append-only, never reorder (index-derived logical IDs). Empty: no VPCs // exist yet; append ids via PR as purpose-built VPCs land. flowLogVpcIds: [], managedByTag: "seahaven-org-baseline", orgManagedDetection: true, }); // ── Per-account GitHub Actions deploy substrate ────────────────────────────── // The shared account-level deploy plumbing for SAM pipelines: permissions // boundary + github-cfn-execution-role (+ optional OIDC provider). mgmt's // copy lives in Sea-Haven-Industries/.github/oidc-deploy-roles.yaml and stays // there until its stacks finish migrating out; these stacks are what let SAM // repos (payments-dashboard, front-integrations, sh-openswe-traces, ...) // target prod/dev at all. Per-repo githubdeploy-* roles are provisioned at // each repo's migration time, never here. createOidcProvider stays false for // both accounts (provider verified present in each, 2026-07-27); a FUTURE // member account without one sets it true on its own instance. First-create // precondition verified 2026-07-27: github-cfn-execution-role and the // seahaven-lambda-execution-boundary policy both returned NoSuchEntity in // 011934824531 AND 710827005802, so the named creates cannot collide with // out-of-band copies. const deploySubstrateProd = new DeploySubstrateStack(app, "deploy-substrate-prod", { stackName: "seahaven-deploy-substrate", env: { account: PROD_ACCOUNT, region: "us-east-1" }, createOidcProvider: false, }); const deploySubstrateDev = new DeploySubstrateStack(app, "deploy-substrate-dev", { stackName: "seahaven-deploy-substrate", env: { account: DEV_ACCOUNT, region: "us-east-1" }, createOidcProvider: false, }); // ── Per-account HCP Terraform deploy substrate ─────────────────────────────── // Prod/dev instances still exist until PLAT-147: they own the live eight // hcptf- pairs (DeletionPolicy Retain) and seahaven-hcptf-iam-management. // Do not append new prod/dev workspace roles here. Do not add a CDK stack for // hcptf-bootstrap (CLI-owned, PLAT-145). External-dev stays: SHOC IAM is not // moving (PLAT-148). deploy-substrate stays for remaining SAM (PLAT-150). // The guardrail policy names seahaven-lambda-execution-boundary ARNs only // inside Condition strings, so CFN infers no creation edge — the explicit // dependency below keeps deploy-substrate first while these stacks remain. const terraformSubstrateProd = new TerraformSubstrateStack( app, "terraform-substrate-prod", { stackName: "seahaven-terraform-substrate", env: { account: PROD_ACCOUNT, region: "us-east-1" }, }, ); terraformSubstrateProd.addStackDependency(deploySubstrateProd); // Shared CloudFront WAF for seahaven-prod (PLAT-92). Same AppWebAcl construct // as mgmt account-baseline; thin stack so prod does not inherit the full // mgmt baseline. Publishes /seahaven/waf/app-web-acl-arn for in-account // CloudFront associations (same-account only). new AppWebAclStack(app, "app-web-acl-prod", { stackName: "seahaven-app-web-acl", env: { account: PROD_ACCOUNT, region: "us-east-1" }, }); const terraformSubstrateDev = new TerraformSubstrateStack( app, "terraform-substrate-dev", { stackName: "seahaven-terraform-substrate", env: { account: DEV_ACCOUNT, region: "us-east-1" }, }, ); terraformSubstrateDev.addStackDependency(deploySubstrateDev); // External-dev already has app.terraform.io federation. Both role gates start // false in cdk.json: POC is enabled by a normal update; dev/staging only by // CloudFormation import after Terraform relinquishes those four live roles. const terraformSubstrateExternalDev = new TerraformSubstrateStack( app, "terraform-substrate-external-dev", { stackName: "seahaven-terraform-substrate", env: { account: EXTERNAL_DEV_ACCOUNT, region: "us-east-1" }, createOidcProvider: false, enableShocBackendPocRoles: contextBoolean("enableShocBackendPocRoles"), enableShocBackendLiveRoles: contextBoolean("enableShocBackendLiveRoles"), enableShocFrontendPocRoles: contextBoolean("enableShocFrontendPocRoles"), enableShocFrontendLiveRoles: contextBoolean("enableShocFrontendLiveRoles"), shocFrontendPocDistributionId: contextString( "shocFrontendPocDistributionId", ), shocFrontendPocOriginAccessControlId: contextString( "shocFrontendPocOriginAccessControlId", ), shocFrontendPocFunctionName: contextString( "shocFrontendPocFunctionName", ), shocFrontendPocHostedZoneId: contextString( "shocFrontendPocHostedZoneId", ), shocFrontendPocCertificateArn: contextString( "shocFrontendPocCertificateArn", ), }, ); // ── Shared DynamoDB CMK (INFRA-95 / M-3) ───────────────────────────────────── // Dedicated, standalone stack so the customer-managed key for sensitive // finance/PII DynamoDB tables is an independent shared dependency for the owning // app repos (payments-dashboard, procurement-ingest, exec-aide). Its ARN is // published to SSM (/seahaven/dynamodb/cmk-arn) for those stacks to consume. new DynamoDbCmkStack(app, "dynamodb-cmk", { stackName: "seahaven-dynamodb-cmk", env: { account: ACCOUNT, region: "us-east-1" }, }); // ── seahaven-prod copies for the procurement-ingest migration ──────────────── // procurement-ingest is moving from mgmt to seahaven-prod; its stacks resolve // the DynamoDB CMK via SSM /seahaven/dynamodb/cmk-arn and import the SNS topic // `site-alerts` by constructed in-account ARN, so both must exist in prod // BEFORE that app's first prod deploy. Same stack names as mgmt (unique // per-account); distinct CDK ids. // No cross-account key-policy statement: the only cross-account reader of the // CMK-encrypted purchase-orders table (seahaven-slack-bot) was decommissioned // 2026-07-23, and its successor sh-mcp is undeployed and uses same-account // DynamoDB access. When/if a cross-account consumer materializes, add a // correctly-scoped grant then (target its real roles + account). // // Recovery note (failed FIRST create): the key is RETAIN, its alias/SSM param // are not — a CREATE_FAILED rollback orphans an unaliased rotation-enabled // key. Before re-running the deploy, list unaliased CMKs in prod and schedule // deletion of the orphan. new DynamoDbCmkStack(app, "dynamodb-cmk-prod", { stackName: "seahaven-dynamodb-cmk", env: { account: PROD_ACCOUNT, region: "us-east-1" }, }); new AlarmTopicStack(app, "alarm-topic-prod", { stackName: "seahaven-alarm-topic", env: { account: PROD_ACCOUNT, region: "us-east-1" }, }); // ── Secondary-region baselines (INFRA-16, INFRA-91) ────────────────────────── // The us-east-1 baseline above is region-pinned by design. These stacks extend // a minimal detective/logging footprint into the secondary regions, codifying // state applied out-of-band this week so it lives in IaC. // us-west-2: Bedrock invocation logging only (INFRA-91). Shares the region with // the offsite backup vault but is an independent concern (separate stack). new RegionalBaselineStack(app, "regional-baseline-us-west-2", { stackName: "seahaven-regional-baseline-us-west-2", env: { account: ACCOUNT, region: "us-west-2" }, bedrockLogging: true, }); // us-east-2: Bedrock invocation logging (INFRA-91) + the still-missing AWS // Config recorder and Security Hub (INFRA-16). GuardDuty + flow logs already // live here (adopted as a follow-up, see lib/regional-baseline-stack.ts). new RegionalBaselineStack(app, "regional-baseline-us-east-2", { stackName: "seahaven-regional-baseline-us-east-2", env: { account: ACCOUNT, region: "us-east-2" }, bedrockLogging: true, configRecorder: true, securityHub: true, }); // AWS Backup (audit C-7). Offsite vault (us-west-2) must exist before the // primary plan that copies to it, hence the explicit dependency. const backupOffsite = new BackupOffsiteStack(app, "backup-offsite", { stackName: "seahaven-backup-offsite", env: { account: "328440206208", region: "us-west-2" }, }); const backupPrimary = new BackupStack(app, "backup", { stackName: "seahaven-backup", env: { account: "328440206208", region: "us-east-1" }, }); backupPrimary.addStackDependency(backupOffsite);