seahaven-org-baseline/.github/workflows
Adam Moussa 0a7c1bc450
seahaven-dev account baseline with org-managed detection (Phase 4) (#49)
* Add seahaven-dev member baseline with org-managed detection

Account 710827005802 (internal dev/staging) is the first account born
after delegation: GuardDuty/Security Hub enroll it via the org admin,
so DetectiveControls gains a localDetectiveServices flag (default true
— zero diff on the three deployed consumers, verified) and the dev
instance sets orgManagedDetection to skip the colliding local
detector/hub/analyzer. Default VPC kept and flow-logged (dev runs real
workloads). Enrollment verified Enabled in both services before this
commit.

* Fix Phase-4 review findings: standards + analyzer stay CFN-owned

SH-DEV-001: org AutoEnableStandards DEFAULT gave dev legacy CIS v1.2.0
and nothing owned CIS v3.0 — org config set to NONE, standards are now
unconditional in DetectiveControls (attach fine to an org-enabled hub),
legacy ruleset disabled in dev. SH-DEVBASE-002: the ORGANIZATION
analyzer treats the whole org as trusted so it cannot flag intra-org
exposure — account analyzer restored unconditionally (coexistence
verified live). Enrollment comments corrected: manual create-members,
the automatic sweep is still unexercised. Zero diff re-verified on all
three deployed baseline stacks.
2026-07-14 16:41:36 -04:00
..
ci.yaml chore(ci): SHA-pin org reusable-workflow caller refs (INFRA-50) (#35) 2026-07-06 18:27:41 -04:00
dependency-review.yml chore(ci): SHA-pin org reusable-workflow caller refs (INFRA-50) (#35) 2026-07-06 18:27:41 -04:00
deploy.yaml seahaven-dev account baseline with org-managed detection (Phase 4) (#49) 2026-07-14 16:41:36 -04:00
labeler.yml chore(ci): SHA-pin org reusable-workflow caller refs (INFRA-50) (#35) 2026-07-06 18:27:41 -04:00