mirror of
https://github.com/Sea-Haven-Industries/seahaven-org-baseline.git
synced 2026-09-30 06:53:17 +00:00
* Add seahaven-dev member baseline with org-managed detection Account 710827005802 (internal dev/staging) is the first account born after delegation: GuardDuty/Security Hub enroll it via the org admin, so DetectiveControls gains a localDetectiveServices flag (default true — zero diff on the three deployed consumers, verified) and the dev instance sets orgManagedDetection to skip the colliding local detector/hub/analyzer. Default VPC kept and flow-logged (dev runs real workloads). Enrollment verified Enabled in both services before this commit. * Fix Phase-4 review findings: standards + analyzer stay CFN-owned SH-DEV-001: org AutoEnableStandards DEFAULT gave dev legacy CIS v1.2.0 and nothing owned CIS v3.0 — org config set to NONE, standards are now unconditional in DetectiveControls (attach fine to an org-enabled hub), legacy ruleset disabled in dev. SH-DEVBASE-002: the ORGANIZATION analyzer treats the whole org as trusted so it cannot flag intra-org exposure — account analyzer restored unconditionally (coexistence verified live). Enrollment comments corrected: manual create-members, the automatic sweep is still unexercised. Zero diff re-verified on all three deployed baseline stacks.
52 lines
1.8 KiB
YAML
52 lines
1.8 KiB
YAML
name: Deploy
|
|
on:
|
|
push:
|
|
branches: [main]
|
|
|
|
permissions:
|
|
id-token: write
|
|
contents: read
|
|
|
|
concurrency:
|
|
group: deploy
|
|
cancel-in-progress: false
|
|
|
|
# One job per target AWS account: cdk deploy with explicit stack selectors so
|
|
# each OIDC role only ever deploys its own account's stacks. A new stack added
|
|
# to bin/app.ts MUST be appended to exactly one job's `stacks` list — explicit
|
|
# selectors mean an unlisted stack is silently never deployed (security review
|
|
# SH-ORG-005).
|
|
jobs:
|
|
deploy-management:
|
|
uses: Sea-Haven-Industries/.github/.github/workflows/cd-cdk.yaml@3cde673b9d05c0e68aac4d997d582f2543853d20 # main
|
|
with:
|
|
node-version: "24"
|
|
stacks: "account-baseline dynamodb-cmk regional-baseline-us-west-2 regional-baseline-us-east-2 backup-offsite backup org-governance"
|
|
secrets:
|
|
deploy-role-arn: ${{ secrets.AWS_DEPLOY_ROLE_ARN }}
|
|
|
|
deploy-external-dev:
|
|
uses: Sea-Haven-Industries/.github/.github/workflows/cd-cdk.yaml@3cde673b9d05c0e68aac4d997d582f2543853d20 # main
|
|
with:
|
|
node-version: "24"
|
|
stacks: "external-dev-baseline"
|
|
secrets:
|
|
deploy-role-arn: ${{ secrets.AWS_DEPLOY_ROLE_ARN_EXTDEV }}
|
|
|
|
deploy-security:
|
|
uses: Sea-Haven-Industries/.github/.github/workflows/cd-cdk.yaml@3cde673b9d05c0e68aac4d997d582f2543853d20 # main
|
|
with:
|
|
node-version: "24"
|
|
stacks: "security-baseline"
|
|
stack-name: "seahaven-security-baseline"
|
|
secrets:
|
|
deploy-role-arn: ${{ secrets.AWS_DEPLOY_ROLE_ARN_SECURITY }}
|
|
|
|
deploy-dev:
|
|
uses: Sea-Haven-Industries/.github/.github/workflows/cd-cdk.yaml@3cde673b9d05c0e68aac4d997d582f2543853d20 # main
|
|
with:
|
|
node-version: "24"
|
|
stacks: "dev-baseline"
|
|
stack-name: "seahaven-dev-baseline"
|
|
secrets:
|
|
deploy-role-arn: ${{ secrets.AWS_DEPLOY_ROLE_ARN_DEV }}
|