seahaven-org-baseline/lib
Adam Moussa 981960433f
fix(iam): scope Terraform guardrail role writes to a Terraform-owned path
Security review (6 detectors + proof-or-kill verifier) confirmed 1 critical and
1 high in the first revision, both inherited by mirroring the SAM copy's
Resource "*" role grants:

- C1 (critical): iam:UpdateAssumeRolePolicy on "*" with DenySelfMutation
  covering only three name patterns lets the principal repoint the
  AdministratorAccess CDK bootstrap role's trust policy to an external account.
- C2 (high): the SAM justification for role/* (SAM auto-roles land at path /
  with no settable RolePath) does not transfer -- Terraform's aws_iam_role
  supports path.

Fixes, closing the class at the root rather than by denylist:
- All role writes, boundary sets and PassRole confined to role/tf-managed/*;
  reads split into a separate statement that keeps Resource "*".
- DenySelfMutation extended to cdk-hnb659fds-*, OrganizationAccountAccessRole
  and seahaven-* as defense in depth.
- OIDC provider made conditional (CreateOIDCProvider), mirroring the sibling
  substrate, so a first-create rollback is recoverable rather than wedging the
  stack in ROLLBACK_COMPLETE against a Retained orphan.
- README corrected: the guardrail policy is NOT Retain (only the provider is),
  so the Deny backstops do not survive a stack delete.

checkov CKV_AWS_109 no longer fires on this template, so no suppression is
needed. The template header records every divergence from the SAM copy.
2026-07-30 16:55:45 -04:00
..
deploy-substrate fix(iam): reconcile the remaining substrate divergences from the mgmt copy 2026-07-27 18:55:10 -04:00
scp Adopt external-dev OU and its 3 SCPs via resource import (#45) 2026-07-14 14:10:10 -04:00
terraform-substrate fix(iam): scope Terraform guardrail role writes to a Terraform-owned path 2026-07-30 16:55:45 -04:00
account-baseline-stack.ts Merge external-dev member baseline; rename to seahaven-org-baseline (#43) 2026-07-14 13:53:07 -04:00
alarm-topic-stack.ts feat(prod): seahaven-prod DynamoDB CMK + site-alerts alarm topic (procurement-ingest migration Phase 0a) (#57) 2026-07-23 15:29:55 -04:00
backup-offsite-stack.ts Add AWS Backup with offsite vault (audit C-7) (#3) 2026-05-29 18:06:17 -04:00
backup-stack.ts chore: drop deleted tables from Phase2 backup selection (#59) 2026-07-23 16:21:04 -04:00
bedrock-logging-regional.ts [INFRA-91/89/16/88/73] Reconcile out-of-band baseline changes + add missing detective controls (#18) 2026-06-08 17:03:18 -04:00
bedrock-logging.ts Add Bedrock invocation logging destinations (#12) 2026-06-03 15:17:39 -04:00
cis-monitoring.ts feat: harden CIS 4.1 detection depth with M-of-N alarm tuning and CloudTrail Insights (#38) 2026-07-07 15:47:41 -04:00
deploy-substrate-stack.ts fix(deploy-substrate): move boundary-gated IAM policy off the role's inline budget 2026-07-27 16:43:15 -04:00
detective-controls.ts seahaven-dev account baseline with org-managed detection (Phase 4) (#49) 2026-07-14 16:41:36 -04:00
dynamodb-cmk-stack.ts [INFRA-95] Shared DynamoDB CMK for sensitive finance/PII tables (M-3) (#21) 2026-06-08 19:04:42 -04:00
flow-logs.ts Merge external-dev member baseline; rename to seahaven-org-baseline (#43) 2026-07-14 13:53:07 -04:00
governance-toggles.ts Merge external-dev member baseline; rename to seahaven-org-baseline (#43) 2026-07-14 13:53:07 -04:00
logs-key.ts [INFRA-96] CMK-encrypt sensitive CloudWatch log groups (M-24) (#20) 2026-06-08 19:04:36 -04:00
member-baseline-stack.ts seahaven-prod account baseline (Phase 5) (#50) 2026-07-14 17:17:55 -04:00
org-governance-stack.ts fix(scp): exempt chatbot:* from workloads-region-lock (global service, us-east-2 control plane) (#58) 2026-07-23 15:47:11 -04:00
regional-baseline-stack.ts [INFRA-91/89/16/88/73] Reconcile out-of-band baseline changes + add missing detective controls (#18) 2026-06-08 17:03:18 -04:00
ses-monitoring.ts Add monitoring + logging layer (audit Day 2: H-1/H-14/M-13) (#6) 2026-06-02 15:16:24 -04:00
terraform-substrate-stack.ts fix(iam): scope Terraform guardrail role writes to a Terraform-owned path 2026-07-30 16:55:45 -04:00
web-acl.ts Add shared CloudFront WAF WebACL (audit Day 3: M-17) (#7) 2026-06-02 16:42:24 -04:00