seahaven-org-baseline/lib/member-baseline-stack.ts
Adam Moussa 57fd67324e
Some checks are pending
Deploy / deploy-management (push) Waiting to run
Deploy / deploy-external-dev (push) Waiting to run
Route AWS notifications to dedicated mailboxes (#46)
Budget alerts and CIS alarm subscriptions now go to aws@seahaven.com
(management) and aws-external-dev@seahaven.com (external-dev) instead
of personal addresses (Adam, 2026-07-14; resolves security-review flag
SH-ORG-007). Owner tags are informational and stay decoupled.
2026-07-14 14:41:42 -04:00

66 lines
2.7 KiB
TypeScript

import * as cdk from "aws-cdk-lib";
import { Construct } from "constructs";
import { DetectiveControls } from "./detective-controls";
import { FlowLogs } from "./flow-logs";
import { GovernanceToggles } from "./governance-toggles";
export interface MemberBaselineStackProps extends cdk.StackProps {
/**
* Physical-name prefix for account-scoped resources (e.g. "seahaven-extdev").
* Also names the monthly budget (`<namePrefix>-monthly-cost`). Stable per
* account — changing it on a deployed stack replaces live resources.
*/
readonly namePrefix: string;
/** Monthly cost budget ceiling in USD. */
readonly monthlyBudgetUsd: number;
/** Sea Haven ops address that receives budget alerts (not the account's tenants). */
readonly budgetAlertEmail: string;
/** Value for the Owner tag (informational; decoupled from alert routing). */
readonly ownerEmail: string;
/** VPC ids to attach flow logs to (from cdk context; may be empty). */
readonly flowLogVpcIds: string[];
/** Value for the ManagedBy tag on every resource in the stack. */
readonly managedByTag: string;
}
/**
* Account-local security baseline for org MEMBER accounts (first tenant:
* seahaven-external-dev). Absorbed from the retired seahaven-external-dev-baseline
* repo — a stripped fork of the management-account baseline, now sharing its
* constructs (prefix-parameterized) instead of forking them.
*
* Deliberately excludes everything that is org-level or prod-specific:
* - No local CloudTrail — the management-account org trail (seahaven-org-trail)
* already captures every member account's events centrally.
* - No CIS Section-4 metric-filter alarms — the Security Hub CIS standard
* evaluates those controls against Config without a local trail log group.
* - No WAF, SES monitoring, Bedrock logging, DynamoDB CMK, or AWS Backup —
* all prod-only concerns.
*
* Contains: AWS Config, GuardDuty, Security Hub (FSBP + CIS v3.0), IAM Access
* Analyzer, Inspector2 (post-deploy CLI, see README), VPC flow logs, and a
* monthly cost Budget.
*/
export class MemberBaselineStack extends cdk.Stack {
constructor(scope: Construct, id: string, props: MemberBaselineStackProps) {
super(scope, id, props);
new DetectiveControls(this, "DetectiveControls", {
namePrefix: props.namePrefix,
});
new FlowLogs(this, "FlowLogs", {
namePrefix: props.namePrefix,
vpcIds: props.flowLogVpcIds,
});
new GovernanceToggles(this, "GovernanceToggles", {
budgetName: `${props.namePrefix}-monthly-cost`,
monthlyLimitUsd: props.monthlyBudgetUsd,
alertEmail: props.budgetAlertEmail,
});
cdk.Tags.of(this).add("Owner", props.ownerEmail);
cdk.Tags.of(this).add("ManagedBy", props.managedByTag);
}
}