mirror of
https://github.com/Sea-Haven-Industries/seahaven-org-baseline.git
synced 2026-09-30 05:43:17 +00:00
* Add org-governance stack: OU skeleton + generalized SCPs Phase 2 of the multi-account segregation plan: codifies the OU tree (workloads/prod/nonprod, security, sandbox, graveyard) and three org-wide SCPs (workloads-region-lock, protect-security-baseline, deny-root-user) generalized from the proven external-dev guardrails. All resources Retain — CFN must never detach a live guardrail. New SCPs attach only to the new empty OUs; extending to external-dev is a separate gated targetIds change after live verification. * Record SCP cross-review dispositions in org-governance Root hardening must precede the OU move (deny-root-user blocks root MFA enrollment), delegated-admin flows ride service-linked roles that SCPs never evaluate, and the cdk exec-role exemption is accepted risk mirroring the external-dev guardrails. * Add org-governance to the management deploy job Explicit stack selectors require every new stack to join exactly one CD job (SH-ORG-005 discipline documented in this file). |
||
|---|---|---|
| .. | ||
| workflows | ||
| dependabot.yml | ||