seahaven-org-baseline/.github/workflows
Adam Moussa 18f0f40e74
seahaven-security account baseline + security-OU guardrails (Phase 3) (#47)
* Add seahaven-security member baseline (Phase 3)

Account 001520130573 is the org's delegated security administrator.
Same member-baseline construct set as external-dev; own CD job under
its own OIDC role. Created at org root pending manual root hardening
before the OU move (deny-root-user invariant).

* Document delegated security administration runbook

Delegation to seahaven-security has no CloudFormation types; the CLI
sequence is the record, same pattern as the other account toggles.

* Apply Phase-3 security-review findings

Delegation runbook marked PENDING with hard preconditions (baseline
deployed, root MFA verified, account inside the security OU) — it had
read as applied before execution, the org's known claimed-done-but-NOT
failure mode (SEC-BASE-A/B). New security-guardrails SCP on the
security OU: region lock, IAM user/key lockout, privileged-role
protection, delegated-admin membership protection (SEC-BASE-C,
cross-reviewed APPROVE). deploy-security gains stack-name pre-flight
(SEC-BASE-D). Default VPC in 001520130573 deleted; empty flow-log list
and aws@ alert routing documented as deliberate (SEC-BASE-F/H).
2026-07-14 15:32:50 -04:00
..
ci.yaml chore(ci): SHA-pin org reusable-workflow caller refs (INFRA-50) (#35) 2026-07-06 18:27:41 -04:00
dependency-review.yml chore(ci): SHA-pin org reusable-workflow caller refs (INFRA-50) (#35) 2026-07-06 18:27:41 -04:00
deploy.yaml seahaven-security account baseline + security-OU guardrails (Phase 3) (#47) 2026-07-14 15:32:50 -04:00
labeler.yml chore(ci): SHA-pin org reusable-workflow caller refs (INFRA-50) (#35) 2026-07-06 18:27:41 -04:00