seahaven-org-baseline/lib/governance-toggles.ts
Adam Moussa 3ab3bc773a
Merge external-dev member baseline; rename to seahaven-org-baseline (#43)
* Parameterize baseline constructs for multi-account reuse

DetectiveControls, FlowLogs, and GovernanceToggles were forked into
seahaven-external-dev-baseline with only physical-name and VPC-sourcing
differences. Prefix/name props let one implementation serve both
accounts; synthesized templates are unchanged (verified: empty cdk diff
against all deployed stacks).

* Absorb external-dev member baseline stack

Moves seahaven-external-dev-baseline's stack in as MemberBaselineStack,
construct ids and physical names byte-identical to the deployed stack
(logical IDs are path-derived; empty cdk diff verified via change set
against 396287094661). Retires the forked repo so member-account
baselines share one drift surface and one dependency pin.

* Rename package to seahaven-org-baseline

Prepares the repo rename: the app now spans the management account and
org member accounts, so 'account-baseline' undersells the scope. README
documents the two-account deploy topology and logical-ID constraints.

* Commit extdev flow-log VPC ids in code, not -c context

Security review SH-ORG-004 (confirmed high): with the ids sourced from
ephemeral cdk context, any context-less deploy silently removes every
flow log in the isolated account. A committed list makes the attachment
set reviewable and immune to a forgotten -c flag. Empty list matches
the deployed stack (zero diff).

* Split CD into per-account deploy jobs

The app now spans two AWS accounts; cdk deploy --all under one role
fails on the other account's stacks (security review IAC-01). Each job
passes explicit stack selectors and its own account's OIDC role via the
new cd-cdk stacks input.
2026-07-14 13:53:07 -04:00

89 lines
2.6 KiB
TypeScript

import * as cdk from "aws-cdk-lib";
import * as budgets from "aws-cdk-lib/aws-budgets";
import { Construct } from "constructs";
export interface GovernanceTogglesProps {
/** Physical name of the AWS Budget (account-scoped, e.g. "seahaven-monthly-cost"). */
readonly budgetName: string;
/** Monthly cost budget ceiling in USD. */
readonly monthlyLimitUsd: number;
/** Email that receives the budget threshold alerts. */
readonly alertEmail: string;
}
/**
* Account-level governance toggles that *are* expressible as CloudFormation
* (audit Day 1). Serves both the management-account baseline and member-account
* baselines (budget name parameterized per account).
*
* Closes:
* M-10 Monthly AWS Budget with 80% / 100% actual + 100% forecast alerts
*
* The remaining Day 1 governance items have no CloudFormation resource and are
* applied via CLI + documented in the README runbook (Adam's call, Day 1):
* M-6 Inspector2 enable (EC2 + Lambda + ECR)
* M-3 EBS encryption-by-default
* M-7 IAM account password policy
* L-8 Billing-metrics preference (us-east-1)
* M-11 Cost-allocation tag activation
*/
export class GovernanceToggles extends Construct {
constructor(scope: Construct, id: string, props: GovernanceTogglesProps) {
super(scope, id);
const subscriber = [
{
subscriptionType: "EMAIL",
address: props.alertEmail,
},
];
new budgets.CfnBudget(this, "MonthlyCostBudget", {
budget: {
budgetName: props.budgetName,
budgetType: "COST",
timeUnit: "MONTHLY",
budgetLimit: {
amount: props.monthlyLimitUsd,
unit: "USD",
},
},
notificationsWithSubscribers: [
{
notification: {
notificationType: "ACTUAL",
comparisonOperator: "GREATER_THAN",
threshold: 80,
thresholdType: "PERCENTAGE",
},
subscribers: subscriber,
},
{
notification: {
notificationType: "ACTUAL",
comparisonOperator: "GREATER_THAN",
threshold: 100,
thresholdType: "PERCENTAGE",
},
subscribers: subscriber,
},
{
notification: {
notificationType: "FORECASTED",
comparisonOperator: "GREATER_THAN",
threshold: 100,
thresholdType: "PERCENTAGE",
},
subscribers: subscriber,
},
],
});
cdk.Annotations.of(this).addInfo(
"Budget alerts: 80%/100% actual + 100% forecast of $" +
props.monthlyLimitUsd +
" to " +
props.alertEmail
);
}
}