mirror of
https://github.com/Sea-Haven-Industries/seahaven-org-baseline.git
synced 2026-09-30 08:03:19 +00:00
* Add account detective layer + budget (audit Day 1: H-2/H-3/H-4/M-5/M-10) Adds to the seahaven-account-baseline stack: - AWS Config recorder (all + global resources) + delivery channel + role + hardened delivery bucket (H-2, CIS 3.3/3.5). Recorder role IAM cross-reviewed. - GuardDuty detector, us-east-1 (H-3) - Security Hub with AWS FSBP v1.0.0 + CIS v3.0.0 standards, depends on Config (H-4) - IAM Access Analyzer, account scope (M-5) - Monthly cost budget $1,200 with 80/100% actual + 100% forecast alerts to adam@seahavenind.com (M-10) Scope us-east-1 only (all workloads here); multi-region is a follow-up. The CLI-applied governance toggles (M-6/M-3/M-7/L-8/M-11) are documented separately in the README runbook. * Document Day 1 detective layer + CLI governance toggles in README * Move Config recorder+channel to CLI (L1 stabilization deadlock) The L1 AWS::Config::ConfigurationRecorder hangs the stack: it never reaches CREATE_COMPLETE until recording is active (needs a delivery channel), and the delivery channel cannot be created until the recorder completes — a deadlock that hung the deploy ~27 min before manual cancel (2026-06-01). Keep the cross-reviewed recorder role + delivery bucket in IaC; create the recorder, delivery channel, and start recording via CLI (documented in README). Security Hub no longer takes a CFN dependency on the recorder; CIS/FSBP controls evaluate once Config is recording. Verified live: recording=true, SUCCESS.
29 lines
1 KiB
JavaScript
29 lines
1 KiB
JavaScript
#!/usr/bin/env node
|
|
import "source-map-support/register";
|
|
import * as cdk from "aws-cdk-lib";
|
|
import { AccountBaselineStack } from "../lib/account-baseline-stack";
|
|
import { BackupOffsiteStack } from "../lib/backup-offsite-stack";
|
|
import { BackupStack } from "../lib/backup-stack";
|
|
|
|
const app = new cdk.App();
|
|
|
|
new AccountBaselineStack(app, "account-baseline", {
|
|
stackName: "seahaven-account-baseline",
|
|
env: { account: "328440206208", region: "us-east-1" },
|
|
monthlyBudgetUsd: 1200,
|
|
budgetAlertEmail: "adam@seahavenind.com",
|
|
});
|
|
|
|
// AWS Backup (audit C-7). Offsite vault (us-west-2) must exist before the
|
|
// primary plan that copies to it, hence the explicit dependency.
|
|
const backupOffsite = new BackupOffsiteStack(app, "backup-offsite", {
|
|
stackName: "seahaven-backup-offsite",
|
|
env: { account: "328440206208", region: "us-west-2" },
|
|
});
|
|
|
|
const backupPrimary = new BackupStack(app, "backup", {
|
|
stackName: "seahaven-backup",
|
|
env: { account: "328440206208", region: "us-east-1" },
|
|
});
|
|
|
|
backupPrimary.addDependency(backupOffsite);
|