mirror of
https://github.com/Sea-Haven-Industries/seahaven-org-baseline.git
synced 2026-09-30 06:53:17 +00:00
* Parameterize baseline constructs for multi-account reuse DetectiveControls, FlowLogs, and GovernanceToggles were forked into seahaven-external-dev-baseline with only physical-name and VPC-sourcing differences. Prefix/name props let one implementation serve both accounts; synthesized templates are unchanged (verified: empty cdk diff against all deployed stacks). * Absorb external-dev member baseline stack Moves seahaven-external-dev-baseline's stack in as MemberBaselineStack, construct ids and physical names byte-identical to the deployed stack (logical IDs are path-derived; empty cdk diff verified via change set against 396287094661). Retires the forked repo so member-account baselines share one drift surface and one dependency pin. * Rename package to seahaven-org-baseline Prepares the repo rename: the app now spans the management account and org member accounts, so 'account-baseline' undersells the scope. README documents the two-account deploy topology and logical-ID constraints. * Commit extdev flow-log VPC ids in code, not -c context Security review SH-ORG-004 (confirmed high): with the ids sourced from ephemeral cdk context, any context-less deploy silently removes every flow log in the isolated account. A committed list makes the attachment set reviewable and immune to a forgotten -c flag. Empty list matches the deployed stack (zero diff). * Split CD into per-account deploy jobs The app now spans two AWS accounts; cdk deploy --all under one role fails on the other account's stacks (security review IAC-01). Each job passes explicit stack selectors and its own account's OIDC role via the new cd-cdk stacks input.
89 lines
2.6 KiB
TypeScript
89 lines
2.6 KiB
TypeScript
import * as cdk from "aws-cdk-lib";
|
|
import * as budgets from "aws-cdk-lib/aws-budgets";
|
|
import { Construct } from "constructs";
|
|
|
|
export interface GovernanceTogglesProps {
|
|
/** Physical name of the AWS Budget (account-scoped, e.g. "seahaven-monthly-cost"). */
|
|
readonly budgetName: string;
|
|
/** Monthly cost budget ceiling in USD. */
|
|
readonly monthlyLimitUsd: number;
|
|
/** Email that receives the budget threshold alerts. */
|
|
readonly alertEmail: string;
|
|
}
|
|
|
|
/**
|
|
* Account-level governance toggles that *are* expressible as CloudFormation
|
|
* (audit Day 1). Serves both the management-account baseline and member-account
|
|
* baselines (budget name parameterized per account).
|
|
*
|
|
* Closes:
|
|
* M-10 Monthly AWS Budget with 80% / 100% actual + 100% forecast alerts
|
|
*
|
|
* The remaining Day 1 governance items have no CloudFormation resource and are
|
|
* applied via CLI + documented in the README runbook (Adam's call, Day 1):
|
|
* M-6 Inspector2 enable (EC2 + Lambda + ECR)
|
|
* M-3 EBS encryption-by-default
|
|
* M-7 IAM account password policy
|
|
* L-8 Billing-metrics preference (us-east-1)
|
|
* M-11 Cost-allocation tag activation
|
|
*/
|
|
export class GovernanceToggles extends Construct {
|
|
constructor(scope: Construct, id: string, props: GovernanceTogglesProps) {
|
|
super(scope, id);
|
|
|
|
const subscriber = [
|
|
{
|
|
subscriptionType: "EMAIL",
|
|
address: props.alertEmail,
|
|
},
|
|
];
|
|
|
|
new budgets.CfnBudget(this, "MonthlyCostBudget", {
|
|
budget: {
|
|
budgetName: props.budgetName,
|
|
budgetType: "COST",
|
|
timeUnit: "MONTHLY",
|
|
budgetLimit: {
|
|
amount: props.monthlyLimitUsd,
|
|
unit: "USD",
|
|
},
|
|
},
|
|
notificationsWithSubscribers: [
|
|
{
|
|
notification: {
|
|
notificationType: "ACTUAL",
|
|
comparisonOperator: "GREATER_THAN",
|
|
threshold: 80,
|
|
thresholdType: "PERCENTAGE",
|
|
},
|
|
subscribers: subscriber,
|
|
},
|
|
{
|
|
notification: {
|
|
notificationType: "ACTUAL",
|
|
comparisonOperator: "GREATER_THAN",
|
|
threshold: 100,
|
|
thresholdType: "PERCENTAGE",
|
|
},
|
|
subscribers: subscriber,
|
|
},
|
|
{
|
|
notification: {
|
|
notificationType: "FORECASTED",
|
|
comparisonOperator: "GREATER_THAN",
|
|
threshold: 100,
|
|
thresholdType: "PERCENTAGE",
|
|
},
|
|
subscribers: subscriber,
|
|
},
|
|
],
|
|
});
|
|
|
|
cdk.Annotations.of(this).addInfo(
|
|
"Budget alerts: 80%/100% actual + 100% forecast of $" +
|
|
props.monthlyLimitUsd +
|
|
" to " +
|
|
props.alertEmail
|
|
);
|
|
}
|
|
}
|