seahaven-org-baseline/lib/ses-monitoring.ts
Adam Moussa 3ba90ddc40
Add monitoring + logging layer (audit Day 2: H-1/H-14/M-13) (#6)
- H-1: 15 CIS Section 4 metric filters (4.1-4.15) on the CloudTrail log group,
  each alarming to a new SSE SNS topic seahaven-cis-alarms (email to adam).
  ALARM-only actions per Sea Haven preference. 4.16 = Security Hub (Day 1).
- H-14: VPC flow logs (ALL traffic) on all 5 VPCs → hardened S3 bucket. Delivery
  bucket policy cross-reviewed; kept the AWS-required s3:x-amz-acl condition +
  logs:*:* source-ARN (cross-reviewer wrongly flagged these; verified against
  AWS flow-logs-s3-permissions docs), dropped the unneeded s3:ListBucket.
- M-13: SES configuration set seahaven-email-events capturing bounce/complaint/
  reject to CloudWatch for reputation visibility.

L-4 (log retention) and L-5 (alarm action) applied via CLI, documented in README.
2026-06-02 15:16:24 -04:00

50 lines
1.6 KiB
TypeScript

import * as cdk from "aws-cdk-lib";
import * as ses from "aws-cdk-lib/aws-ses";
import { Construct } from "constructs";
/**
* SES configuration set capturing bounce/complaint events (audit M-13).
*
* Gives reputation visibility beyond the suppression list by emitting bounce,
* complaint, and reject events to CloudWatch metrics (dimensioned by config
* set). Associating this set as the default on the live sending identities is a
* follow-up CLI step (documented in the README) — creating it here does not
* change current sending behaviour.
*/
export class SesMonitoring extends Construct {
constructor(scope: Construct, id: string) {
super(scope, id);
const configSetName = "seahaven-email-events";
const configSet = new ses.CfnConfigurationSet(this, "ConfigSet", {
name: configSetName,
reputationOptions: { reputationMetricsEnabled: true },
});
const eventDest = new ses.CfnConfigurationSetEventDestination(
this,
"BounceComplaintDest",
{
configurationSetName: configSetName,
eventDestination: {
name: "bounce-complaint-cw",
enabled: true,
matchingEventTypes: ["bounce", "complaint", "reject"],
cloudWatchDestination: {
dimensionConfigurations: [
{
defaultDimensionValue: "none",
dimensionName: "ses:configuration-set",
dimensionValueSource: "messageTag",
},
],
},
},
}
);
eventDest.node.addDependency(configSet);
new cdk.CfnOutput(this, "SesConfigSetName", { value: configSetName });
}
}