mirror of
https://github.com/Sea-Haven-Industries/seahaven-org-baseline.git
synced 2026-09-30 04:33:15 +00:00
- H-1: 15 CIS Section 4 metric filters (4.1-4.15) on the CloudTrail log group, each alarming to a new SSE SNS topic seahaven-cis-alarms (email to adam). ALARM-only actions per Sea Haven preference. 4.16 = Security Hub (Day 1). - H-14: VPC flow logs (ALL traffic) on all 5 VPCs → hardened S3 bucket. Delivery bucket policy cross-reviewed; kept the AWS-required s3:x-amz-acl condition + logs:*:* source-ARN (cross-reviewer wrongly flagged these; verified against AWS flow-logs-s3-permissions docs), dropped the unneeded s3:ListBucket. - M-13: SES configuration set seahaven-email-events capturing bounce/complaint/ reject to CloudWatch for reputation visibility. L-4 (log retention) and L-5 (alarm action) applied via CLI, documented in README.
50 lines
1.6 KiB
TypeScript
50 lines
1.6 KiB
TypeScript
import * as cdk from "aws-cdk-lib";
|
|
import * as ses from "aws-cdk-lib/aws-ses";
|
|
import { Construct } from "constructs";
|
|
|
|
/**
|
|
* SES configuration set capturing bounce/complaint events (audit M-13).
|
|
*
|
|
* Gives reputation visibility beyond the suppression list by emitting bounce,
|
|
* complaint, and reject events to CloudWatch metrics (dimensioned by config
|
|
* set). Associating this set as the default on the live sending identities is a
|
|
* follow-up CLI step (documented in the README) — creating it here does not
|
|
* change current sending behaviour.
|
|
*/
|
|
export class SesMonitoring extends Construct {
|
|
constructor(scope: Construct, id: string) {
|
|
super(scope, id);
|
|
|
|
const configSetName = "seahaven-email-events";
|
|
|
|
const configSet = new ses.CfnConfigurationSet(this, "ConfigSet", {
|
|
name: configSetName,
|
|
reputationOptions: { reputationMetricsEnabled: true },
|
|
});
|
|
|
|
const eventDest = new ses.CfnConfigurationSetEventDestination(
|
|
this,
|
|
"BounceComplaintDest",
|
|
{
|
|
configurationSetName: configSetName,
|
|
eventDestination: {
|
|
name: "bounce-complaint-cw",
|
|
enabled: true,
|
|
matchingEventTypes: ["bounce", "complaint", "reject"],
|
|
cloudWatchDestination: {
|
|
dimensionConfigurations: [
|
|
{
|
|
defaultDimensionValue: "none",
|
|
dimensionName: "ses:configuration-set",
|
|
dimensionValueSource: "messageTag",
|
|
},
|
|
],
|
|
},
|
|
},
|
|
}
|
|
);
|
|
eventDest.node.addDependency(configSet);
|
|
|
|
new cdk.CfnOutput(this, "SesConfigSetName", { value: configSetName });
|
|
}
|
|
}
|