seahaven-org-baseline/lib
Adam Moussa 42781f743e
fix(baseline): drop departed mgmt resources and retain drifted web acl (#171)
Nightly backup jobs fail on resources that have left the management account.
The CloudFront WebACL is already gone while CloudFormation still owns it, so
the deletion policy has to be Retain before a later change can remove it.
2026-10-01 23:57:42 +00:00
..
deploy-substrate fix(iam): shrink shared lambda boundary to the four-statement floor (PLAT-52) (#158) 2026-09-28 13:46:18 -04:00
hcptf-bootstrap feat(iam): allow PassRole to ECS tasks and EventBridge Scheduler (#151) 2026-09-21 18:59:08 +00:00
scp feat(scp): deny iam changes on the platform path (PLAT-233) (#159) 2026-09-28 16:27:10 +00:00
terraform-substrate chore(terraform-substrate): forget imported prod hcptf pairs (PLAT-147) (#164) 2026-09-28 15:56:04 -04:00
account-baseline-stack.ts fix(baseline): drop departed mgmt resources and retain drifted web acl (#171) 2026-10-01 23:57:42 +00:00
alarm-topic-stack.ts feat(prod): seahaven-prod DynamoDB CMK + site-alerts alarm topic (procurement-ingest migration Phase 0a) (#57) 2026-07-23 15:29:55 -04:00
app-web-acl-stack.ts feat(waf): add seahaven-prod shared CloudFront WebACL (PLAT-92) (#96) 2026-08-07 17:07:04 -04:00
backup-offsite-stack.ts Add AWS Backup with offsite vault (audit C-7) (#3) 2026-05-29 18:06:17 -04:00
backup-stack.ts fix(baseline): drop departed mgmt resources and retain drifted web acl (#171) 2026-10-01 23:57:42 +00:00
bedrock-logging-regional.ts [INFRA-91/89/16/88/73] Reconcile out-of-band baseline changes + add missing detective controls (#18) 2026-06-08 17:03:18 -04:00
bedrock-logging.ts Add Bedrock invocation logging destinations (#12) 2026-06-03 15:17:39 -04:00
cis-monitoring.ts feat(iam): add platform permission set and org-admin assume alarm (SEC-37) (#161) 2026-09-28 16:27:12 +00:00
deploy-substrate-stack.ts fix(deploy-substrate): move boundary-gated IAM policy off the role's inline budget 2026-07-27 16:43:15 -04:00
detective-controls.ts seahaven-dev account baseline with org-managed detection (Phase 4) (#49) 2026-07-14 16:41:36 -04:00
dynamodb-cmk-stack.ts [INFRA-95] Shared DynamoDB CMK for sensitive finance/PII tables (M-3) (#21) 2026-06-08 19:04:42 -04:00
engineering-access-stack.ts feat(iam): add engineering view-only permission sets (PLAT-235) (#169) 2026-10-01 19:35:17 +00:00
flow-logs.ts fix(baseline): drop departed mgmt resources and retain drifted web acl (#171) 2026-10-01 23:57:42 +00:00
governance-toggles.ts Merge external-dev member baseline; rename to seahaven-org-baseline (#43) 2026-07-14 13:53:07 -04:00
logs-key.ts [INFRA-96] CMK-encrypt sensitive CloudWatch log groups (M-24) (#20) 2026-06-08 19:04:36 -04:00
member-baseline-stack.ts seahaven-prod account baseline (Phase 5) (#50) 2026-07-14 17:17:55 -04:00
org-governance-stack.ts feat(scp): deny iam changes on the platform path (PLAT-233) (#159) 2026-09-28 16:27:10 +00:00
platform-access-stack.ts feat(iam): add platform permission set and org-admin assume alarm (SEC-37) (#161) 2026-09-28 16:27:12 +00:00
regional-baseline-stack.ts [INFRA-91/89/16/88/73] Reconcile out-of-band baseline changes + add missing detective controls (#18) 2026-06-08 17:03:18 -04:00
seahaven-site-hcptf-stack.ts fix(iam): let the site plan role describe SSM parameters (PLAT-225) (#154) 2026-09-25 16:40:34 +00:00
ses-monitoring.ts Add monitoring + logging layer (audit Day 2: H-1/H-14/M-13) (#6) 2026-06-02 15:16:24 -04:00
terraform-substrate-stack.ts feat(iam): lock app-owned HCP IAM and add bootstrap SCP (PLAT-143) (#137) 2026-09-02 15:22:48 +00:00
web-acl.ts fix(baseline): drop departed mgmt resources and retain drifted web acl (#171) 2026-10-01 23:57:42 +00:00