mirror of
https://github.com/Sea-Haven-Industries/seahaven-org-baseline.git
synced 2026-09-30 08:03:19 +00:00
Reintroduce the scoped vault access policy that was split out of INFRA-89 after two lockout-class bugs. Adds a Deny on the destructive recovery-point and vault-lifecycle actions (DeleteRecoveryPoint, UpdateRecoveryPointLifecycle, DeleteBackupVault, DeleteBackupVaultAccessPolicy, DeleteBackupVaultLockConfiguration, PutBackupVaultLockConfiguration) for every principal except three exempted operational identities via StringNotLike on aws:PrincipalArn: 1. SSO AdministratorAccess role (break-glass human admin) 2. seahaven-backup-service-role (AWS Backup lifecycle) 3. cdk-hnb659fds-cfn-exec-role-* (CloudFormation manages the vault) The CFN-exec-role exemption is the fix for the 2026-06-08 strand failure: without it CloudFormation cannot re-assert the vault lock config and the deploy strands the policy. Uses Deny + AnyPrincipal + StringNotLike (not NotPrincipal, which rejects wildcard ARNs). aws:PrincipalArn normalizes assumed-role sessions to the IAM role ARN, so the iam::role/ ARN forms are correct (AWS docs: "Do not specify the assumed role session ARN as a value for this condition key"). Deployed and verified: deploy succeeded (proves exec role not locked out), access policy present with all three exemptions, vault still Locked (min1/max2555, LockDate null, 168 RPs), follow-up cdk diff clean (no drift). |
||
|---|---|---|
| .. | ||
| account-baseline-stack.ts | ||
| backup-offsite-stack.ts | ||
| backup-stack.ts | ||
| bedrock-logging-regional.ts | ||
| bedrock-logging.ts | ||
| cis-monitoring.ts | ||
| detective-controls.ts | ||
| flow-logs.ts | ||
| governance-toggles.ts | ||
| regional-baseline-stack.ts | ||
| ses-monitoring.ts | ||
| web-acl.ts | ||