mirror of
https://github.com/Sea-Haven-Industries/seahaven-org-baseline.git
synced 2026-09-30 08:03:19 +00:00
Budget alerts and CIS alarm subscriptions now go to aws@seahaven.com (management) and aws-external-dev@seahaven.com (external-dev) instead of personal addresses (Adam, 2026-07-14; resolves security-review flag SH-ORG-007). Owner tags are informational and stay decoupled.
121 lines
5.6 KiB
JavaScript
121 lines
5.6 KiB
JavaScript
#!/usr/bin/env node
|
|
import "source-map-support/register";
|
|
import * as cdk from "aws-cdk-lib";
|
|
import { AccountBaselineStack } from "../lib/account-baseline-stack";
|
|
import { BackupOffsiteStack } from "../lib/backup-offsite-stack";
|
|
import { BackupStack } from "../lib/backup-stack";
|
|
import { RegionalBaselineStack } from "../lib/regional-baseline-stack";
|
|
import { DynamoDbCmkStack } from "../lib/dynamodb-cmk-stack";
|
|
import { MemberBaselineStack } from "../lib/member-baseline-stack";
|
|
import { OrgGovernanceStack } from "../lib/org-governance-stack";
|
|
|
|
const ACCOUNT = "328440206208";
|
|
const EXTERNAL_DEV_ACCOUNT = "396287094661";
|
|
|
|
// All 5 VPCs in 328440206208 / us-east-1 (4 custom + default), audit Agent 7.
|
|
// Index-derived logical IDs — append only, never reorder.
|
|
const PROD_VPC_IDS = [
|
|
"vpc-061d66990b6a4d1fb",
|
|
"vpc-0542a9e934b417d23",
|
|
"vpc-062d200c68bd4ca0e",
|
|
"vpc-0d3d4b67bd0cf8a68",
|
|
"vpc-02c10a89d66f6f9b8",
|
|
];
|
|
|
|
const app = new cdk.App();
|
|
|
|
new AccountBaselineStack(app, "account-baseline", {
|
|
stackName: "seahaven-account-baseline",
|
|
env: { account: ACCOUNT, region: "us-east-1" },
|
|
monthlyBudgetUsd: 1200,
|
|
// Dedicated AWS-notifications mailbox (Adam, 2026-07-14). Also feeds the CIS
|
|
// alarm SNS subscription — a changed endpoint must CONFIRM via the email
|
|
// link before alarm notifications flow again.
|
|
budgetAlertEmail: "aws@seahaven.com",
|
|
flowLogVpcIds: PROD_VPC_IDS,
|
|
});
|
|
|
|
// ── Member-account baseline: seahaven-external-dev ───────────────────────────
|
|
// Absorbed from the retired seahaven-external-dev-baseline repo. Stack name and
|
|
// every construct id preserved byte-identically (logical IDs are path-derived —
|
|
// renaming anything here replaces live resources). Deploys to the isolated
|
|
// external-dev member account via its own OIDC deploy role, NOT the mgmt role.
|
|
//
|
|
// Flow-log VPC ids are COMMITTED here, not passed via -c context. The old
|
|
// repo's `-c flowLogVpcIds=...` pattern was a confirmed security-review trap
|
|
// (SH-ORG-004): once flow logs were attached via context, any context-less
|
|
// deploy (including CI) would silently REMOVE them all. Append ids via PR;
|
|
// never reorder (index-derived logical IDs). Empty = hardened bucket only,
|
|
// matching the currently deployed stack.
|
|
const EXTDEV_FLOW_LOG_VPC_IDS: string[] = [];
|
|
|
|
// ── Org structure: OUs + generalized SCPs (management account only) ─────────
|
|
// Existing external-dev OU + its 3 SCPs are adopted into this stack via
|
|
// `cdk import` post-deploy — see lib/org-governance-stack.ts header + README.
|
|
new OrgGovernanceStack(app, "org-governance", {
|
|
stackName: "seahaven-org-governance",
|
|
env: { account: ACCOUNT, region: "us-east-1" },
|
|
});
|
|
|
|
new MemberBaselineStack(app, "external-dev-baseline", {
|
|
stackName: "seahaven-external-dev-baseline",
|
|
env: { account: EXTERNAL_DEV_ACCOUNT, region: "us-east-1" },
|
|
namePrefix: "seahaven-extdev",
|
|
monthlyBudgetUsd: 200,
|
|
// Account-dedicated AWS-notifications mailbox (Adam, 2026-07-14 — resolves
|
|
// security-review flag SH-ORG-007).
|
|
budgetAlertEmail: "aws-external-dev@seahaven.com",
|
|
ownerEmail: "adam@seahaven.com",
|
|
flowLogVpcIds: EXTDEV_FLOW_LOG_VPC_IDS,
|
|
// Keeps the tag value the stack was deployed with (zero-diff merge). Update
|
|
// to the current repo name in a deliberate follow-up change if desired.
|
|
managedByTag: "seahaven-external-dev-baseline",
|
|
});
|
|
|
|
// ── Shared DynamoDB CMK (INFRA-95 / M-3) ─────────────────────────────────────
|
|
// Dedicated, standalone stack so the customer-managed key for sensitive
|
|
// finance/PII DynamoDB tables is an independent shared dependency for the owning
|
|
// app repos (payments-dashboard, procurement-ingest, exec-aide). Its ARN is
|
|
// published to SSM (/seahaven/dynamodb/cmk-arn) for those stacks to consume.
|
|
new DynamoDbCmkStack(app, "dynamodb-cmk", {
|
|
stackName: "seahaven-dynamodb-cmk",
|
|
env: { account: ACCOUNT, region: "us-east-1" },
|
|
});
|
|
|
|
// ── Secondary-region baselines (INFRA-16, INFRA-91) ──────────────────────────
|
|
// The us-east-1 baseline above is region-pinned by design. These stacks extend
|
|
// a minimal detective/logging footprint into the secondary regions, codifying
|
|
// state applied out-of-band this week so it lives in IaC.
|
|
|
|
// us-west-2: Bedrock invocation logging only (INFRA-91). Shares the region with
|
|
// the offsite backup vault but is an independent concern (separate stack).
|
|
new RegionalBaselineStack(app, "regional-baseline-us-west-2", {
|
|
stackName: "seahaven-regional-baseline-us-west-2",
|
|
env: { account: ACCOUNT, region: "us-west-2" },
|
|
bedrockLogging: true,
|
|
});
|
|
|
|
// us-east-2: Bedrock invocation logging (INFRA-91) + the still-missing AWS
|
|
// Config recorder and Security Hub (INFRA-16). GuardDuty + flow logs already
|
|
// live here (adopted as a follow-up, see lib/regional-baseline-stack.ts).
|
|
new RegionalBaselineStack(app, "regional-baseline-us-east-2", {
|
|
stackName: "seahaven-regional-baseline-us-east-2",
|
|
env: { account: ACCOUNT, region: "us-east-2" },
|
|
bedrockLogging: true,
|
|
configRecorder: true,
|
|
securityHub: true,
|
|
});
|
|
|
|
// AWS Backup (audit C-7). Offsite vault (us-west-2) must exist before the
|
|
// primary plan that copies to it, hence the explicit dependency.
|
|
const backupOffsite = new BackupOffsiteStack(app, "backup-offsite", {
|
|
stackName: "seahaven-backup-offsite",
|
|
env: { account: "328440206208", region: "us-west-2" },
|
|
});
|
|
|
|
const backupPrimary = new BackupStack(app, "backup", {
|
|
stackName: "seahaven-backup",
|
|
env: { account: "328440206208", region: "us-east-1" },
|
|
});
|
|
|
|
backupPrimary.addDependency(backupOffsite);
|