seahaven-org-baseline/lib/governance-toggles.ts
Adam Moussa 38d4a5753a
Account detective layer + budget (audit Day 1) (#5)
* Add account detective layer + budget (audit Day 1: H-2/H-3/H-4/M-5/M-10)

Adds to the seahaven-account-baseline stack:
- AWS Config recorder (all + global resources) + delivery channel + role +
  hardened delivery bucket (H-2, CIS 3.3/3.5). Recorder role IAM cross-reviewed.
- GuardDuty detector, us-east-1 (H-3)
- Security Hub with AWS FSBP v1.0.0 + CIS v3.0.0 standards, depends on Config (H-4)
- IAM Access Analyzer, account scope (M-5)
- Monthly cost budget $1,200 with 80/100% actual + 100% forecast alerts to
  adam@seahavenind.com (M-10)

Scope us-east-1 only (all workloads here); multi-region is a follow-up.
The CLI-applied governance toggles (M-6/M-3/M-7/L-8/M-11) are documented
separately in the README runbook.

* Document Day 1 detective layer + CLI governance toggles in README

* Move Config recorder+channel to CLI (L1 stabilization deadlock)

The L1 AWS::Config::ConfigurationRecorder hangs the stack: it never reaches
CREATE_COMPLETE until recording is active (needs a delivery channel), and the
delivery channel cannot be created until the recorder completes — a deadlock
that hung the deploy ~27 min before manual cancel (2026-06-01).

Keep the cross-reviewed recorder role + delivery bucket in IaC; create the
recorder, delivery channel, and start recording via CLI (documented in README).
Security Hub no longer takes a CFN dependency on the recorder; CIS/FSBP controls
evaluate once Config is recording. Verified live: recording=true, SUCCESS.
2026-06-01 17:56:12 -04:00

86 lines
2.4 KiB
TypeScript

import * as cdk from "aws-cdk-lib";
import * as budgets from "aws-cdk-lib/aws-budgets";
import { Construct } from "constructs";
export interface GovernanceTogglesProps {
/** Monthly cost budget ceiling in USD. */
readonly monthlyLimitUsd: number;
/** Email that receives the budget threshold alerts. */
readonly alertEmail: string;
}
/**
* Account-level governance toggles that *are* expressible as CloudFormation
* (audit Day 1).
*
* Closes:
* M-10 Monthly AWS Budget with 80% / 100% actual + 100% forecast alerts
*
* The remaining Day 1 governance items have no CloudFormation resource and are
* applied via CLI + documented in the README runbook (Adam's call, Day 1):
* M-6 Inspector2 enable (EC2 + Lambda + ECR)
* M-3 EBS encryption-by-default
* M-7 IAM account password policy
* L-8 Billing-metrics preference (us-east-1)
* M-11 Cost-allocation tag activation
*/
export class GovernanceToggles extends Construct {
constructor(scope: Construct, id: string, props: GovernanceTogglesProps) {
super(scope, id);
const subscriber = [
{
subscriptionType: "EMAIL",
address: props.alertEmail,
},
];
new budgets.CfnBudget(this, "MonthlyCostBudget", {
budget: {
budgetName: "seahaven-monthly-cost",
budgetType: "COST",
timeUnit: "MONTHLY",
budgetLimit: {
amount: props.monthlyLimitUsd,
unit: "USD",
},
},
notificationsWithSubscribers: [
{
notification: {
notificationType: "ACTUAL",
comparisonOperator: "GREATER_THAN",
threshold: 80,
thresholdType: "PERCENTAGE",
},
subscribers: subscriber,
},
{
notification: {
notificationType: "ACTUAL",
comparisonOperator: "GREATER_THAN",
threshold: 100,
thresholdType: "PERCENTAGE",
},
subscribers: subscriber,
},
{
notification: {
notificationType: "FORECASTED",
comparisonOperator: "GREATER_THAN",
threshold: 100,
thresholdType: "PERCENTAGE",
},
subscribers: subscriber,
},
],
});
cdk.Annotations.of(this).addInfo(
"Budget alerts: 80%/100% actual + 100% forecast of $" +
props.monthlyLimitUsd +
" to " +
props.alertEmail
);
}
}