mirror of
https://github.com/Sea-Haven-Industries/seahaven-org-baseline.git
synced 2026-10-02 22:43:13 +00:00
* Add account detective layer + budget (audit Day 1: H-2/H-3/H-4/M-5/M-10) Adds to the seahaven-account-baseline stack: - AWS Config recorder (all + global resources) + delivery channel + role + hardened delivery bucket (H-2, CIS 3.3/3.5). Recorder role IAM cross-reviewed. - GuardDuty detector, us-east-1 (H-3) - Security Hub with AWS FSBP v1.0.0 + CIS v3.0.0 standards, depends on Config (H-4) - IAM Access Analyzer, account scope (M-5) - Monthly cost budget $1,200 with 80/100% actual + 100% forecast alerts to adam@seahavenind.com (M-10) Scope us-east-1 only (all workloads here); multi-region is a follow-up. The CLI-applied governance toggles (M-6/M-3/M-7/L-8/M-11) are documented separately in the README runbook. * Document Day 1 detective layer + CLI governance toggles in README * Move Config recorder+channel to CLI (L1 stabilization deadlock) The L1 AWS::Config::ConfigurationRecorder hangs the stack: it never reaches CREATE_COMPLETE until recording is active (needs a delivery channel), and the delivery channel cannot be created until the recorder completes — a deadlock that hung the deploy ~27 min before manual cancel (2026-06-01). Keep the cross-reviewed recorder role + delivery bucket in IaC; create the recorder, delivery channel, and start recording via CLI (documented in README). Security Hub no longer takes a CFN dependency on the recorder; CIS/FSBP controls evaluate once Config is recording. Verified live: recording=true, SUCCESS.
86 lines
2.4 KiB
TypeScript
86 lines
2.4 KiB
TypeScript
import * as cdk from "aws-cdk-lib";
|
|
import * as budgets from "aws-cdk-lib/aws-budgets";
|
|
import { Construct } from "constructs";
|
|
|
|
export interface GovernanceTogglesProps {
|
|
/** Monthly cost budget ceiling in USD. */
|
|
readonly monthlyLimitUsd: number;
|
|
/** Email that receives the budget threshold alerts. */
|
|
readonly alertEmail: string;
|
|
}
|
|
|
|
/**
|
|
* Account-level governance toggles that *are* expressible as CloudFormation
|
|
* (audit Day 1).
|
|
*
|
|
* Closes:
|
|
* M-10 Monthly AWS Budget with 80% / 100% actual + 100% forecast alerts
|
|
*
|
|
* The remaining Day 1 governance items have no CloudFormation resource and are
|
|
* applied via CLI + documented in the README runbook (Adam's call, Day 1):
|
|
* M-6 Inspector2 enable (EC2 + Lambda + ECR)
|
|
* M-3 EBS encryption-by-default
|
|
* M-7 IAM account password policy
|
|
* L-8 Billing-metrics preference (us-east-1)
|
|
* M-11 Cost-allocation tag activation
|
|
*/
|
|
export class GovernanceToggles extends Construct {
|
|
constructor(scope: Construct, id: string, props: GovernanceTogglesProps) {
|
|
super(scope, id);
|
|
|
|
const subscriber = [
|
|
{
|
|
subscriptionType: "EMAIL",
|
|
address: props.alertEmail,
|
|
},
|
|
];
|
|
|
|
new budgets.CfnBudget(this, "MonthlyCostBudget", {
|
|
budget: {
|
|
budgetName: "seahaven-monthly-cost",
|
|
budgetType: "COST",
|
|
timeUnit: "MONTHLY",
|
|
budgetLimit: {
|
|
amount: props.monthlyLimitUsd,
|
|
unit: "USD",
|
|
},
|
|
},
|
|
notificationsWithSubscribers: [
|
|
{
|
|
notification: {
|
|
notificationType: "ACTUAL",
|
|
comparisonOperator: "GREATER_THAN",
|
|
threshold: 80,
|
|
thresholdType: "PERCENTAGE",
|
|
},
|
|
subscribers: subscriber,
|
|
},
|
|
{
|
|
notification: {
|
|
notificationType: "ACTUAL",
|
|
comparisonOperator: "GREATER_THAN",
|
|
threshold: 100,
|
|
thresholdType: "PERCENTAGE",
|
|
},
|
|
subscribers: subscriber,
|
|
},
|
|
{
|
|
notification: {
|
|
notificationType: "FORECASTED",
|
|
comparisonOperator: "GREATER_THAN",
|
|
threshold: 100,
|
|
thresholdType: "PERCENTAGE",
|
|
},
|
|
subscribers: subscriber,
|
|
},
|
|
],
|
|
});
|
|
|
|
cdk.Annotations.of(this).addInfo(
|
|
"Budget alerts: 80%/100% actual + 100% forecast of $" +
|
|
props.monthlyLimitUsd +
|
|
" to " +
|
|
props.alertEmail
|
|
);
|
|
}
|
|
}
|