mirror of
https://github.com/Sea-Haven-Industries/seahaven-org-baseline.git
synced 2026-10-02 00:23:19 +00:00
* [INFRA-96] CMK-encrypt sensitive CloudWatch log groups (M-24) Add a dedicated customer-managed CMK (alias/seahaven-logs) for encrypting the sensitive CloudWatch Logs groups (CloudTrail + finance/PII Lambdas). - lib/logs-key.ts: LogsKey construct. Key policy grants the CloudWatch Logs service principal (logs.us-east-1.amazonaws.com) Encrypt*/Decrypt*/ ReEncrypt*/GenerateDataKey*/DescribeKey, scoped by the kms:EncryptionContext:aws:logs:arn condition (REQUIRED per AWS docs or log delivery breaks). Cross-reviewed (GPT-4.1): tightened Describe* -> DescribeKey; CreateGrant omitted (not needed for plain log-group encryption). - account-baseline-stack.ts: instantiate LogsKey and set KmsKeyId on the L2 Trail's CloudWatch log group in place (escape hatch on the existing AWS::Logs::LogGroup) so it keeps the same logical id + physical name - additive, no replacement, CIS Section-4 metric filters (which import the group by name) keep working, live audit trail not disrupted. Gated by context `encryptTrailLogGroup` so the CMK can be smoke-tested on a low-risk Lambda group before the most-sensitive CloudTrail group. Finance/PII Lambda log groups (exec-aide-*, payments-*, po-email-processor, vendor-reply-processor) are owned by other stacks and associated to this CMK via the CLI for now; codifying KmsKeyId in those repos is tracked as drift. * [INFRA-96] Document sensitive-logs CMK (M-24) in README |
||
|---|---|---|
| .. | ||
| account-baseline-stack.ts | ||
| backup-offsite-stack.ts | ||
| backup-stack.ts | ||
| bedrock-logging-regional.ts | ||
| bedrock-logging.ts | ||
| cis-monitoring.ts | ||
| detective-controls.ts | ||
| flow-logs.ts | ||
| governance-toggles.ts | ||
| logs-key.ts | ||
| regional-baseline-stack.ts | ||
| ses-monitoring.ts | ||
| web-acl.ts | ||