seahaven-org-baseline/lib
Adam Moussa 7a1623e8d4
Some checks failed
Deploy / deploy-management (push) Has been cancelled
Deploy / deploy-external-dev (push) Has been cancelled
Deploy / deploy-security (push) Has been cancelled
Deploy / deploy-dev (push) Has been cancelled
Deploy / deploy-prod (push) Has been cancelled
fix(iam): allow paychex period table and optional secrets (PLAT-195) (#147)
* fix(iam): allow paychex period table and optional secrets (PLAT-195)

The processor role already allows these ARNs. The live boundary denied
them, so GetSecretValue and period PutItem returned HTTP 400. Sync the
template to the live ceiling and add the missing period table plus
slack-admin and afterhours secret suffixes.

* fix(iam): keep paychex boundary description unchanged (PLAT-195)

IAM managed-policy Description is immutable. Changing it on a named
policy forces replacement and 409s against the live ManagedPolicyName.
Widen PolicyDocument only.
2026-09-14 18:31:08 +00:00
..
deploy-substrate fix(iam): allow paychex period table and optional secrets (PLAT-195) (#147) 2026-09-14 18:31:08 +00:00
hcptf-bootstrap fix(iam): use unique HCP bootstrap workspace names (PLAT-143) (#138) 2026-09-02 15:51:39 +00:00
scp chore(iam): remove frontend tf-poc substrate after teardown (PLAT-194) (#146) 2026-09-11 22:17:00 +00:00
terraform-substrate chore(iam): remove frontend tf-poc substrate after teardown (PLAT-194) (#146) 2026-09-11 22:17:00 +00:00
account-baseline-stack.ts Merge external-dev member baseline; rename to seahaven-org-baseline (#43) 2026-07-14 13:53:07 -04:00
alarm-topic-stack.ts feat(prod): seahaven-prod DynamoDB CMK + site-alerts alarm topic (procurement-ingest migration Phase 0a) (#57) 2026-07-23 15:29:55 -04:00
app-web-acl-stack.ts feat(waf): add seahaven-prod shared CloudFront WebACL (PLAT-92) (#96) 2026-08-07 17:07:04 -04:00
backup-offsite-stack.ts Add AWS Backup with offsite vault (audit C-7) (#3) 2026-05-29 18:06:17 -04:00
backup-stack.ts chore: drop deleted tables from Phase2 backup selection (#59) 2026-07-23 16:21:04 -04:00
bedrock-logging-regional.ts [INFRA-91/89/16/88/73] Reconcile out-of-band baseline changes + add missing detective controls (#18) 2026-06-08 17:03:18 -04:00
bedrock-logging.ts Add Bedrock invocation logging destinations (#12) 2026-06-03 15:17:39 -04:00
cis-monitoring.ts feat: harden CIS 4.1 detection depth with M-of-N alarm tuning and CloudTrail Insights (#38) 2026-07-07 15:47:41 -04:00
deploy-substrate-stack.ts fix(deploy-substrate): move boundary-gated IAM policy off the role's inline budget 2026-07-27 16:43:15 -04:00
detective-controls.ts seahaven-dev account baseline with org-managed detection (Phase 4) (#49) 2026-07-14 16:41:36 -04:00
dynamodb-cmk-stack.ts [INFRA-95] Shared DynamoDB CMK for sensitive finance/PII tables (M-3) (#21) 2026-06-08 19:04:42 -04:00
flow-logs.ts Merge external-dev member baseline; rename to seahaven-org-baseline (#43) 2026-07-14 13:53:07 -04:00
governance-toggles.ts Merge external-dev member baseline; rename to seahaven-org-baseline (#43) 2026-07-14 13:53:07 -04:00
logs-key.ts [INFRA-96] CMK-encrypt sensitive CloudWatch log groups (M-24) (#20) 2026-06-08 19:04:36 -04:00
member-baseline-stack.ts seahaven-prod account baseline (Phase 5) (#50) 2026-07-14 17:17:55 -04:00
org-governance-stack.ts feat(iam): lock app-owned HCP IAM and add bootstrap SCP (PLAT-143) (#137) 2026-09-02 15:22:48 +00:00
regional-baseline-stack.ts [INFRA-91/89/16/88/73] Reconcile out-of-band baseline changes + add missing detective controls (#18) 2026-06-08 17:03:18 -04:00
ses-monitoring.ts Add monitoring + logging layer (audit Day 2: H-1/H-14/M-13) (#6) 2026-06-02 15:16:24 -04:00
terraform-substrate-stack.ts feat(iam): lock app-owned HCP IAM and add bootstrap SCP (PLAT-143) (#137) 2026-09-02 15:22:48 +00:00
web-acl.ts Add shared CloudFront WAF WebACL (audit Day 3: M-17) (#7) 2026-06-02 16:42:24 -04:00