seahaven-org-baseline/lib
Adam Moussa 8cbc98d927
feat(scp): deny iam changes on the platform path (PLAT-233) (#159)
* feat(scp): deny iam changes on role/platform unless the platform principal (PLAT-233)

Adds ProtectPlatformPath beside the existing name denies in the
prod/nonprod SCP and the security OU copy. New hcptf-bootstrap
creates use /platform/. Existing roles are not recreated.

Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com>

* fix(scp): use live bootstrap ARNs and close the platform path gaps (PLAT-233)

Resolve simulate and printed role ARNs from iam:GetRole so a /platform/
create is not reported as an unpathed role. Deny boundary changes on
role/platform/*, and match both Identity Center SSO role ARN shapes.

Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com>

* fix(scp): deny platform-path changes in bootstrap simulate (PLAT-233)

Add a simulate case for role/platform/hcptf-example and fail when CreateRole,
PutRolePolicy, or DeleteRole is allowed. The unpathed hcptf-* import check stays.

Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com>

---------

Co-authored-by: Cursor Agent <cursoragent@cursor.com>
Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com>
2026-09-28 16:27:10 +00:00
..
deploy-substrate fix(iam): allow payroll schedule invoke under the paychex boundary (PLAT-228) (#155) 2026-09-25 21:35:19 +00:00
hcptf-bootstrap feat(iam): allow PassRole to ECS tasks and EventBridge Scheduler (#151) 2026-09-21 18:59:08 +00:00
scp feat(scp): deny iam changes on the platform path (PLAT-233) (#159) 2026-09-28 16:27:10 +00:00
terraform-substrate feat(iam): move seahaven-site exec roles into their own stack (PLAT-225) (#153) 2026-09-24 23:37:39 +00:00
account-baseline-stack.ts Merge external-dev member baseline; rename to seahaven-org-baseline (#43) 2026-07-14 13:53:07 -04:00
alarm-topic-stack.ts feat(prod): seahaven-prod DynamoDB CMK + site-alerts alarm topic (procurement-ingest migration Phase 0a) (#57) 2026-07-23 15:29:55 -04:00
app-web-acl-stack.ts feat(waf): add seahaven-prod shared CloudFront WebACL (PLAT-92) (#96) 2026-08-07 17:07:04 -04:00
backup-offsite-stack.ts Add AWS Backup with offsite vault (audit C-7) (#3) 2026-05-29 18:06:17 -04:00
backup-stack.ts chore: drop deleted tables from Phase2 backup selection (#59) 2026-07-23 16:21:04 -04:00
bedrock-logging-regional.ts [INFRA-91/89/16/88/73] Reconcile out-of-band baseline changes + add missing detective controls (#18) 2026-06-08 17:03:18 -04:00
bedrock-logging.ts Add Bedrock invocation logging destinations (#12) 2026-06-03 15:17:39 -04:00
cis-monitoring.ts feat: harden CIS 4.1 detection depth with M-of-N alarm tuning and CloudTrail Insights (#38) 2026-07-07 15:47:41 -04:00
deploy-substrate-stack.ts fix(deploy-substrate): move boundary-gated IAM policy off the role's inline budget 2026-07-27 16:43:15 -04:00
detective-controls.ts seahaven-dev account baseline with org-managed detection (Phase 4) (#49) 2026-07-14 16:41:36 -04:00
dynamodb-cmk-stack.ts [INFRA-95] Shared DynamoDB CMK for sensitive finance/PII tables (M-3) (#21) 2026-06-08 19:04:42 -04:00
flow-logs.ts Merge external-dev member baseline; rename to seahaven-org-baseline (#43) 2026-07-14 13:53:07 -04:00
governance-toggles.ts Merge external-dev member baseline; rename to seahaven-org-baseline (#43) 2026-07-14 13:53:07 -04:00
logs-key.ts [INFRA-96] CMK-encrypt sensitive CloudWatch log groups (M-24) (#20) 2026-06-08 19:04:36 -04:00
member-baseline-stack.ts seahaven-prod account baseline (Phase 5) (#50) 2026-07-14 17:17:55 -04:00
org-governance-stack.ts feat(scp): deny iam changes on the platform path (PLAT-233) (#159) 2026-09-28 16:27:10 +00:00
regional-baseline-stack.ts [INFRA-91/89/16/88/73] Reconcile out-of-band baseline changes + add missing detective controls (#18) 2026-06-08 17:03:18 -04:00
seahaven-site-hcptf-stack.ts fix(iam): let the site plan role describe SSM parameters (PLAT-225) (#154) 2026-09-25 16:40:34 +00:00
ses-monitoring.ts Add monitoring + logging layer (audit Day 2: H-1/H-14/M-13) (#6) 2026-06-02 15:16:24 -04:00
terraform-substrate-stack.ts feat(iam): lock app-owned HCP IAM and add bootstrap SCP (PLAT-143) (#137) 2026-09-02 15:22:48 +00:00
web-acl.ts Add shared CloudFront WAF WebACL (audit Day 3: M-17) (#7) 2026-06-02 16:42:24 -04:00