mirror of
https://github.com/Sea-Haven-Industries/seahaven-org-baseline.git
synced 2026-09-30 08:03:19 +00:00
* Codify primary vault lock + add backups (INFRA-89, INFRA-88) INFRA-89: codify the GOVERNANCE Vault Lock applied out-of-band on the seahaven-primary vault (MinRetention 1d, MaxRetention 2555d, no changeableFor = admin-removable) so it lives in IaC. Values match the live lock exactly, so the deploy is a no-op adoption. Add a scoped vault access policy that denies manual recovery-point deletion and lock/policy tampering to all principals except the AWS Backup service role and the break-glass SSO AdministratorAccess role, so automatic lifecycle expiry still works but humans cannot prune recovery points by hand. Cross-review (GPT-4.1) BLOCK: NotPrincipal does not support wildcard ARN matching, so the SSO exemption is expressed as Effect DENY with Principal * and a StringNotLike condition on aws:PrincipalArn, which does support wildcards. This avoids an unrecoverable vault lockout. INFRA-88: add 6 S3 buckets (kb-docs, payroll-emails [PII], amazon-po, extracted-amazon-po, proposal-system uploads + generated) to the phase2-offsite-everything selection. Versioning verified enabled on all 6 against the live account (S3 backup requires versioning). Refs: INFRA-89, INFRA-88 * Promote account trail to organization trail (INFRA-73) INFRA-73: set isOrganizationTrail on seahaven-org-trail and pass orgId (o-9kufuzz6b4) so the L2 Trail attaches the AWSLogs/<org-id>/* bucket PutObject statement for member-account delivery. CloudTrail org trusted-access is already enabled on the management account. Broaden the KMS key policy with an org-scoped GenerateDataKey/DescribeKey statement for member-account trail delivery, guarded by aws:PrincipalOrgID. The existing single-account statements are preserved so management-account delivery is unaffected. Cross-review (GPT-4.1) BLOCK: the member KMS SourceArn and encryption context must be wildcarded across accounts (org-trail shadow trails present the member account id), not pinned to the management account, or member delivery silently fails. Fixed before checkpoint. CHECKPOINT: delicate org-trail KMS/bucket-policy change — code + diff captured for review, NOT deployed. Refs: INFRA-73 * Add secondary-region baseline stacks (INFRA-91, INFRA-16) INFRA-91: codify the Bedrock model-invocation logging applied out-of-band in us-west-2 and us-east-2 (per-region delivery role seahaven-bedrock-invocation-logging-<region> + log group /aws/bedrock/model-invocations 90d, CloudWatch-only). The account-level logging config itself has no CFN resource type and is applied via CLI (already live), same as us-east-1. INFRA-16: add the still-missing us-east-2 detective controls — AWS Config recorder role + delivery bucket (recorder/channel via CLI to avoid the CFN stabilization deadlock seen in us-east-1) and Security Hub with FSBP + CIS v3.0. GuardDuty + flow logs already live in us-east-2 and are left for a follow-up adoption to keep this change non-destructive. The us-east-1 baseline stays region-pinned; these are separate RegionalBaselineStack instances composed opt-in per region. CHECKPOINT: new multi-region stacks. The live Bedrock role + log group already exist (CLI-created), so a plain deploy would collide — these need cdk import / changeset adoption, not cdk deploy. Code + diff captured for review, NOT deployed. Refs: INFRA-91, INFRA-16 * Drop vault access policy from this deploy; tracked in INFRA-94 (kept governance lock codify + selection)
71 lines
2.7 KiB
TypeScript
71 lines
2.7 KiB
TypeScript
import * as cdk from "aws-cdk-lib";
|
|
import * as iam from "aws-cdk-lib/aws-iam";
|
|
import * as logs from "aws-cdk-lib/aws-logs";
|
|
import { Construct } from "constructs";
|
|
|
|
/**
|
|
* Regional Bedrock model-invocation logging destination + delivery role
|
|
* (INFRA-91). Bedrock invocation logging is account-level *per region*, so
|
|
* extending the us-east-1 coverage (lib/bedrock-logging.ts) to the other
|
|
* regions where Bedrock is reachable (us-west-2, us-east-2) requires a separate
|
|
* regional stack with its own log group + delivery role per region.
|
|
*
|
|
* This codifies the out-of-band CLI state applied 2026-06 to MATCH exactly so
|
|
* the adoption diff is minimal:
|
|
* - IAM role seahaven-bedrock-invocation-logging-<region>
|
|
* - log group /aws/bedrock/model-invocations (90d)
|
|
* - CloudWatch-only delivery (no S3 leg — unlike us-east-1, these regions log
|
|
* to CloudWatch only; the large-payload S3 bucket is us-east-1 only).
|
|
*
|
|
* Like us-east-1, the account-level logging configuration itself has no CFN
|
|
* resource type (`PutModelInvocationLoggingConfiguration`); it is applied via
|
|
* CLI per region (already live — see README). This construct owns only the
|
|
* destinations + role the live config references.
|
|
*/
|
|
export class BedrockLoggingRegional extends Construct {
|
|
public readonly logGroup: logs.LogGroup;
|
|
public readonly deliveryRole: iam.Role;
|
|
|
|
constructor(scope: Construct, id: string) {
|
|
super(scope, id);
|
|
|
|
const stack = cdk.Stack.of(this);
|
|
|
|
this.logGroup = new logs.LogGroup(this, "InvocationLogGroup", {
|
|
logGroupName: "/aws/bedrock/model-invocations",
|
|
retention: logs.RetentionDays.THREE_MONTHS,
|
|
removalPolicy: cdk.RemovalPolicy.RETAIN,
|
|
});
|
|
|
|
// Region-suffixed role name matches the live CLI-created role so CFN can
|
|
// adopt it by import rather than creating a colliding new one.
|
|
this.deliveryRole = new iam.Role(this, "DeliveryRole", {
|
|
roleName: `seahaven-bedrock-invocation-logging-${stack.region}`,
|
|
assumedBy: new iam.ServicePrincipal("bedrock.amazonaws.com", {
|
|
conditions: {
|
|
StringEquals: { "aws:SourceAccount": stack.account },
|
|
ArnLike: {
|
|
"aws:SourceArn": `arn:aws:bedrock:${stack.region}:${stack.account}:*`,
|
|
},
|
|
},
|
|
}),
|
|
});
|
|
|
|
this.deliveryRole.addToPolicy(
|
|
new iam.PolicyStatement({
|
|
actions: ["logs:CreateLogStream", "logs:PutLogEvents"],
|
|
resources: [
|
|
this.logGroup.logGroupArn,
|
|
`${this.logGroup.logGroupArn}:log-stream:*`,
|
|
],
|
|
}),
|
|
);
|
|
|
|
new cdk.CfnOutput(this, "BedrockLogGroupName", {
|
|
value: this.logGroup.logGroupName,
|
|
});
|
|
new cdk.CfnOutput(this, "BedrockLoggingRoleArn", {
|
|
value: this.deliveryRole.roleArn,
|
|
});
|
|
}
|
|
}
|