mirror of
https://github.com/Sea-Haven-Industries/seahaven-org-baseline.git
synced 2026-09-30 06:53:17 +00:00
Previously the L2 cloudtrail.Trail auto-created a log group with a CDK-generated hash suffix in its name. The 15 CIS Section 4 metric filters in CisMonitoring imported that group by the hardcoded generated name. If the Trail or log group was ever recreated the suffix changes and all 15 filters would silently detach with no error, leaving the account unmonitored. Replace with an explicit logs.LogGroup named seahaven-account-baseline-trail-logs (stable, no hash suffix) with RemovalPolicy.RETAIN. Pass the CDK object — not a name constant — to the Trail via cloudWatchLogGroup and forward it to CisMonitoring via a new trailLogGroup prop. All 15 filters now reference the CDK object so they can never drift from the group the Trail actually delivers to. The old auto-named log group is orphaned by this deploy (CloudFormation loses track of it and does not delete it). Historical audit logs in the old group remain accessible in CloudWatch under the old name; no audit history is destroyed. Refs: INFRA-19 |
||
|---|---|---|
| .. | ||
| account-baseline-stack.ts | ||
| backup-offsite-stack.ts | ||
| backup-stack.ts | ||
| bedrock-logging-regional.ts | ||
| bedrock-logging.ts | ||
| cis-monitoring.ts | ||
| detective-controls.ts | ||
| dynamodb-cmk-stack.ts | ||
| flow-logs.ts | ||
| governance-toggles.ts | ||
| logs-key.ts | ||
| regional-baseline-stack.ts | ||
| ses-monitoring.ts | ||
| web-acl.ts | ||