seahaven-org-baseline/lib
Adam Moussa cd82b49f17
Stabilize CloudTrail log group name to prevent filter detachment (#23)
Previously the L2 cloudtrail.Trail auto-created a log group with a
CDK-generated hash suffix in its name. The 15 CIS Section 4 metric
filters in CisMonitoring imported that group by the hardcoded generated
name. If the Trail or log group was ever recreated the suffix changes
and all 15 filters would silently detach with no error, leaving the
account unmonitored.

Replace with an explicit logs.LogGroup named
seahaven-account-baseline-trail-logs (stable, no hash suffix) with
RemovalPolicy.RETAIN. Pass the CDK object — not a name constant — to
the Trail via cloudWatchLogGroup and forward it to CisMonitoring via a
new trailLogGroup prop. All 15 filters now reference the CDK object so
they can never drift from the group the Trail actually delivers to.

The old auto-named log group is orphaned by this deploy (CloudFormation
loses track of it and does not delete it). Historical audit logs in the
old group remain accessible in CloudWatch under the old name; no audit
history is destroyed.

Refs: INFRA-19
2026-06-10 14:44:33 -04:00
..
account-baseline-stack.ts Stabilize CloudTrail log group name to prevent filter detachment (#23) 2026-06-10 14:44:33 -04:00
backup-offsite-stack.ts Add AWS Backup with offsite vault (audit C-7) (#3) 2026-05-29 18:06:17 -04:00
backup-stack.ts [INFRA-94] Add Backup vault access policy on seahaven-primary (#19) 2026-06-08 17:34:01 -04:00
bedrock-logging-regional.ts [INFRA-91/89/16/88/73] Reconcile out-of-band baseline changes + add missing detective controls (#18) 2026-06-08 17:03:18 -04:00
bedrock-logging.ts Add Bedrock invocation logging destinations (#12) 2026-06-03 15:17:39 -04:00
cis-monitoring.ts Stabilize CloudTrail log group name to prevent filter detachment (#23) 2026-06-10 14:44:33 -04:00
detective-controls.ts Bring Config recorder + channel under IaC via AwsCustomResource (#22) 2026-06-10 14:38:23 -04:00
dynamodb-cmk-stack.ts [INFRA-95] Shared DynamoDB CMK for sensitive finance/PII tables (M-3) (#21) 2026-06-08 19:04:42 -04:00
flow-logs.ts Add monitoring + logging layer (audit Day 2: H-1/H-14/M-13) (#6) 2026-06-02 15:16:24 -04:00
governance-toggles.ts Account detective layer + budget (audit Day 1) (#5) 2026-06-01 17:56:12 -04:00
logs-key.ts [INFRA-96] CMK-encrypt sensitive CloudWatch log groups (M-24) (#20) 2026-06-08 19:04:36 -04:00
regional-baseline-stack.ts [INFRA-91/89/16/88/73] Reconcile out-of-band baseline changes + add missing detective controls (#18) 2026-06-08 17:03:18 -04:00
ses-monitoring.ts Add monitoring + logging layer (audit Day 2: H-1/H-14/M-13) (#6) 2026-06-02 15:16:24 -04:00
web-acl.ts Add shared CloudFront WAF WebACL (audit Day 3: M-17) (#7) 2026-06-02 16:42:24 -04:00