mirror of
https://github.com/Sea-Haven-Industries/seahaven-org-baseline.git
synced 2026-09-30 09:13:17 +00:00
SAM repos migrating off the frozen management account need the shared deploy plumbing (permissions boundary + github-cfn-execution-role) in their target account; none of it existed outside mgmt, so there was no OIDC SAM deploy path into seahaven-prod or seahaven-dev at all. Adds a templated, per-account substrate stack so onboarding a future account is one bin/app.ts instance plus one CD job, not a hand-rolled copy. Per-repo githubdeploy-* roles stay out by design: they are provisioned per repo at migration time so an account never accumulates trust for repos that do not deploy to it. The template is a verbatim extraction of the reviewed mgmt substrate, with deliberate, documented divergences — notably the removal of iam:DeleteRolePermissionsBoundary plus explicit Deny backstops, which closes a confirmed privilege-escalation path (see PR body). |
||
|---|---|---|
| .. | ||
| deploy-substrate | ||
| scp | ||
| account-baseline-stack.ts | ||
| alarm-topic-stack.ts | ||
| backup-offsite-stack.ts | ||
| backup-stack.ts | ||
| bedrock-logging-regional.ts | ||
| bedrock-logging.ts | ||
| cis-monitoring.ts | ||
| deploy-substrate-stack.ts | ||
| detective-controls.ts | ||
| dynamodb-cmk-stack.ts | ||
| flow-logs.ts | ||
| governance-toggles.ts | ||
| logs-key.ts | ||
| member-baseline-stack.ts | ||
| org-governance-stack.ts | ||
| regional-baseline-stack.ts | ||
| ses-monitoring.ts | ||
| web-acl.ts | ||