mirror of
https://github.com/Sea-Haven-Industries/seahaven-org-baseline.git
synced 2026-09-30 10:23:16 +00:00
* Add seahaven-prod member baseline (Phase 5) Account 011934824531 is the target for all new production stacks; the management account is frozen for new workloads. First proven exercise of the automatic enrollment sweep (Enabled in 124s, no manual create-members) and of AutoEnableStandards=NONE (no pre-enabled standards, so CFN owns FSBP + CIS v3.0 cleanly). Default VPC deleted; budget starts at $100 and resizes as tenants land. * Apply Phase-5 review findings Fleet gap closed: EBS encryption-by-default + IAM password policy were management-account-only (the runbook's unscoped 'applied' claim hid it); now applied and verified in all three member accounts, runbook scoped per account. README stack inventory corrected (eleven stacks, org-governance rows restored). Sweep comments reconciled: the automatic enrollment sweep is proven (seahaven-prod, ~2min).
76 lines
3.3 KiB
TypeScript
76 lines
3.3 KiB
TypeScript
import * as cdk from "aws-cdk-lib";
|
|
import { Construct } from "constructs";
|
|
import { DetectiveControls } from "./detective-controls";
|
|
import { FlowLogs } from "./flow-logs";
|
|
import { GovernanceToggles } from "./governance-toggles";
|
|
|
|
export interface MemberBaselineStackProps extends cdk.StackProps {
|
|
/**
|
|
* Physical-name prefix for account-scoped resources (e.g. "seahaven-extdev").
|
|
* Also names the monthly budget (`<namePrefix>-monthly-cost`). Stable per
|
|
* account — changing it on a deployed stack replaces live resources.
|
|
*/
|
|
readonly namePrefix: string;
|
|
/** Monthly cost budget ceiling in USD. */
|
|
readonly monthlyBudgetUsd: number;
|
|
/** Sea Haven ops address that receives budget alerts (not the account's tenants). */
|
|
readonly budgetAlertEmail: string;
|
|
/** Value for the Owner tag (informational; decoupled from alert routing). */
|
|
readonly ownerEmail: string;
|
|
/** VPC ids to attach flow logs to (from cdk context; may be empty). */
|
|
readonly flowLogVpcIds: string[];
|
|
/** Value for the ManagedBy tag on every resource in the stack. */
|
|
readonly managedByTag: string;
|
|
/**
|
|
* TRUE for accounts created after org delegation (2026-07-14): the GuardDuty
|
|
* detector and Security Hub hub are org-managed (auto-enrolled), so the
|
|
* stack must not create local duplicates. Standards and the account analyzer
|
|
* remain CFN-owned either way. Default FALSE (pre-delegation accounts).
|
|
*/
|
|
readonly orgManagedDetection?: boolean;
|
|
}
|
|
|
|
/**
|
|
* Account-local security baseline for org MEMBER accounts (first tenant:
|
|
* seahaven-external-dev). Absorbed from the retired seahaven-external-dev-baseline
|
|
* repo — a stripped fork of the management-account baseline, now sharing its
|
|
* constructs (prefix-parameterized) instead of forking them.
|
|
*
|
|
* Deliberately excludes everything that is org-level or prod-specific:
|
|
* - No local CloudTrail — the management-account org trail (seahaven-org-trail)
|
|
* already captures every member account's events centrally.
|
|
* - No CIS Section-4 metric-filter alarms — the Security Hub CIS standard
|
|
* evaluates those controls against Config without a local trail log group.
|
|
* - No WAF, SES monitoring, Bedrock logging, DynamoDB CMK, or AWS Backup —
|
|
* all prod-only concerns.
|
|
*
|
|
* Contains: AWS Config, Security Hub standards (FSBP + CIS v3.0), IAM Access
|
|
* Analyzer, Inspector2 (post-deploy CLI, see README), VPC flow logs, and a
|
|
* monthly cost Budget — plus the GuardDuty detector + Security Hub hub only
|
|
* when the account predates org delegation (orgManagedDetection false); newer
|
|
* accounts get those from the delegated admin.
|
|
*/
|
|
export class MemberBaselineStack extends cdk.Stack {
|
|
constructor(scope: Construct, id: string, props: MemberBaselineStackProps) {
|
|
super(scope, id, props);
|
|
|
|
new DetectiveControls(this, "DetectiveControls", {
|
|
namePrefix: props.namePrefix,
|
|
localDetectiveServices: !(props.orgManagedDetection ?? false),
|
|
});
|
|
|
|
new FlowLogs(this, "FlowLogs", {
|
|
namePrefix: props.namePrefix,
|
|
vpcIds: props.flowLogVpcIds,
|
|
});
|
|
|
|
new GovernanceToggles(this, "GovernanceToggles", {
|
|
budgetName: `${props.namePrefix}-monthly-cost`,
|
|
monthlyLimitUsd: props.monthlyBudgetUsd,
|
|
alertEmail: props.budgetAlertEmail,
|
|
});
|
|
|
|
cdk.Tags.of(this).add("Owner", props.ownerEmail);
|
|
cdk.Tags.of(this).add("ManagedBy", props.managedByTag);
|
|
}
|
|
}
|