seahaven-org-baseline/lib
Adam Moussa e22c4ac005
Bring Config recorder + channel under IaC via AwsCustomResource (#22)
The L1 AWS::Config::ConfigurationRecorder deadlocks the CDK stack
(recorder can't complete without a delivery channel; channel can't be
created without a recorder — observed 2026-06-01).

Fix: three AwsCustomResource nodes call PutConfigurationRecorder →
PutDeliveryChannel → StartConfigurationRecorder in sequence. Put* is
an idempotent upsert, so the deploy adopts the existing CLI-created
recorder and channel without destroying or interrupting them. onDelete
stops recording rather than deleting the per-account singleton.

New IAM permissions on the custom-resource role (cross-reviewed,
GPT-4.1 APPROVE — no BLOCK):
  config:PutConfigurationRecorder
  config:PutDeliveryChannel
  config:StartConfigurationRecorder
  config:StopConfigurationRecorder
  iam:PassRole → seahaven-config-recorder-role (service=config)

cdk diff shows [+] adds only — no existing resources destroyed or
replaced. Removes README note that recorder/channel are CLI-only.

Refs: INFRA-17
2026-06-10 14:38:23 -04:00
..
account-baseline-stack.ts [INFRA-96] CMK-encrypt sensitive CloudWatch log groups (M-24) (#20) 2026-06-08 19:04:36 -04:00
backup-offsite-stack.ts Add AWS Backup with offsite vault (audit C-7) (#3) 2026-05-29 18:06:17 -04:00
backup-stack.ts [INFRA-94] Add Backup vault access policy on seahaven-primary (#19) 2026-06-08 17:34:01 -04:00
bedrock-logging-regional.ts [INFRA-91/89/16/88/73] Reconcile out-of-band baseline changes + add missing detective controls (#18) 2026-06-08 17:03:18 -04:00
bedrock-logging.ts Add Bedrock invocation logging destinations (#12) 2026-06-03 15:17:39 -04:00
cis-monitoring.ts Replace aws/sns key with CMK on alarm topics (#13) 2026-06-03 15:33:52 -04:00
detective-controls.ts Bring Config recorder + channel under IaC via AwsCustomResource (#22) 2026-06-10 14:38:23 -04:00
dynamodb-cmk-stack.ts [INFRA-95] Shared DynamoDB CMK for sensitive finance/PII tables (M-3) (#21) 2026-06-08 19:04:42 -04:00
flow-logs.ts Add monitoring + logging layer (audit Day 2: H-1/H-14/M-13) (#6) 2026-06-02 15:16:24 -04:00
governance-toggles.ts Account detective layer + budget (audit Day 1) (#5) 2026-06-01 17:56:12 -04:00
logs-key.ts [INFRA-96] CMK-encrypt sensitive CloudWatch log groups (M-24) (#20) 2026-06-08 19:04:36 -04:00
regional-baseline-stack.ts [INFRA-91/89/16/88/73] Reconcile out-of-band baseline changes + add missing detective controls (#18) 2026-06-08 17:03:18 -04:00
ses-monitoring.ts Add monitoring + logging layer (audit Day 2: H-1/H-14/M-13) (#6) 2026-06-02 15:16:24 -04:00
web-acl.ts Add shared CloudFront WAF WebACL (audit Day 3: M-17) (#7) 2026-06-02 16:42:24 -04:00