mirror of
https://github.com/Sea-Haven-Industries/seahaven-org-baseline.git
synced 2026-10-01 12:03:17 +00:00
The L1 AWS::Config::ConfigurationRecorder deadlocks the CDK stack (recorder can't complete without a delivery channel; channel can't be created without a recorder — observed 2026-06-01). Fix: three AwsCustomResource nodes call PutConfigurationRecorder → PutDeliveryChannel → StartConfigurationRecorder in sequence. Put* is an idempotent upsert, so the deploy adopts the existing CLI-created recorder and channel without destroying or interrupting them. onDelete stops recording rather than deleting the per-account singleton. New IAM permissions on the custom-resource role (cross-reviewed, GPT-4.1 APPROVE — no BLOCK): config:PutConfigurationRecorder config:PutDeliveryChannel config:StartConfigurationRecorder config:StopConfigurationRecorder iam:PassRole → seahaven-config-recorder-role (service=config) cdk diff shows [+] adds only — no existing resources destroyed or replaced. Removes README note that recorder/channel are CLI-only. Refs: INFRA-17 |
||
|---|---|---|
| .. | ||
| account-baseline-stack.ts | ||
| backup-offsite-stack.ts | ||
| backup-stack.ts | ||
| bedrock-logging-regional.ts | ||
| bedrock-logging.ts | ||
| cis-monitoring.ts | ||
| detective-controls.ts | ||
| dynamodb-cmk-stack.ts | ||
| flow-logs.ts | ||
| governance-toggles.ts | ||
| logs-key.ts | ||
| regional-baseline-stack.ts | ||
| ses-monitoring.ts | ||
| web-acl.ts | ||