seahaven-org-baseline/lib
Adam Moussa f2a0cc40d6
Expand AWS Backup to remaining DDB + EBS (audit Day 4 phase-2) (#8)
Add a second BackupSelection 'phase2-offsite-everything' on the existing
seahaven-critical-daily plan covering the 15 remaining DynamoDB tables and
all 9 in-use EBS volumes, with the same daily backup + cross-region copy to
the GOVERNANCE-locked seahaven-offsite vault ('offsite for everything').

Reuses seahaven-backup-service-role (AWSBackupServiceRolePolicyForBackup
already grants DDB/RDS/EBS) - no IAM change. Explicit-ARN (not tag-based) to
avoid drifting the standalone file-share volumes and stack-owned tables, same
as phase-1. The 4 deprecated ledgerflow delete-targets are excluded.

Cross-reviewed (no BLOCK). Follow-up: migrate EBS to tag-based selection with
tags codified in owning stacks for resilience to volume replacement.

Deployed to seahaven-backup before merge; selection verified live (24 resources).
2026-06-03 11:18:53 -04:00
..
account-baseline-stack.ts Add shared CloudFront WAF WebACL (audit Day 3: M-17) (#7) 2026-06-02 16:42:24 -04:00
backup-offsite-stack.ts Add AWS Backup with offsite vault (audit C-7) (#3) 2026-05-29 18:06:17 -04:00
backup-stack.ts Expand AWS Backup to remaining DDB + EBS (audit Day 4 phase-2) (#8) 2026-06-03 11:18:53 -04:00
cis-monitoring.ts Add monitoring + logging layer (audit Day 2: H-1/H-14/M-13) (#6) 2026-06-02 15:16:24 -04:00
detective-controls.ts Account detective layer + budget (audit Day 1) (#5) 2026-06-01 17:56:12 -04:00
flow-logs.ts Add monitoring + logging layer (audit Day 2: H-1/H-14/M-13) (#6) 2026-06-02 15:16:24 -04:00
governance-toggles.ts Account detective layer + budget (audit Day 1) (#5) 2026-06-01 17:56:12 -04:00
ses-monitoring.ts Add monitoring + logging layer (audit Day 2: H-1/H-14/M-13) (#6) 2026-06-02 15:16:24 -04:00
web-acl.ts Add shared CloudFront WAF WebACL (audit Day 3: M-17) (#7) 2026-06-02 16:42:24 -04:00