docs+infra: re-verify security monitoring (#161), enable Security Hub + Access Analyzer
With full account access now available, re-ran every check the original pass couldn't: CloudTrail, GuardDuty, and ECR scanning were already true (the doc's claim that ECR scanning wasn't enabled was wrong). Enabled Security Hub and IAM Access Analyzer on both accounts (low-cost, no config decisions needed).
Left AWS Config and account-level S3 Block Public Access deliberately unenabled — Config needs its own cost/setup pass, and account-level BPA would break musehub-releases' intentional public access (installer/release tarballs) without an explicit bucket-level exception first.
Also documents real findings from the now-confirmed-working ECR scan: 7 CRITICAL CVEs in the running image, all base-OS packages with no vendor fix available yet, traced to playwright's chromium install (OG cards, #129) pulling in X11/xorg-server rather than sloppy dependency management.
Semantic Changes
19 symbols
Files Changed
~2
1060 in snapshot
0 comments
muse hub commit comment sha256:75d2964a7ec35f461373e3c83b208df829526661ea6a17060f95df5d50d21fb0 --body "your comment"
No comments yet. Be the first to start the discussion.