AWS CDK IAM and VPC security as code: KMS, WAFv2, and Security Hub in one stack
Security-as-code on AWS CDK: least-privilege IAM, KMS, VPC endpoints for secrets, WAFv2, Security Hub.
Production CDK stack enforcing KMS encryption, least-privilege IAM, VPC endpoint routing, WAFv2 on CloudFront and API Gateway, and Security Hub — versioned and testable.