From 2381907236dddb7b1f09637c4fcd3c2030bb33f3 Mon Sep 17 00:00:00 2001 From: Adam Moussa <166072409+amoussa1229@users.noreply.github.com> Date: Tue, 2 Jun 2026 17:19:48 -0400 Subject: [PATCH] Grant wafv2 to github-cfn-execution-role for WAF associations (audit M-17) (#33) MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Adds read + (dis)associate wafv2 actions so SAM/CFN deploys can attach the shared seahaven-app-waf CloudFront WebACL to app distributions (meal-order orders). Without it, the WebACL association fails 'Unable to verify read permissions on Web ACL'. IAM cross-reviewed (no BLOCK). Not wafv2:* — scoped to read + associate. Same manual-changeset deploy path as the H-16 change. --- oidc-deploy-roles.yaml | 12 ++++++++++++ 1 file changed, 12 insertions(+) diff --git a/oidc-deploy-roles.yaml b/oidc-deploy-roles.yaml index b8f1973..fbb3279 100644 --- a/oidc-deploy-roles.yaml +++ b/oidc-deploy-roles.yaml @@ -76,6 +76,18 @@ Resources: - cloudfront:* - ssm:* Resource: "*" + # WAF (audit M-17) — needed for SAM/CFN-managed WebACL associations + # on CloudFront distributions (meal-order-manager orders). Read + + # (dis)associate only, not wafv2:*. Added 2026-06-02. + - Effect: Allow + Action: + - wafv2:GetWebACL + - wafv2:GetWebACLForResource + - wafv2:ListWebACLs + - wafv2:AssociateWebACL + - wafv2:DisassociateWebACL + - wafv2:ListResourcesForWebACL + Resource: "*" # --------------------------------------------------------------------------- # SAM deploy roles (4 repos)