Grant wafv2 to github-cfn-execution-role for WAF associations (audit M-17)

Adds read + (dis)associate wafv2 actions so SAM/CFN deploys can attach the shared
seahaven-app-waf CloudFront WebACL to app distributions (meal-order orders).
Without it, the WebACL association fails 'Unable to verify read permissions on
Web ACL'. IAM cross-reviewed (no BLOCK). Not wafv2:* — scoped to read +
associate. Same manual-changeset deploy path as the H-16 change.
This commit is contained in:
Adam Moussa 2026-06-02 17:15:47 -04:00
parent f5e93b7933
commit 7bf32c7fbd

View file

@ -76,6 +76,18 @@ Resources:
- cloudfront:*
- ssm:*
Resource: "*"
# WAF (audit M-17) — needed for SAM/CFN-managed WebACL associations
# on CloudFront distributions (meal-order-manager orders). Read +
# (dis)associate only, not wafv2:*. Added 2026-06-02.
- Effect: Allow
Action:
- wafv2:GetWebACL
- wafv2:GetWebACLForResource
- wafv2:ListWebACLs
- wafv2:AssociateWebACL
- wafv2:DisassociateWebACL
- wafv2:ListResourcesForWebACL
Resource: "*"
# ---------------------------------------------------------------------------
# SAM deploy roles (4 repos)