Adds read + (dis)associate wafv2 actions so SAM/CFN deploys can attach the shared
seahaven-app-waf CloudFront WebACL to app distributions (meal-order orders).
Without it, the WebACL association fails 'Unable to verify read permissions on
Web ACL'. IAM cross-reviewed (no BLOCK). Not wafv2:* — scoped to read +
associate. Same manual-changeset deploy path as the H-16 change.
- New githubdeploy-seahaven-account-baseline OIDC role (CDK pattern: assumes
cdk-hnb659fds-*, scoped to the repo's main branch). Wires CD for the shared
account-baseline repo (CloudTrail C-1 + AWS Backup C-7).
- Codify cloudfront:* and ssm:* on github-cfn-execution-role to reconcile
out-of-band drift (audit H-16). These are needed by live SAM deploys
(meal-order CloudFront; afterhours/payments/meal-order SSM params).
Deployed via change set wire-account-baseline-and-h16; stack now IN_SYNC.
IAM cross-review completed (new role confirmed; cfn-exec breadth documented).
Mirrors the existing per-repo deploy roles (StringLike sub claim, scoped to
repo:<org>/apm-wo-analysis:ref:refs/heads/main, sts:AssumeRole on
cdk-hnb659fds-* only). Cross-reviewed (cross_reviewer): additive, no existing
role modified; the one flagged item (StringLike->StringEquals) was a false
positive — all 8 existing roles use StringLike, so this is consistent.
- SQS/EC2/SNS as inline policy (managed policy quota is 10)
- cd-sam.yaml now accepts optional parameter-overrides input for
SAM templates with required parameters
- Add cloudformation:CreateChangeSet on aws:transform/* to the shared
CFN execution role (required for SAM's Serverless transform)
- Remove working-directory from pip install step so it finds
requirements.txt at repo root (not just cdk-dir)