error_message = "This configuration targets account ${local.account_id}, but the credentials resolve to ${data.aws_caller_identity.current.account_id}."
}
}
# Alarm sink owned by seahaven-org-baseline, not by this configuration.
data"aws_sns_topic""site_alerts"{
name = "site-alerts"
}
# Shared CloudFront WAF WebACL (audit M-17), published to Parameter Store by the
# org baseline. aws_cloudfront_distribution.web_acl_id takes the WAFv2 ARN
# despite the attribute name.
data"aws_ssm_parameter""app_web_acl_arn"{
name = "/seahaven/waf/app-web-acl-arn"
}
# Google OAuth client ID used by submit-order and the admin authorizer. The
# parameter is created and rotated out-of-band because it varies per
# environment; this lookup only asserts that it exists before an apply wires
# functions that read it at runtime. Its NAME, not its value, is what reaches