Associate shared WAF WebACL with orders distribution (audit M-17) (#19)
Some checks failed
Deploy / deploy (push) Has been cancelled

Re-adds WebACLId (from SSM /seahaven/waf/app-web-acl-arn) now that the
github-cfn-execution-role has wafv2 perms. Deployed + verified: orders.seahaven.com
distribution now fronted by seahaven-app-waf.
This commit is contained in:
Adam Moussa 2026-06-02 17:20:58 -04:00 • committed by GitHub
parent e0b12cb93e
commit 9c1717a77c
No known key found for this signature in database
GPG key ID: B5690EEEBB952194

View file

@ -21,6 +21,12 @@ Parameters:
Type: String
Default: adam@seahavenind.com
Description: SES verified sender email for payroll reports
# Shared CloudFront WAF WebACL ARN (audit M-17), published to SSM by
# seahaven-account-baseline. Resolved at deploy time.
WebAclArn:
Type: AWS::SSM::Parameter::Value<String>
Default: /seahaven/waf/app-web-acl-arn
Description: ARN of the shared seahaven-app-waf CloudFront WebACL
Conditions:
HasCustomDomain: !Not [!Equals [!Ref CertificateArn, '']]
@ -164,9 +170,7 @@ Resources:
Comment: meal-order-manager form hosting
PriceClass: PriceClass_100
HttpVersion: http2and3
# WebACLId (M-17) deferred: the github-cfn-execution-role lacks wafv2
# permissions, so the WAF association fails ("Unable to verify read
# permissions on Web ACL"). Re-add once the deploy role is granted wafv2.
WebACLId: !Ref WebAclArn # shared CloudFront WAF (audit M-17)
Aliases: !If
- HasCustomDomain
- [!Ref CustomDomain]