diff --git a/template.yaml b/template.yaml index 965bc08..3f1b36f 100644 --- a/template.yaml +++ b/template.yaml @@ -21,6 +21,12 @@ Parameters: Type: String Default: adam@seahavenind.com Description: SES verified sender email for payroll reports + # Shared CloudFront WAF WebACL ARN (audit M-17), published to SSM by + # seahaven-account-baseline. Resolved at deploy time. + WebAclArn: + Type: AWS::SSM::Parameter::Value + Default: /seahaven/waf/app-web-acl-arn + Description: ARN of the shared seahaven-app-waf CloudFront WebACL Conditions: HasCustomDomain: !Not [!Equals [!Ref CertificateArn, '']] @@ -164,9 +170,7 @@ Resources: Comment: meal-order-manager form hosting PriceClass: PriceClass_100 HttpVersion: http2and3 - # WebACLId (M-17) deferred: the github-cfn-execution-role lacks wafv2 - # permissions, so the WAF association fails ("Unable to verify read - # permissions on Web ACL"). Re-add once the deploy role is granted wafv2. + WebACLId: !Ref WebAclArn # shared CloudFront WAF (audit M-17) Aliases: !If - HasCustomDomain - [!Ref CustomDomain]