2026-08-07 17:07:04 -04:00
|
|
|
import * as cdk from "aws-cdk-lib";
|
|
|
|
|
import { Construct } from "constructs";
|
|
|
|
|
import { AppWebAcl } from "./web-acl";
|
|
|
|
|
|
|
|
|
|
/**
|
|
|
|
|
* Thin per-account stack that owns the shared CloudFront WAFv2 WebACL (M-17)
|
|
|
|
|
* and publishes its ARN to SSM `/seahaven/waf/app-web-acl-arn`.
|
|
|
|
|
*
|
2026-10-02 00:25:04 +00:00
|
|
|
* Prod owns this stack (PLAT-92). The management account's copy lived inside
|
|
|
|
|
* `AccountBaselineStack` and was removed after its deletion policy was Retain,
|
|
|
|
|
* because the physical ACL was already gone. App stacks associate by reading
|
|
|
|
|
* the SSM param in-account. WAFv2 CloudFront associations are same-account only.
|
2026-08-07 17:07:04 -04:00
|
|
|
*/
|
|
|
|
|
export class AppWebAclStack extends cdk.Stack {
|
|
|
|
|
constructor(scope: Construct, id: string, props?: cdk.StackProps) {
|
|
|
|
|
super(scope, id, props);
|
|
|
|
|
|
|
|
|
|
new AppWebAcl(this, "AppWebAcl");
|
|
|
|
|
|
|
|
|
|
cdk.Tags.of(this).add("Project", "account-baseline");
|
|
|
|
|
cdk.Tags.of(this).add("Owner", "adam@seahavenind.com");
|
|
|
|
|
cdk.Tags.of(this).add("ManagedBy", "cdk");
|
|
|
|
|
}
|
|
|
|
|
}
|