mirror of
https://github.com/Sea-Haven-Industries/seahaven-org-baseline.git
synced 2026-10-03 01:03:13 +00:00
fix(baseline): stop the mgmt web acl parameter from reading a missing acl (#172)
CloudFormation refreshes WebACL.Arn with GetWebACL when the parameter depends on it. The ACL is already gone, so that call fails the update before Retain can stick.
This commit is contained in:
parent
54c81dedc9
commit
cd37817e1f
2 changed files with 22 additions and 2 deletions
|
|
@ -258,8 +258,12 @@ export class AccountBaselineStack extends cdk.Stack {
|
|||
// deletion policy has to be in the live template before the construct is
|
||||
// removed, or CloudFormation Deletes, fails, and rollback tries to
|
||||
// recreate it. The SSM parameter stays on Delete.
|
||||
// existingWebAclId keeps the parameter and output off WebACL.Arn. GetAtt
|
||||
// calls GetWebACL, which fails because the ACL is gone. The id is the
|
||||
// physical id CloudFormation already recorded for AppWebAclFE38F02F.
|
||||
new AppWebAcl(this, "AppWebAcl", {
|
||||
webAclRemovalPolicy: cdk.RemovalPolicy.RETAIN,
|
||||
existingWebAclId: "cd668fe8-5cff-4d6a-9432-5c32145a7db4",
|
||||
});
|
||||
|
||||
// ── Day 5 AI governance ──
|
||||
|
|
|
|||
|
|
@ -21,6 +21,13 @@ export interface AppWebAclProps {
|
|||
* already gone and a Delete call would fail and roll back into a recreate.
|
||||
*/
|
||||
readonly webAclRemovalPolicy?: cdk.RemovalPolicy;
|
||||
/**
|
||||
* Physical id of a WebACL CloudFormation already tracks. When set, the SSM
|
||||
* parameter and output publish `global/webacl/seahaven-app-waf/<id>` with
|
||||
* account and region tokens, and do not reference WebACL.Arn. GetAtt on a
|
||||
* missing ACL calls GetWebACL and fails the stack update.
|
||||
*/
|
||||
readonly existingWebAclId?: string;
|
||||
}
|
||||
|
||||
export class AppWebAcl extends Construct {
|
||||
|
|
@ -78,12 +85,21 @@ export class AppWebAcl extends Construct {
|
|||
webAcl.applyRemovalPolicy(props.webAclRemovalPolicy);
|
||||
}
|
||||
|
||||
const publishedArn = props?.existingWebAclId
|
||||
? cdk.Stack.of(this).formatArn({
|
||||
service: "wafv2",
|
||||
resource: "global/webacl",
|
||||
resourceName: `seahaven-app-waf/${props.existingWebAclId}`,
|
||||
arnFormat: cdk.ArnFormat.SLASH_RESOURCE_NAME,
|
||||
})
|
||||
: webAcl.attrArn;
|
||||
|
||||
new ssm.StringParameter(this, "AppWebAclArnParam", {
|
||||
parameterName: "/seahaven/waf/app-web-acl-arn",
|
||||
stringValue: webAcl.attrArn,
|
||||
stringValue: publishedArn,
|
||||
description: "ARN of the shared CloudFront WAF WebACL (audit M-17)",
|
||||
});
|
||||
|
||||
new cdk.CfnOutput(this, "AppWebAclArn", { value: webAcl.attrArn });
|
||||
new cdk.CfnOutput(this, "AppWebAclArn", { value: publishedArn });
|
||||
}
|
||||
}
|
||||
|
|
|
|||
Loading…
Add table
Reference in a new issue