import * as cdk from "aws-cdk-lib"; import { Construct } from "constructs"; import { AppWebAcl } from "./web-acl"; /** * Thin per-account stack that owns the shared CloudFront WAFv2 WebACL (M-17) * and publishes its ARN to SSM `/seahaven/waf/app-web-acl-arn`. * * Mgmt already has this ACL inside `AccountBaselineStack`. Workload accounts * (starting with seahaven-prod / PLAT-92) get a dedicated stack so we do not * pull the full mgmt baseline (trail, budgets, flow logs, …) into prod just * to share a CloudFront WAF. App stacks associate by reading the SSM param * in-account — WAFv2 CloudFront associations are same-account only. */ export class AppWebAclStack extends cdk.Stack { constructor(scope: Construct, id: string, props?: cdk.StackProps) { super(scope, id, props); new AppWebAcl(this, "AppWebAcl"); cdk.Tags.of(this).add("Project", "account-baseline"); cdk.Tags.of(this).add("Owner", "adam@seahavenind.com"); cdk.Tags.of(this).add("ManagedBy", "cdk"); } }