seahaven-org-baseline/lib/app-web-acl-stack.ts
Adam Moussa a6f22880db
Some checks are pending
Deploy / deploy-management (push) Waiting to run
Deploy / deploy-external-dev (push) Waiting to run
Deploy / deploy-security (push) Waiting to run
Deploy / deploy-dev (push) Waiting to run
Deploy / deploy-prod (push) Waiting to run
feat(waf): add seahaven-prod shared CloudFront WebACL (PLAT-92) (#96)
* feat(waf): add seahaven-prod shared CloudFront WebACL stack

Stand up AppWebAcl in a thin prod stack and widen seahaven-site HCP
roles to read the SSM ARN so CloudFront can associate the ACL in-account.

* fix(deploy): add app-web-acl-prod to deploy.yaml
2026-08-07 17:07:04 -04:00

25 lines
1,010 B
TypeScript

import * as cdk from "aws-cdk-lib";
import { Construct } from "constructs";
import { AppWebAcl } from "./web-acl";
/**
* Thin per-account stack that owns the shared CloudFront WAFv2 WebACL (M-17)
* and publishes its ARN to SSM `/seahaven/waf/app-web-acl-arn`.
*
* Mgmt already has this ACL inside `AccountBaselineStack`. Workload accounts
* (starting with seahaven-prod / PLAT-92) get a dedicated stack so we do not
* pull the full mgmt baseline (trail, budgets, flow logs, …) into prod just
* to share a CloudFront WAF. App stacks associate by reading the SSM param
* in-account — WAFv2 CloudFront associations are same-account only.
*/
export class AppWebAclStack extends cdk.Stack {
constructor(scope: Construct, id: string, props?: cdk.StackProps) {
super(scope, id, props);
new AppWebAcl(this, "AppWebAcl");
cdk.Tags.of(this).add("Project", "account-baseline");
cdk.Tags.of(this).add("Owner", "adam@seahavenind.com");
cdk.Tags.of(this).add("ManagedBy", "cdk");
}
}