From 37c6f80eba59e7304e197ef5a12a1664d37c4827 Mon Sep 17 00:00:00 2001 From: Adam Moussa <166072409+amoussa1229@users.noreply.github.com> Date: Fri, 7 Aug 2026 17:21:46 -0400 Subject: [PATCH] feat(infra): associate shared prod CloudFront WAF (PLAT-92) (#38) * feat(infra): associate shared prod CloudFront WAF with site distribution Read /seahaven/waf/app-web-acl-arn and set web_acl_id so the marketing site sits behind the same-account M-17 WebACL. * chore: empty commit to trigger CI * fix(infra): mark CloudFront WebACL output nonsensitive SSM String parameters are sensitive by default, which broke the HCP speculative plan when exporting the WebACL ARN. --- terraform/cloudfront.tf | 8 ++++++++ terraform/outputs.tf | 7 +++++++ 2 files changed, 15 insertions(+) diff --git a/terraform/cloudfront.tf b/terraform/cloudfront.tf index e507ddd..2f18033 100644 --- a/terraform/cloudfront.tf +++ b/terraform/cloudfront.tf @@ -6,6 +6,13 @@ resource "aws_cloudfront_origin_access_control" "site" { signing_protocol = "sigv4" } +# Shared CloudFront WAF (M-17) published by org-baseline stack seahaven-app-web-acl +# in this account (PLAT-92). aws_cloudfront_distribution.web_acl_id takes the +# WAFv2 ARN despite the attribute name. +data "aws_ssm_parameter" "app_web_acl_arn" { + name = "/seahaven/waf/app-web-acl-arn" +} + resource "aws_cloudfront_distribution" "site" { enabled = true is_ipv6_enabled = true @@ -14,6 +21,7 @@ resource "aws_cloudfront_distribution" "site" { price_class = "PriceClass_100" http_version = "http2and3" aliases = var.attach_apex_alias ? [var.domain_name] : [] + web_acl_id = data.aws_ssm_parameter.app_web_acl_arn.value origin { domain_name = aws_s3_bucket.origin.bucket_regional_domain_name diff --git a/terraform/outputs.tf b/terraform/outputs.tf index 4bd075d..f0d259e 100644 --- a/terraform/outputs.tf +++ b/terraform/outputs.tf @@ -13,6 +13,13 @@ output "cloudfront_domain_name" { value = aws_cloudfront_distribution.site.domain_name } +output "cloudfront_web_acl_id" { + description = "WAFv2 WebACL ARN associated with the distribution (SSM /seahaven/waf/app-web-acl-arn)" + # SSM String params are sensitive by default in the AWS provider; the WebACL ARN is not a secret. + value = nonsensitive(aws_cloudfront_distribution.site.web_acl_id) + sensitive = false +} + output "github_deploy_role_arn" { description = "OIDC role ARN for GitHub Actions content deploy" value = aws_iam_role.github_deploy.arn