mirror of
https://github.com/Sea-Haven-Industries/seahaven-site.git
synced 2026-09-30 05:23:18 +00:00
feat(infra): associate shared prod CloudFront WAF (PLAT-92) (#38)
Some checks failed
Deploy / deploy (push) Has been cancelled
Some checks failed
Deploy / deploy (push) Has been cancelled
* feat(infra): associate shared prod CloudFront WAF with site distribution Read /seahaven/waf/app-web-acl-arn and set web_acl_id so the marketing site sits behind the same-account M-17 WebACL. * chore: empty commit to trigger CI * fix(infra): mark CloudFront WebACL output nonsensitive SSM String parameters are sensitive by default, which broke the HCP speculative plan when exporting the WebACL ARN.
This commit is contained in:
parent
7812ec102d
commit
37c6f80eba
2 changed files with 15 additions and 0 deletions
|
|
@ -6,6 +6,13 @@ resource "aws_cloudfront_origin_access_control" "site" {
|
|||
signing_protocol = "sigv4"
|
||||
}
|
||||
|
||||
# Shared CloudFront WAF (M-17) published by org-baseline stack seahaven-app-web-acl
|
||||
# in this account (PLAT-92). aws_cloudfront_distribution.web_acl_id takes the
|
||||
# WAFv2 ARN despite the attribute name.
|
||||
data "aws_ssm_parameter" "app_web_acl_arn" {
|
||||
name = "/seahaven/waf/app-web-acl-arn"
|
||||
}
|
||||
|
||||
resource "aws_cloudfront_distribution" "site" {
|
||||
enabled = true
|
||||
is_ipv6_enabled = true
|
||||
|
|
@ -14,6 +21,7 @@ resource "aws_cloudfront_distribution" "site" {
|
|||
price_class = "PriceClass_100"
|
||||
http_version = "http2and3"
|
||||
aliases = var.attach_apex_alias ? [var.domain_name] : []
|
||||
web_acl_id = data.aws_ssm_parameter.app_web_acl_arn.value
|
||||
|
||||
origin {
|
||||
domain_name = aws_s3_bucket.origin.bucket_regional_domain_name
|
||||
|
|
|
|||
|
|
@ -13,6 +13,13 @@ output "cloudfront_domain_name" {
|
|||
value = aws_cloudfront_distribution.site.domain_name
|
||||
}
|
||||
|
||||
output "cloudfront_web_acl_id" {
|
||||
description = "WAFv2 WebACL ARN associated with the distribution (SSM /seahaven/waf/app-web-acl-arn)"
|
||||
# SSM String params are sensitive by default in the AWS provider; the WebACL ARN is not a secret.
|
||||
value = nonsensitive(aws_cloudfront_distribution.site.web_acl_id)
|
||||
sensitive = false
|
||||
}
|
||||
|
||||
output "github_deploy_role_arn" {
|
||||
description = "OIDC role ARN for GitHub Actions content deploy"
|
||||
value = aws_iam_role.github_deploy.arn
|
||||
|
|
|
|||
Loading…
Add table
Reference in a new issue