fix(infra): mark CloudFront WebACL output nonsensitive

SSM String parameters are sensitive by default, which broke the HCP
speculative plan when exporting the WebACL ARN.
This commit is contained in:
Adam Moussa 2026-08-07 17:15:54 -04:00
parent 4cc36221a6
commit 85b5f0878a
No known key found for this signature in database

View file

@ -15,7 +15,9 @@ output "cloudfront_domain_name" {
output "cloudfront_web_acl_id" {
description = "WAFv2 WebACL ARN associated with the distribution (SSM /seahaven/waf/app-web-acl-arn)"
value = aws_cloudfront_distribution.site.web_acl_id
# SSM String params are sensitive by default in the AWS provider; the WebACL ARN is not a secret.
value = nonsensitive(aws_cloudfront_distribution.site.web_acl_id)
sensitive = false
}
output "github_deploy_role_arn" {