From 85b5f0878a45a68b58c0e4a5ca4a1f247876be5d Mon Sep 17 00:00:00 2001 From: Adam Moussa Date: Fri, 7 Aug 2026 17:15:54 -0400 Subject: [PATCH] fix(infra): mark CloudFront WebACL output nonsensitive SSM String parameters are sensitive by default, which broke the HCP speculative plan when exporting the WebACL ARN. --- terraform/outputs.tf | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) diff --git a/terraform/outputs.tf b/terraform/outputs.tf index 0668e69..f0d259e 100644 --- a/terraform/outputs.tf +++ b/terraform/outputs.tf @@ -15,7 +15,9 @@ output "cloudfront_domain_name" { output "cloudfront_web_acl_id" { description = "WAFv2 WebACL ARN associated with the distribution (SSM /seahaven/waf/app-web-acl-arn)" - value = aws_cloudfront_distribution.site.web_acl_id + # SSM String params are sensitive by default in the AWS provider; the WebACL ARN is not a secret. + value = nonsensitive(aws_cloudfront_distribution.site.web_acl_id) + sensitive = false } output "github_deploy_role_arn" {