feat(infra): associate shared prod CloudFront WAF with site distribution

Read /seahaven/waf/app-web-acl-arn and set web_acl_id so the marketing
site sits behind the same-account M-17 WebACL.
This commit is contained in:
Adam Moussa 2026-08-07 16:16:04 -04:00
parent 7812ec102d
commit a34bc12198
No known key found for this signature in database
2 changed files with 13 additions and 0 deletions

View file

@ -6,6 +6,13 @@ resource "aws_cloudfront_origin_access_control" "site" {
signing_protocol = "sigv4"
}
# Shared CloudFront WAF (M-17) published by org-baseline stack seahaven-app-web-acl
# in this account (PLAT-92). aws_cloudfront_distribution.web_acl_id takes the
# WAFv2 ARN despite the attribute name.
data "aws_ssm_parameter" "app_web_acl_arn" {
name = "/seahaven/waf/app-web-acl-arn"
}
resource "aws_cloudfront_distribution" "site" {
enabled = true
is_ipv6_enabled = true
@ -14,6 +21,7 @@ resource "aws_cloudfront_distribution" "site" {
price_class = "PriceClass_100"
http_version = "http2and3"
aliases = var.attach_apex_alias ? [var.domain_name] : []
web_acl_id = data.aws_ssm_parameter.app_web_acl_arn.value
origin {
domain_name = aws_s3_bucket.origin.bucket_regional_domain_name

View file

@ -13,6 +13,11 @@ output "cloudfront_domain_name" {
value = aws_cloudfront_distribution.site.domain_name
}
output "cloudfront_web_acl_id" {
description = "WAFv2 WebACL ARN associated with the distribution (SSM /seahaven/waf/app-web-acl-arn)"
value = aws_cloudfront_distribution.site.web_acl_id
}
output "github_deploy_role_arn" {
description = "OIDC role ARN for GitHub Actions content deploy"
value = aws_iam_role.github_deploy.arn