* feat(ci): deploy the marketing site through the org static caller (PLAT-225)
Prod still ships on merge to main. Exec roles leave this workspace, and the deploy reads the bucket and distribution from SSM.
* fix(ci): run the static check after the legacy ci job
Both jobs call ci-static, which cancels the other in-progress run on the same ref, so ci-complete never saw both succeed.
* fix(ci): address review feedback
* fix(ci): address review feedback
* fix(ci): address review feedback
* fix(ci): address review feedback
* fix(careers): return 301s for retired job URLs
Send the old careers paths to the Paychex portal from the viewer-request function so clients get a permanent redirect instead of the HTML stub.
* fix(careers): match retired job redirects case-insensitively
CloudFront does not normalize URI case, so a mixed-case old job link skipped the 301 and missed the lowercase S3 stub.
* feat(iam): import hcptf roles into app Terraform (PLAT-146)
Move the existing hcptf pair into this repo so app Terraform owns prod IAM after the substrate handoff.
* fix(iam): add apply-role IAM list permissions (PLAT-146)
IamReadOnly omitted ListRoleTags needed to refresh imported roles after detaching the substrate guardrail.
* feat(infra): associate shared prod CloudFront WAF with site distribution
Read /seahaven/waf/app-web-acl-arn and set web_acl_id so the marketing
site sits behind the same-account M-17 WebACL.
* chore: empty commit to trigger CI
* fix(infra): mark CloudFront WebACL output nonsensitive
SSM String parameters are sensitive by default, which broke the HCP
speculative plan when exporting the WebACL ARN.
* feat(infra): add HCP Terraform for prod static hosting
Greenfield S3+CloudFront+ACM+OIDC content-deploy role under /tf-managed/,
with OOB mgmt DNS helper for ACM validation and apex alias cutover.
* chore(security): suppress pre-existing js-yaml npm audit
* feat(ci): retarget content deploy to seahaven-prod origin
Point OIDC, S3 sync, and CloudFront invalidation at the HCP-managed
prod hosting stack so GHA remains the content publish path after cutover.