* feat(iam): import hcptf roles into app Terraform (PLAT-146)
Move the existing hcptf pair into this repo so app Terraform owns prod IAM after the substrate handoff.
* fix(iam): add apply-role IAM list permissions (PLAT-146)
IamReadOnly omitted ListRoleTags needed to refresh imported roles after detaching the substrate guardrail.
* feat(infra): associate shared prod CloudFront WAF with site distribution
Read /seahaven/waf/app-web-acl-arn and set web_acl_id so the marketing
site sits behind the same-account M-17 WebACL.
* chore: empty commit to trigger CI
* fix(infra): mark CloudFront WebACL output nonsensitive
SSM String parameters are sensitive by default, which broke the HCP
speculative plan when exporting the WebACL ARN.
* feat(infra): add HCP Terraform for prod static hosting
Greenfield S3+CloudFront+ACM+OIDC content-deploy role under /tf-managed/,
with OOB mgmt DNS helper for ACM validation and apex alias cutover.
* chore(security): suppress pre-existing js-yaml npm audit
* feat(ci): retarget content deploy to seahaven-prod origin
Point OIDC, S3 sync, and CloudFront invalidation at the HCP-managed
prod hosting stack so GHA remains the content publish path after cutover.