output "origin_bucket_name" { description = "S3 origin bucket name for content sync" value = aws_s3_bucket.origin.bucket } output "cloudfront_distribution_id" { description = "CloudFront distribution ID for invalidations" value = aws_cloudfront_distribution.site.id } output "cloudfront_domain_name" { description = "CloudFront distribution domain (*.cloudfront.net)" value = aws_cloudfront_distribution.site.domain_name } output "cloudfront_web_acl_id" { description = "WAFv2 WebACL ARN associated with the distribution (SSM /seahaven/waf/app-web-acl-arn)" # SSM String params are sensitive by default in the AWS provider; the WebACL ARN is not a secret. value = nonsensitive(aws_cloudfront_distribution.site.web_acl_id) sensitive = false } output "github_deploy_role_arn" { description = "OIDC role ARN for GitHub Actions content deploy" value = aws_iam_role.github_deploy.arn } output "acm_certificate_arn" { description = "ACM certificate ARN (us-east-1) for the apex domain" value = aws_acm_certificate.site.arn } output "acm_validation_records" { description = "DNS validation CNAMEs to upsert in the mgmt seahaven.com zone" value = [ for dvo in aws_acm_certificate.site.domain_validation_options : { name = dvo.resource_record_name type = dvo.resource_record_type value = dvo.resource_record_value } ] }