seahaven-site/terraform/outputs.tf
Adam Moussa 37c6f80eba
Some checks failed
Deploy / deploy (push) Has been cancelled
feat(infra): associate shared prod CloudFront WAF (PLAT-92) (#38)
* feat(infra): associate shared prod CloudFront WAF with site distribution

Read /seahaven/waf/app-web-acl-arn and set web_acl_id so the marketing
site sits behind the same-account M-17 WebACL.

* chore: empty commit to trigger CI

* fix(infra): mark CloudFront WebACL output nonsensitive

SSM String parameters are sensitive by default, which broke the HCP
speculative plan when exporting the WebACL ARN.
2026-08-07 17:21:46 -04:00

42 lines
1.4 KiB
HCL

output "origin_bucket_name" {
description = "S3 origin bucket name for content sync"
value = aws_s3_bucket.origin.bucket
}
output "cloudfront_distribution_id" {
description = "CloudFront distribution ID for invalidations"
value = aws_cloudfront_distribution.site.id
}
output "cloudfront_domain_name" {
description = "CloudFront distribution domain (*.cloudfront.net)"
value = aws_cloudfront_distribution.site.domain_name
}
output "cloudfront_web_acl_id" {
description = "WAFv2 WebACL ARN associated with the distribution (SSM /seahaven/waf/app-web-acl-arn)"
# SSM String params are sensitive by default in the AWS provider; the WebACL ARN is not a secret.
value = nonsensitive(aws_cloudfront_distribution.site.web_acl_id)
sensitive = false
}
output "github_deploy_role_arn" {
description = "OIDC role ARN for GitHub Actions content deploy"
value = aws_iam_role.github_deploy.arn
}
output "acm_certificate_arn" {
description = "ACM certificate ARN (us-east-1) for the apex domain"
value = aws_acm_certificate.site.arn
}
output "acm_validation_records" {
description = "DNS validation CNAMEs to upsert in the mgmt seahaven.com zone"
value = [
for dvo in aws_acm_certificate.site.domain_validation_options : {
name = dvo.resource_record_name
type = dvo.resource_record_type
value = dvo.resource_record_value
}
]
}