* fix(terraform): ignore origin response_completion_timeout in the release plan guard (SH-300)
AWS returns 0 when the timeout is unset. The provider writes null on
origin_path updates, so the first real CD plan failed closed.
* fix(ci): drop duplicate verify from the content CD workflow (SH-300)
Frontend checks already runs verify on PRs and pushes. Removing the
validate job also requires dropping needs: validate so dispatch can run.
* fix(terraform): equate origin timeout 0 and null only (SH-300)
Numeric timeout changes still fail closed. Rename the filter so it is
not read as an after_unknown allowlist.
* feat(terraform): ship dev content CD through Terraform (SH-300)
GitHub uploads immutable release prefixes; Terraform owns live publish.
Push-to-dev stays off until TERRAFORM_CONTENT_CD_ENABLED is set.
* fix(terraform): align release-plan guard flags and CloudFront verify IAM (SH-300)
Remove the push-to-dev trigger and the org cd-cdk.yaml caller so CI no
longer runs cdk deploy during the adoption. The workflow assumes the
pinned dev role and runs the simple scripts/deploy-web.sh against a
pinned bucket and distribution, which keeps content deploys working
after CloudFormation relinquishes the stack outputs. Staging is
untouched.
Self-contained CDK app (S3 + CloudFront + OIDC deploy role) deployed via the org reusable cd-cdk.yaml. Frontend served on dev.seahaven.com with the *.seahaven.com cert and a Route 53 apex alias; the SPA calls the dev backend directly at https://api.dev.seahaven.com/api.