The SPA is served over HTTPS by CloudFront but the backend
(console.seahavenind.com) is HTTP-only, so direct API calls would be blocked
as mixed content. Add a CloudFront /api/* behavior that proxies to the backend
over HTTP (browser <-> CloudFront is HTTPS; CloudFront <-> origin is HTTP) and
set VITE_API_URL=/api (same-origin).
Because distribution-level customErrorResponses are global and would rewrite
real /api 403/404s into the SPA shell, replace them with a viewer-request
CloudFront Function scoped to the S3 (default) behavior that rewrites
extensionless paths to /index.html. /api/* carries no function association.
Backend host is configurable via `-c apiOriginDomain=<host>` (default
console.seahavenind.com).
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Provision the frontend's AWS hosting as a CDK app local to this repo
(private S3 + OAC, CloudFront with SPA 403/404 -> index.html fallback) and a
GitHub OIDC deploy role scoped to the dev branch. Deploy on push to dev via
the org reusable cd-cdk.yaml: cdk deploy provisions infra, then
scripts/deploy-web.sh builds the SPA, syncs to S3 (immutable hashed assets,
no-cache index.html) and invalidates CloudFront.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>