Move the dev frontend to its custom domain now that the backend, DNS zones,
and ACM cert all live in the dev account (396287094661):
- CloudFront alias dev.seahaven.com with the *.seahaven.com ACM cert
- /api/* proxied over HTTPS to api.dev.seahaven.com (no CORS, no mixed content)
- Route 53 apex A/AAAA alias -> CloudFront in the delegated dev.seahaven.com zone
Env-specific values (domain, cert, zone, API host, protocol) are parameterized
and set in cdk.json context so the CI `cdk deploy` produces this with no flags;
staging/prod override the same keys per environment.
The SPA is served over HTTPS by CloudFront but the backend
(console.seahavenind.com) is HTTP-only, so direct API calls would be blocked
as mixed content. Add a CloudFront /api/* behavior that proxies to the backend
over HTTP (browser <-> CloudFront is HTTPS; CloudFront <-> origin is HTTP) and
set VITE_API_URL=/api (same-origin).
Because distribution-level customErrorResponses are global and would rewrite
real /api 403/404s into the SPA shell, replace them with a viewer-request
CloudFront Function scoped to the S3 (default) behavior that rewrites
extensionless paths to /index.html. /api/* carries no function association.
Backend host is configurable via `-c apiOriginDomain=<host>` (default
console.seahavenind.com).
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Provision the frontend's AWS hosting as a CDK app local to this repo
(private S3 + OAC, CloudFront with SPA 403/404 -> index.html fallback) and a
GitHub OIDC deploy role scoped to the dev branch. Deploy on push to dev via
the org reusable cd-cdk.yaml: cdk deploy provisions infra, then
scripts/deploy-web.sh builds the SPA, syncs to S3 (immutable hashed assets,
no-cache index.html) and invalidates CloudFront.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>