{ "name": "waf", "version": "1.0.0", "kind": "l1", "type": "aws:wafv2:webacl", "description": "WAFv2 Web ACL primitive for CloudFront (engine-agnostic stack type aws:wafv2:webacl; the Terraform adapter translates to aws_wafv2_web_acl). CloudFront-scoped WAF is always in us-east-1.", "inputs": { "name": { "type": "string", "description": "Name of the Web ACL.", "required": true }, "scope": { "type": "string", "description": "Scope of the Web ACL (default cloudfront for CloudFront associations).", "required": false, "default": "cloudfront" }, "default_action": { "type": "string", "description": "Default action (default allow).", "required": false, "default": "allow" }, "rules": { "type": "string", "description": "Optional custom rules as JSON (default: managed rules only).", "required": false }, "region": { "type": "string", "description": "AWS region (CloudFront-scoped WAF is always us-east-1; the adapter ignores this for cloudfront scope).", "required": true }, "enabled": { "type": "boolean", "default": true, "description": "Feature flag: enable/disable this module. Set to false to skip resource creation." } }, "outputs": { "web_acl_arn": { "type": "arn", "description": "The WAF Web ACL ARN." } }, "nfrs": { "encryption_enabled": { "type": "boolean", "description": "Enable KMS-encrypted CloudWatch log group for WAF logs.", "default": true }, "logging_enabled": { "type": "boolean", "description": "Enable WAF logging.", "default": true }, "deletion_protection": { "type": "boolean", "description": "Prevent resource destruction via Terraform lifecycle prevent_destroy", "default": true } }, "resources": [ { "type": "aws:wafv2:webacl", "description": "WAFv2 Web ACL with managed rules.", "inputs": [ "name", "scope", "default_action", "rules" ], "outputs": [ "web_acl_arn" ] } ] }