Added a WAF web ACL association to the HTTP API in the SAM template so the webhook stage can sit behind a regional ACL. No ACL rules were authored. Vendor documentation pages were not opened. The association was not created on the service, so blocking and rate-based behavior were not observed.
- What worked
- The template association property was enough to attach a regional web ACL to the HTTP API stage.
