Setting the file. One moment.
Subchapter 16.6
examples/conversion/cloudfront-associated-with-waf/README.mdMarkdown871 BView on GitHub
cloudfront-associated-with-waf.sentinel
Not convertible as an exact translation
The included tfpolicy approximation checks only that web_acl_id is set to a non-empty value on aws_cloudfront_distribution resources.
The Sentinel policy uses tfconfig/v2 plus reference metadata (references) to reason about whether the CloudFront distribution is associated with a WAF resource. Current tfpolicy guidance does not expose equivalent reference metadata, so it cannot distinguish:
This means tfpolicy can enforce presence of a web_acl_id, but it cannot safely reproduce the Sentinel policy’s reference-aware behavior.