From 057fc816b26daf38c2f880d8774fecb84d83ee2d Mon Sep 17 00:00:00 2001 From: Adam Moussa Date: Fri, 5 Jun 2026 17:31:14 -0400 Subject: [PATCH] INFRA-28: add HTTP API access logging and throttling (audit M-18) Add AccessLogSettings on the implicit HTTP API stage pointing at a new /aws/apigateway/afterhours-shift-manager log group with 90-day retention, plus DefaultRouteSettings throttling (100 rps / 50 burst). Mirrors the M-18 pattern landed on payments-dashboard. --- template.yaml | 14 ++++++++++++++ 1 file changed, 14 insertions(+) diff --git a/template.yaml b/template.yaml index 7d2354f..a6307b5 100644 --- a/template.yaml +++ b/template.yaml @@ -21,8 +21,22 @@ Globals: MemorySize: 1024 Architectures: - arm64 + # Access logging + default throttling on the implicit HTTP API (audit M-18). + HttpApi: + AccessLogSettings: + DestinationArn: !GetAtt ApiAccessLogGroup.Arn + Format: '{"requestId":"$context.requestId","ip":"$context.identity.sourceIp","requestTime":"$context.requestTime","method":"$context.httpMethod","routeKey":"$context.routeKey","status":"$context.status","protocol":"$context.protocol","responseLength":"$context.responseLength","integrationError":"$context.integrationErrorMessage"}' + DefaultRouteSettings: + ThrottlingBurstLimit: 50 + ThrottlingRateLimit: 100 Resources: + ApiAccessLogGroup: + Type: AWS::Logs::LogGroup + Properties: + LogGroupName: /aws/apigateway/afterhours-shift-manager + RetentionInDays: 90 + # --- Shared Lambda Layer --- SharedLayer: Type: AWS::Serverless::LayerVersion