Add arm64, log retention, and compliance fixes

- Set arm64 architecture globally for all Lambda functions
- Add explicit CloudWatch log groups with 60-day retention
- Add missing WeeklyPostFunctionArn to stack outputs
- Add Dependabot assignees for both ecosystems
- Add samconfig.toml.example for onboarding
This commit is contained in:
Adam Moussa 2026-05-12 15:36:22 -04:00
parent f26fe978b5
commit 3de9243f6b
3 changed files with 36 additions and 0 deletions

View file

@ -4,6 +4,8 @@ updates:
directory: "/"
schedule:
interval: "weekly"
assignees:
- "amoussa1229"
groups:
minor-and-patch:
update-types:
@ -13,6 +15,8 @@ updates:
directory: "/"
schedule:
interval: "weekly"
assignees:
- "amoussa1229"
groups:
minor-and-patch:
update-types:

9
samconfig.toml.example Normal file
View file

@ -0,0 +1,9 @@
version = 0.1
[default.deploy.parameters]
stack_name = "afterhours-shift-manager"
resolve_s3 = true
s3_prefix = "afterhours-shift-manager"
region = "us-east-1"
capabilities = "CAPABILITY_IAM"
confirm_changeset = true

View file

@ -16,6 +16,8 @@ Globals:
Runtime: python3.12
Timeout: 30
MemorySize: 1024
Architectures:
- arm64
Resources:
# --- DynamoDB ---
@ -181,6 +183,25 @@ Resources:
Description: "Sync roster from 3CX at 6am EDT"
Enabled: true
# --- CloudWatch Log Groups (explicit 60-day retention) ---
SlackBotLogGroup:
Type: AWS::Logs::LogGroup
Properties:
LogGroupName: !Sub "/aws/lambda/${SlackBotFunction}"
RetentionInDays: 60
WeeklyPostLogGroup:
Type: AWS::Logs::LogGroup
Properties:
LogGroupName: !Sub "/aws/lambda/${WeeklyPostFunction}"
RetentionInDays: 60
RosterSyncLogGroup:
Type: AWS::Logs::LogGroup
Properties:
LogGroupName: !Sub "/aws/lambda/${RosterSyncFunction}"
RetentionInDays: 60
Outputs:
SlackBotApiUrl:
Description: URL for Slack app Request URL configuration
@ -189,5 +210,7 @@ Outputs:
Value: !Ref ShiftTable
SlackBotFunctionArn:
Value: !GetAtt SlackBotFunction.Arn
WeeklyPostFunctionArn:
Value: !GetAtt WeeklyPostFunction.Arn
RosterSyncFunctionArn:
Value: !GetAtt RosterSyncFunction.Arn