INFRA-28: add HTTP API access logging and throttling (audit M-18) (#98)
Some checks failed
Deploy / deploy (push) Has been cancelled

Add AccessLogSettings on the implicit HTTP API stage pointing at a new
/aws/apigateway/afterhours-shift-manager log group with 90-day retention,
plus DefaultRouteSettings throttling (100 rps / 50 burst). Mirrors the
M-18 pattern landed on payments-dashboard.
This commit is contained in:
Adam Moussa 2026-06-05 17:47:41 -04:00 • committed by GitHub
parent 9bea3ed4c7
commit efa4bc569d
No known key found for this signature in database
GPG key ID: B5690EEEBB952194

View file

@ -21,8 +21,22 @@ Globals:
MemorySize: 1024
Architectures:
- arm64
# Access logging + default throttling on the implicit HTTP API (audit M-18).
HttpApi:
AccessLogSettings:
DestinationArn: !GetAtt ApiAccessLogGroup.Arn
Format: '{"requestId":"$context.requestId","ip":"$context.identity.sourceIp","requestTime":"$context.requestTime","method":"$context.httpMethod","routeKey":"$context.routeKey","status":"$context.status","protocol":"$context.protocol","responseLength":"$context.responseLength","integrationError":"$context.integrationErrorMessage"}'
DefaultRouteSettings:
ThrottlingBurstLimit: 50
ThrottlingRateLimit: 100
Resources:
ApiAccessLogGroup:
Type: AWS::Logs::LogGroup
Properties:
LogGroupName: /aws/apigateway/afterhours-shift-manager
RetentionInDays: 90
# --- Shared Lambda Layer ---
SharedLayer:
Type: AWS::Serverless::LayerVersion