apm-wo-analysis/terraform/apigateway.tf
Adam Moussa f13d2e3ff1
Some checks are pending
Deploy / Deploy to prod (push) Waiting to run
feat(infra): migrate pipeline and Grafana to HCP Terraform (PLAT-75) (#57)
* feat(infra): migrate pipeline and Grafana to HCP Terraform (PLAT-75)

Move apm-wo-analysis into seahaven-prod under workspace apm-wo-analysis-prod
with in-repo hcptf/githubdeploy IAM, stub Lambdas, and GitHub Actions zip CD.

* chore(iam): add Checkov skip comments for HCP IAM documents

Pre-push HIGH findings are the DLM snapshot describe, tagged EC2 creates,
exec boundary DescribeLogGroups star, and the drop-uploader user policy.
2026-09-16 20:33:24 +00:00

77 lines
2.6 KiB
HCL

resource "aws_apigatewayv2_api" "http" {
name = local.project
protocol_type = "HTTP"
description = "apm-wo-analysis Slack interactivity API"
}
resource "aws_apigatewayv2_integration" "interactions" {
api_id = aws_apigatewayv2_api.http.id
integration_type = "AWS_PROXY"
integration_method = "POST"
integration_uri = aws_lambda_function.this["slack_interactions"].invoke_arn
payload_format_version = "2.0"
timeout_milliseconds = 30000
}
resource "aws_apigatewayv2_route" "interactions" {
api_id = aws_apigatewayv2_api.http.id
route_key = "POST /slack/interactions"
target = "integrations/${aws_apigatewayv2_integration.interactions.id}"
}
resource "aws_apigatewayv2_stage" "default" {
api_id = aws_apigatewayv2_api.http.id
name = "$default"
auto_deploy = true
access_log_settings {
destination_arn = aws_cloudwatch_log_group.api_access.arn
format = "{\"requestId\":\"$context.requestId\",\"ip\":\"$context.identity.sourceIp\",\"requestTime\":\"$context.requestTime\",\"method\":\"$context.httpMethod\",\"routeKey\":\"$context.routeKey\",\"status\":\"$context.status\",\"protocol\":\"$context.protocol\",\"responseLength\":\"$context.responseLength\",\"integrationError\":\"$context.integrationErrorMessage\"}"
}
default_route_settings {
throttling_burst_limit = 20
throttling_rate_limit = 10
}
depends_on = [
aws_apigatewayv2_route.interactions,
aws_iam_role_policy_attachment.hcptf_apply_services,
]
}
resource "aws_lambda_permission" "api_interactions" {
statement_id = "AllowApiGatewayInvokeInteractions"
action = "lambda:InvokeFunction"
function_name = aws_lambda_function.this["slack_interactions"].function_name
principal = "apigateway.amazonaws.com"
source_arn = "${aws_apigatewayv2_api.http.execution_arn}/*/*"
}
data "aws_acm_certificate" "slack" {
count = var.attach_custom_domains ? 1 : 0
domain = var.slack_interactions_domain
statuses = ["ISSUED"]
most_recent = true
}
resource "aws_apigatewayv2_domain_name" "slack" {
count = var.attach_custom_domains ? 1 : 0
domain_name = var.slack_interactions_domain
domain_name_configuration {
certificate_arn = data.aws_acm_certificate.slack[0].arn
endpoint_type = "REGIONAL"
security_policy = "TLS_1_2"
}
}
resource "aws_apigatewayv2_api_mapping" "slack" {
count = var.attach_custom_domains ? 1 : 0
api_id = aws_apigatewayv2_api.http.id
domain_name = aws_apigatewayv2_domain_name.slack[0].id
stage = aws_apigatewayv2_stage.default.id
}