# AWS Infrastructure ## IaC Strategy - **SAM** is the default for new serverless stacks (Lambda + API Gateway + DynamoDB) - **CDK** only for complex infrastructure (ECS, VPCs, multi-service compositions) - Every deployed resource should be managed by CloudFormation - No manually-created Lambdas, roles, or other resources outside of IaC ## Lambda Defaults These apply to every Lambda in every project. Verify, don't assume. | Setting | Value | |---|---| | Runtime | Python 3.12 or Node 22.x | | Architecture | arm64 | | Log retention | 60 days (explicit in IaC template) | | Naming | kebab-case, matching the stack name prefix | Never rely on the CloudWatch default for log retention. Always set `RetentionInDays` explicitly in the template. ## CloudFormation Outputs Every stack should export: - Function ARNs - Any externally-consumable URLs (API Gateway endpoints, etc.) ## S3 - Every non-CloudFormation bucket must have `Purpose` and `ManagedBy` tags - Define lifecycle policies in the IaC template - Use Glacier Deep Archive for archival data ## README Every repo must have a README that accurately describes: - Project architecture - Lambdas and services - Data flow - Configuration requirements Update the README in the same commit where functionality changes. If a README is missing or outdated when you start working on a project, fix it as part of the current work.