mirror of
https://github.com/Sea-Haven-Industries/google-user-sync.git
synced 2026-05-18 20:20:17 +00:00
75 lines
2.7 KiB
JavaScript
75 lines
2.7 KiB
JavaScript
const { Stack, Duration, RemovalPolicy, CfnOutput } = require("aws-cdk-lib");
|
|
const lambda = require("aws-cdk-lib/aws-lambda");
|
|
const events = require("aws-cdk-lib/aws-events");
|
|
const targets = require("aws-cdk-lib/aws-events-targets");
|
|
const secretsmanager = require("aws-cdk-lib/aws-secretsmanager");
|
|
const logs = require("aws-cdk-lib/aws-logs");
|
|
const path = require("path");
|
|
|
|
class GoogleUserSyncStack extends Stack {
|
|
constructor(scope, id, props) {
|
|
super(scope, id, props);
|
|
|
|
// -----------------------------------------------------------------
|
|
// Reference existing secrets (created manually per PLAN.md Step 6)
|
|
// -----------------------------------------------------------------
|
|
const googleSecret = secretsmanager.Secret.fromSecretNameV2(
|
|
this,
|
|
"GoogleServiceAccountSecret",
|
|
"google-user-sync/google-service-account"
|
|
);
|
|
|
|
const frontSecret = secretsmanager.Secret.fromSecretNameV2(
|
|
this,
|
|
"FrontApiTokenSecret",
|
|
"google-user-sync/front-api-token"
|
|
);
|
|
|
|
// -----------------------------------------------------------------
|
|
// Lambda function
|
|
// -----------------------------------------------------------------
|
|
const syncFn = new lambda.Function(this, "GoogleUserSyncFn", {
|
|
functionName: "google-user-sync",
|
|
runtime: lambda.Runtime.NODEJS_22_X,
|
|
architecture: lambda.Architecture.ARM_64,
|
|
handler: "index.handler",
|
|
code: lambda.Code.fromAsset(path.join(__dirname, "..", "lambda")),
|
|
timeout: Duration.minutes(5),
|
|
memorySize: 256,
|
|
environment: {
|
|
GOOGLE_SECRET_ARN: googleSecret.secretArn,
|
|
FRONT_SECRET_ARN: frontSecret.secretArn,
|
|
GOOGLE_ADMIN_EMAIL: "adam@seahavenind.com",
|
|
GOOGLE_DOMAIN: "seahavenind.com",
|
|
GOOGLE_OUS: "/Office/Scheduling,/Office/Operations",
|
|
},
|
|
logRetention: logs.RetentionDays.TWO_MONTHS,
|
|
});
|
|
|
|
// Grant the Lambda read access to both secrets
|
|
googleSecret.grantRead(syncFn);
|
|
frontSecret.grantRead(syncFn);
|
|
|
|
// -----------------------------------------------------------------
|
|
// EventBridge scheduled rule — daily at 6:00 AM ET (11:00 UTC)
|
|
// -----------------------------------------------------------------
|
|
const rule = new events.Rule(this, "DailySyncRule", {
|
|
ruleName: "google-user-sync-daily",
|
|
schedule: events.Schedule.cron({
|
|
minute: "0",
|
|
hour: "11", // 11:00 UTC = 6:00 AM ET (EST+5) / 7:00 AM EDT
|
|
month: "*",
|
|
weekDay: "MON-FRI",
|
|
year: "*",
|
|
}),
|
|
});
|
|
|
|
rule.addTarget(new targets.LambdaFunction(syncFn));
|
|
|
|
new CfnOutput(this, "SyncFunctionArn", {
|
|
value: syncFn.functionArn,
|
|
});
|
|
}
|
|
}
|
|
|
|
module.exports = { GoogleUserSyncStack };
|