2026-08-07 19:19:51 -04:00
|
|
|
# Log groups are created explicitly rather than left to Lambda's implicit
|
|
|
|
|
# on-first-invoke creation, so retention is enforced from the start. Each name
|
|
|
|
|
# matches the runtime default (/aws/lambda/<function-name>), and every function
|
|
|
|
|
# depends on its group.
|
|
|
|
|
|
|
|
|
|
resource "aws_cloudwatch_log_group" "function" {
|
|
|
|
|
for_each = local.function_packages
|
|
|
|
|
|
|
|
|
|
name = "/aws/lambda/${local.project}-${replace(each.key, "_", "-")}"
|
2026-09-18 18:38:45 +00:00
|
|
|
retention_in_days = local.is_prod ? 60 : 14
|
2026-08-07 19:19:51 -04:00
|
|
|
}
|
|
|
|
|
|
|
|
|
|
# Longer than the Lambda groups on purpose, for request-level forensics.
|
|
|
|
|
resource "aws_cloudwatch_log_group" "api_access" {
|
|
|
|
|
name = "/aws/apigateway/${local.project}"
|
2026-09-18 18:38:45 +00:00
|
|
|
retention_in_days = local.is_prod ? 90 : 14
|
2026-08-07 19:19:51 -04:00
|
|
|
}
|