# Log groups are created explicitly rather than left to Lambda's implicit # on-first-invoke creation, so retention is enforced from the start. Each name # matches the runtime default (/aws/lambda/), and every function # depends on its group. resource "aws_cloudwatch_log_group" "function" { for_each = local.function_packages name = "/aws/lambda/${local.project}-${replace(each.key, "_", "-")}" retention_in_days = 60 } # Longer than the Lambda groups on purpose, for request-level forensics. resource "aws_cloudwatch_log_group" "api_access" { name = "/aws/apigateway/${local.project}" retention_in_days = 90 }