Add API access logging + throttling (audit Day 3: M-18) (#32)
Some checks are pending
Deploy / deploy (push) Waiting to run

Implicit HTTP API: access logging to /aws/apigateway/payments-dashboard (90d) +
default route throttling (100 rps / 50 burst) via Globals.HttpApi.
This commit is contained in:
Adam Moussa 2026-06-02 17:36:59 -04:00 • committed by GitHub
parent a2a7e3f533
commit 46cd49766c
No known key found for this signature in database
GPG key ID: B5690EEEBB952194

View file

@ -12,8 +12,22 @@ Globals:
Environment:
Variables:
TABLE_NAME: !Ref DashboardTable
# Access logging + default throttling on the implicit HTTP API (audit M-18).
HttpApi:
AccessLogSettings:
DestinationArn: !GetAtt ApiAccessLogGroup.Arn
Format: '{"requestId":"$context.requestId","ip":"$context.identity.sourceIp","requestTime":"$context.requestTime","method":"$context.httpMethod","routeKey":"$context.routeKey","status":"$context.status","protocol":"$context.protocol","responseLength":"$context.responseLength","integrationError":"$context.integrationErrorMessage"}'
DefaultRouteSettings:
ThrottlingBurstLimit: 50
ThrottlingRateLimit: 100
Resources:
ApiAccessLogGroup:
Type: AWS::Logs::LogGroup
Properties:
LogGroupName: /aws/apigateway/payments-dashboard
RetentionInDays: 90
# VPC with private subnet + NAT Gateway for static outbound IP
Vpc:
Type: AWS::EC2::VPC