From 46cd49766c22b146f514f0c109dfafab26000d30 Mon Sep 17 00:00:00 2001 From: Adam Moussa <166072409+amoussa1229@users.noreply.github.com> Date: Tue, 2 Jun 2026 17:36:59 -0400 Subject: [PATCH] Add API access logging + throttling (audit Day 3: M-18) (#32) Implicit HTTP API: access logging to /aws/apigateway/payments-dashboard (90d) + default route throttling (100 rps / 50 burst) via Globals.HttpApi. --- template.yaml | 14 ++++++++++++++ 1 file changed, 14 insertions(+) diff --git a/template.yaml b/template.yaml index 6b95031..a6acb1a 100644 --- a/template.yaml +++ b/template.yaml @@ -12,8 +12,22 @@ Globals: Environment: Variables: TABLE_NAME: !Ref DashboardTable + # Access logging + default throttling on the implicit HTTP API (audit M-18). + HttpApi: + AccessLogSettings: + DestinationArn: !GetAtt ApiAccessLogGroup.Arn + Format: '{"requestId":"$context.requestId","ip":"$context.identity.sourceIp","requestTime":"$context.requestTime","method":"$context.httpMethod","routeKey":"$context.routeKey","status":"$context.status","protocol":"$context.protocol","responseLength":"$context.responseLength","integrationError":"$context.integrationErrorMessage"}' + DefaultRouteSettings: + ThrottlingBurstLimit: 50 + ThrottlingRateLimit: 100 Resources: + ApiAccessLogGroup: + Type: AWS::Logs::LogGroup + Properties: + LogGroupName: /aws/apigateway/payments-dashboard + RetentionInDays: 90 + # VPC with private subnet + NAT Gateway for static outbound IP Vpc: Type: AWS::EC2::VPC