Fix Lambda compliance and rename SQS queue

- Switch runtime to nodejs22.x and architecture to arm64
- Add explicit CloudWatch log groups with 60-day retention for all Lambdas
- Rename SQS queue from payments-contractor-batch to payments-payroll-batch
  (now handles both employee and contractor batching)
- Remove stale comment
This commit is contained in:
Adam Moussa 2026-04-30 14:15:05 -04:00
parent fe7c9cebca
commit 5bebd954bd
2 changed files with 35 additions and 10 deletions

View file

@ -18,7 +18,7 @@ const ssm = new SSMClient();
const TABLE_NAME = process.env.TABLE_NAME;
const CHANNEL_ID = process.env.PAYROLL_CHANNEL_ID;
const QUEUE_URL = process.env.CONTRACTOR_BATCH_QUEUE_URL;
const QUEUE_URL = process.env.PAYROLL_BATCH_QUEUE_URL;
let cachedToken;
async function getSlackToken() {

View file

@ -4,7 +4,9 @@ Description: Payments Dashboard - S3 CSV ingestion to Slack App Home
Globals:
Function:
Runtime: nodejs20.x
Runtime: nodejs22.x
Architectures:
- arm64
Timeout: 30
MemorySize: 256
Environment:
@ -129,7 +131,6 @@ Resources:
AttributeName: ttl
Enabled: true
# Payroll email ingestion (replaces Dataddo/Aurora pipeline)
PayrollEmailBucket:
Type: AWS::S3::Bucket
Properties:
@ -174,14 +175,38 @@ Resources:
BucketName: !Ref PayrollEmailBucket
ObjectKeyPrefix: inbound/
ContractorBatchQueue:
PayrollBatchQueue:
Type: AWS::SQS::Queue
Properties:
QueueName: payments-contractor-batch
QueueName: payments-payroll-batch
DelaySeconds: 600
MessageRetentionPeriod: 86400
VisibilityTimeout: 60
ProcessPayrollEmailLogGroup:
Type: AWS::Logs::LogGroup
Properties:
LogGroupName: /aws/lambda/payments-processPayrollEmail
RetentionInDays: 60
ProcessPaymentCsvLogGroup:
Type: AWS::Logs::LogGroup
Properties:
LogGroupName: /aws/lambda/payments-processPaymentCsv
RetentionInDays: 60
SlackAppHomeLogGroup:
Type: AWS::Logs::LogGroup
Properties:
LogGroupName: /aws/lambda/payments-slackAppHome
RetentionInDays: 60
FetchBoaTransactionsLogGroup:
Type: AWS::Logs::LogGroup
Properties:
LogGroupName: /aws/lambda/payments-fetchBoaTransactions
RetentionInDays: 60
ProcessPayrollEmailFunction:
Type: AWS::Serverless::Function
Properties:
@ -192,7 +217,7 @@ Resources:
Variables:
SLACK_BOT_TOKEN_PARAM: /payments-dashboard/slack-bot-token
PAYROLL_CHANNEL_ID: C0AV5RBMYKU
CONTRACTOR_BATCH_QUEUE_URL: !Ref ContractorBatchQueue
PAYROLL_BATCH_QUEUE_URL: !Ref PayrollBatchQueue
Events:
EmailReceived:
Type: S3
@ -204,10 +229,10 @@ Resources:
Rules:
- Name: prefix
Value: inbound/
ContractorBatch:
PayrollBatch:
Type: SQS
Properties:
Queue: !GetAtt ContractorBatchQueue.Arn
Queue: !GetAtt PayrollBatchQueue.Arn
BatchSize: 1
Policies:
- S3ReadPolicy:
@ -217,9 +242,9 @@ Resources:
- SSMParameterReadPolicy:
ParameterName: payments-dashboard/slack-bot-token
- SQSSendMessagePolicy:
QueueName: !GetAtt ContractorBatchQueue.QueueName
QueueName: !GetAtt PayrollBatchQueue.QueueName
- SQSPollerPolicy:
QueueName: !GetAtt ContractorBatchQueue.QueueName
QueueName: !GetAtt PayrollBatchQueue.QueueName
ProcessPaymentCsvFunction:
Type: AWS::Serverless::Function