Fix Lambda compliance and rename SQS queue

- Switch runtime to nodejs22.x and architecture to arm64
- Add explicit CloudWatch log groups with 60-day retention for all Lambdas
- Rename SQS queue from payments-contractor-batch to payments-payroll-batch
  (now handles both employee and contractor batching)
- Remove stale comment
This commit is contained in:
Adam Moussa 2026-04-30 14:15:05 -04:00
parent fe7c9cebca
commit 5bebd954bd
2 changed files with 35 additions and 10 deletions

View file

@ -18,7 +18,7 @@ const ssm = new SSMClient();
const TABLE_NAME = process.env.TABLE_NAME; const TABLE_NAME = process.env.TABLE_NAME;
const CHANNEL_ID = process.env.PAYROLL_CHANNEL_ID; const CHANNEL_ID = process.env.PAYROLL_CHANNEL_ID;
const QUEUE_URL = process.env.CONTRACTOR_BATCH_QUEUE_URL; const QUEUE_URL = process.env.PAYROLL_BATCH_QUEUE_URL;
let cachedToken; let cachedToken;
async function getSlackToken() { async function getSlackToken() {

View file

@ -4,7 +4,9 @@ Description: Payments Dashboard - S3 CSV ingestion to Slack App Home
Globals: Globals:
Function: Function:
Runtime: nodejs20.x Runtime: nodejs22.x
Architectures:
- arm64
Timeout: 30 Timeout: 30
MemorySize: 256 MemorySize: 256
Environment: Environment:
@ -129,7 +131,6 @@ Resources:
AttributeName: ttl AttributeName: ttl
Enabled: true Enabled: true
# Payroll email ingestion (replaces Dataddo/Aurora pipeline)
PayrollEmailBucket: PayrollEmailBucket:
Type: AWS::S3::Bucket Type: AWS::S3::Bucket
Properties: Properties:
@ -174,14 +175,38 @@ Resources:
BucketName: !Ref PayrollEmailBucket BucketName: !Ref PayrollEmailBucket
ObjectKeyPrefix: inbound/ ObjectKeyPrefix: inbound/
ContractorBatchQueue: PayrollBatchQueue:
Type: AWS::SQS::Queue Type: AWS::SQS::Queue
Properties: Properties:
QueueName: payments-contractor-batch QueueName: payments-payroll-batch
DelaySeconds: 600 DelaySeconds: 600
MessageRetentionPeriod: 86400 MessageRetentionPeriod: 86400
VisibilityTimeout: 60 VisibilityTimeout: 60
ProcessPayrollEmailLogGroup:
Type: AWS::Logs::LogGroup
Properties:
LogGroupName: /aws/lambda/payments-processPayrollEmail
RetentionInDays: 60
ProcessPaymentCsvLogGroup:
Type: AWS::Logs::LogGroup
Properties:
LogGroupName: /aws/lambda/payments-processPaymentCsv
RetentionInDays: 60
SlackAppHomeLogGroup:
Type: AWS::Logs::LogGroup
Properties:
LogGroupName: /aws/lambda/payments-slackAppHome
RetentionInDays: 60
FetchBoaTransactionsLogGroup:
Type: AWS::Logs::LogGroup
Properties:
LogGroupName: /aws/lambda/payments-fetchBoaTransactions
RetentionInDays: 60
ProcessPayrollEmailFunction: ProcessPayrollEmailFunction:
Type: AWS::Serverless::Function Type: AWS::Serverless::Function
Properties: Properties:
@ -192,7 +217,7 @@ Resources:
Variables: Variables:
SLACK_BOT_TOKEN_PARAM: /payments-dashboard/slack-bot-token SLACK_BOT_TOKEN_PARAM: /payments-dashboard/slack-bot-token
PAYROLL_CHANNEL_ID: C0AV5RBMYKU PAYROLL_CHANNEL_ID: C0AV5RBMYKU
CONTRACTOR_BATCH_QUEUE_URL: !Ref ContractorBatchQueue PAYROLL_BATCH_QUEUE_URL: !Ref PayrollBatchQueue
Events: Events:
EmailReceived: EmailReceived:
Type: S3 Type: S3
@ -204,10 +229,10 @@ Resources:
Rules: Rules:
- Name: prefix - Name: prefix
Value: inbound/ Value: inbound/
ContractorBatch: PayrollBatch:
Type: SQS Type: SQS
Properties: Properties:
Queue: !GetAtt ContractorBatchQueue.Arn Queue: !GetAtt PayrollBatchQueue.Arn
BatchSize: 1 BatchSize: 1
Policies: Policies:
- S3ReadPolicy: - S3ReadPolicy:
@ -217,9 +242,9 @@ Resources:
- SSMParameterReadPolicy: - SSMParameterReadPolicy:
ParameterName: payments-dashboard/slack-bot-token ParameterName: payments-dashboard/slack-bot-token
- SQSSendMessagePolicy: - SQSSendMessagePolicy:
QueueName: !GetAtt ContractorBatchQueue.QueueName QueueName: !GetAtt PayrollBatchQueue.QueueName
- SQSPollerPolicy: - SQSPollerPolicy:
QueueName: !GetAtt ContractorBatchQueue.QueueName QueueName: !GetAtt PayrollBatchQueue.QueueName
ProcessPaymentCsvFunction: ProcessPaymentCsvFunction:
Type: AWS::Serverless::Function Type: AWS::Serverless::Function