From a1f62a0d2e2c7d1e744cbe774006ea2e4eebc3fd Mon Sep 17 00:00:00 2001 From: Adam Moussa <166072409+amoussa1229@users.noreply.github.com> Date: Tue, 2 Jun 2026 17:35:19 -0400 Subject: [PATCH] Add API access logging + throttling (audit Day 3: M-18) Implicit HTTP API: access logging to /aws/apigateway/payments-dashboard (90d) + default route throttling (100 rps / 50 burst) via Globals.HttpApi. --- template.yaml | 14 ++++++++++++++ 1 file changed, 14 insertions(+) diff --git a/template.yaml b/template.yaml index 6b95031..a6acb1a 100644 --- a/template.yaml +++ b/template.yaml @@ -12,8 +12,22 @@ Globals: Environment: Variables: TABLE_NAME: !Ref DashboardTable + # Access logging + default throttling on the implicit HTTP API (audit M-18). + HttpApi: + AccessLogSettings: + DestinationArn: !GetAtt ApiAccessLogGroup.Arn + Format: '{"requestId":"$context.requestId","ip":"$context.identity.sourceIp","requestTime":"$context.requestTime","method":"$context.httpMethod","routeKey":"$context.routeKey","status":"$context.status","protocol":"$context.protocol","responseLength":"$context.responseLength","integrationError":"$context.integrationErrorMessage"}' + DefaultRouteSettings: + ThrottlingBurstLimit: 50 + ThrottlingRateLimit: 100 Resources: + ApiAccessLogGroup: + Type: AWS::Logs::LogGroup + Properties: + LogGroupName: /aws/apigateway/payments-dashboard + RetentionInDays: 90 + # VPC with private subnet + NAT Gateway for static outbound IP Vpc: Type: AWS::EC2::VPC