Add API access logging + throttling (audit Day 3: M-18)

Implicit HTTP API: access logging to /aws/apigateway/payments-dashboard (90d) +
default route throttling (100 rps / 50 burst) via Globals.HttpApi.
This commit is contained in:
Adam Moussa 2026-06-02 17:22:13 -04:00
parent 12bfd7b20a
commit a6c0948d37

View file

@ -12,8 +12,22 @@ Globals:
Environment:
Variables:
TABLE_NAME: !Ref DashboardTable
# Access logging + default throttling on the implicit HTTP API (audit M-18).
HttpApi:
AccessLogSettings:
DestinationArn: !GetAtt ApiAccessLogGroup.Arn
Format: '{"requestId":"$context.requestId","ip":"$context.identity.sourceIp","requestTime":"$context.requestTime","method":"$context.httpMethod","routeKey":"$context.routeKey","status":"$context.status","protocol":"$context.protocol","responseLength":"$context.responseLength","integrationError":"$context.integrationErrorMessage"}'
DefaultRouteSettings:
ThrottlingBurstLimit: 50
ThrottlingRateLimit: 100
Resources:
ApiAccessLogGroup:
Type: AWS::Logs::LogGroup
Properties:
LogGroupName: /aws/apigateway/payments-dashboard
RetentionInDays: 90
# VPC with private subnet + NAT Gateway for static outbound IP
Vpc:
Type: AWS::EC2::VPC
@ -272,6 +286,7 @@ Resources:
BOA_CHECK_MGMT_SECRET_PARAM: /payments-dashboard/boa-check-mgmt-token
BOA_ACCOUNT_NUMBER_PARAM: /payments-dashboard/boa-account-number
BOA_COMPANY_ID_PARAM: /payments-dashboard/boa-company-id
SLACK_APP_HOME_FUNCTION: !Ref SlackAppHomeFunction
VpcConfig:
SubnetIds:
- !Ref PrivateSubnet
@ -311,6 +326,11 @@ Resources:
- ec2:DescribeNetworkInterfaces
- ec2:DeleteNetworkInterface
Resource: "*"
- Version: "2012-10-17"
Statement:
- Effect: Allow
Action: lambda:InvokeFunction
Resource: !GetAtt SlackAppHomeFunction.Arn
SlackAppHomeFunction:
Type: AWS::Serverless::Function
@ -332,7 +352,7 @@ Resources:
Path: /slack/events
Method: POST
Policies:
- DynamoDBReadPolicy:
- DynamoDBCrudPolicy:
TableName: !Ref DashboardTable
- SSMParameterReadPolicy:
ParameterName: payments-dashboard/slack-bot-token