diff --git a/template.yaml b/template.yaml index 6b95031..72d93a8 100644 --- a/template.yaml +++ b/template.yaml @@ -12,8 +12,22 @@ Globals: Environment: Variables: TABLE_NAME: !Ref DashboardTable + # Access logging + default throttling on the implicit HTTP API (audit M-18). + HttpApi: + AccessLogSettings: + DestinationArn: !GetAtt ApiAccessLogGroup.Arn + Format: '{"requestId":"$context.requestId","ip":"$context.identity.sourceIp","requestTime":"$context.requestTime","method":"$context.httpMethod","routeKey":"$context.routeKey","status":"$context.status","protocol":"$context.protocol","responseLength":"$context.responseLength","integrationError":"$context.integrationErrorMessage"}' + DefaultRouteSettings: + ThrottlingBurstLimit: 50 + ThrottlingRateLimit: 100 Resources: + ApiAccessLogGroup: + Type: AWS::Logs::LogGroup + Properties: + LogGroupName: /aws/apigateway/payments-dashboard + RetentionInDays: 90 + # VPC with private subnet + NAT Gateway for static outbound IP Vpc: Type: AWS::EC2::VPC @@ -272,6 +286,7 @@ Resources: BOA_CHECK_MGMT_SECRET_PARAM: /payments-dashboard/boa-check-mgmt-token BOA_ACCOUNT_NUMBER_PARAM: /payments-dashboard/boa-account-number BOA_COMPANY_ID_PARAM: /payments-dashboard/boa-company-id + SLACK_APP_HOME_FUNCTION: !Ref SlackAppHomeFunction VpcConfig: SubnetIds: - !Ref PrivateSubnet @@ -311,6 +326,11 @@ Resources: - ec2:DescribeNetworkInterfaces - ec2:DeleteNetworkInterface Resource: "*" + - Version: "2012-10-17" + Statement: + - Effect: Allow + Action: lambda:InvokeFunction + Resource: !GetAtt SlackAppHomeFunction.Arn SlackAppHomeFunction: Type: AWS::Serverless::Function @@ -332,7 +352,7 @@ Resources: Path: /slack/events Method: POST Policies: - - DynamoDBReadPolicy: + - DynamoDBCrudPolicy: TableName: !Ref DashboardTable - SSMParameterReadPolicy: ParameterName: payments-dashboard/slack-bot-token