Add S3/DDB gateway endpoints and payroll-batch DLQ (#37)
Some checks are pending
Deploy / deploy (push) Waiting to run

Audit M-22: S3 and DynamoDB traffic from the VPC was billed through
the NAT gateway; gateway endpoints are free and keep it on the AWS
backbone.

Audit L-15: payroll-batch messages were silently lost after max
receives. Adds a 14-day DLQ with maxReceiveCount 3 and an ALARM-only
notification to site-alerts so a caught failure is actually seen.
This commit is contained in:
Adam Moussa 2026-06-03 15:32:17 -04:00 • committed by GitHub
parent c8a55060a9
commit a7aa626455
No known key found for this signature in database
GPG key ID: B5690EEEBB952194

View file

@ -110,6 +110,28 @@ Resources:
DestinationCidrBlock: 0.0.0.0/0
NatGatewayId: !Ref NatGateway
# Gateway endpoints (audit M-22): keep S3/DynamoDB traffic off the NAT
# gateway — free, and removes per-GB NAT data-processing charges.
S3GatewayEndpoint:
Type: AWS::EC2::VPCEndpoint
Properties:
VpcId: !Ref Vpc
ServiceName: !Sub com.amazonaws.${AWS::Region}.s3
VpcEndpointType: Gateway
RouteTableIds:
- !Ref PublicRouteTable
- !Ref PrivateRouteTable
DynamoDbGatewayEndpoint:
Type: AWS::EC2::VPCEndpoint
Properties:
VpcId: !Ref Vpc
ServiceName: !Sub com.amazonaws.${AWS::Region}.dynamodb
VpcEndpointType: Gateway
RouteTableIds:
- !Ref PublicRouteTable
- !Ref PrivateRouteTable
PrivateSubnetRouteTableAssociation:
Type: AWS::EC2::SubnetRouteTableAssociation
Properties:
@ -196,6 +218,37 @@ Resources:
DelaySeconds: 600
MessageRetentionPeriod: 86400
VisibilityTimeout: 60
RedrivePolicy:
deadLetterTargetArn: !GetAtt PayrollBatchDLQ.Arn
maxReceiveCount: 3
# Audit L-15: payroll-batch messages were lost after max receives. 14-day
# retention so a failure on Friday survives the weekend.
PayrollBatchDLQ:
Type: AWS::SQS::Queue
Properties:
QueueName: payments-payroll-batch-dlq
MessageRetentionPeriod: 1209600
PayrollBatchDLQAlarm:
Type: AWS::CloudWatch::Alarm
Properties:
AlarmName: payments-payroll-batch-dlq-messages
AlarmDescription: Failed payroll-batch messages landed in the DLQ
Namespace: AWS/SQS
MetricName: ApproximateNumberOfMessagesVisible
Dimensions:
- Name: QueueName
Value: !GetAtt PayrollBatchDLQ.QueueName
Statistic: Maximum
Period: 300
EvaluationPeriods: 1
Threshold: 0
ComparisonOperator: GreaterThanThreshold
TreatMissingData: notBreaching
# ALARM-only notification by convention — no OK/recovery action
AlarmActions:
- !Sub arn:aws:sns:${AWS::Region}:${AWS::AccountId}:site-alerts
ProcessPayrollEmailLogGroup:
Type: AWS::Logs::LogGroup