mirror of
https://github.com/Sea-Haven-Industries/payments-dashboard.git
synced 2026-09-30 06:33:11 +00:00
Add S3/DDB gateway endpoints and payroll-batch DLQ (#37)
Some checks are pending
Deploy / deploy (push) Waiting to run
Some checks are pending
Deploy / deploy (push) Waiting to run
Audit M-22: S3 and DynamoDB traffic from the VPC was billed through the NAT gateway; gateway endpoints are free and keep it on the AWS backbone. Audit L-15: payroll-batch messages were silently lost after max receives. Adds a 14-day DLQ with maxReceiveCount 3 and an ALARM-only notification to site-alerts so a caught failure is actually seen.
This commit is contained in:
parent
c8a55060a9
commit
a7aa626455
1 changed files with 53 additions and 0 deletions
|
|
@ -110,6 +110,28 @@ Resources:
|
|||
DestinationCidrBlock: 0.0.0.0/0
|
||||
NatGatewayId: !Ref NatGateway
|
||||
|
||||
# Gateway endpoints (audit M-22): keep S3/DynamoDB traffic off the NAT
|
||||
# gateway — free, and removes per-GB NAT data-processing charges.
|
||||
S3GatewayEndpoint:
|
||||
Type: AWS::EC2::VPCEndpoint
|
||||
Properties:
|
||||
VpcId: !Ref Vpc
|
||||
ServiceName: !Sub com.amazonaws.${AWS::Region}.s3
|
||||
VpcEndpointType: Gateway
|
||||
RouteTableIds:
|
||||
- !Ref PublicRouteTable
|
||||
- !Ref PrivateRouteTable
|
||||
|
||||
DynamoDbGatewayEndpoint:
|
||||
Type: AWS::EC2::VPCEndpoint
|
||||
Properties:
|
||||
VpcId: !Ref Vpc
|
||||
ServiceName: !Sub com.amazonaws.${AWS::Region}.dynamodb
|
||||
VpcEndpointType: Gateway
|
||||
RouteTableIds:
|
||||
- !Ref PublicRouteTable
|
||||
- !Ref PrivateRouteTable
|
||||
|
||||
PrivateSubnetRouteTableAssociation:
|
||||
Type: AWS::EC2::SubnetRouteTableAssociation
|
||||
Properties:
|
||||
|
|
@ -196,6 +218,37 @@ Resources:
|
|||
DelaySeconds: 600
|
||||
MessageRetentionPeriod: 86400
|
||||
VisibilityTimeout: 60
|
||||
RedrivePolicy:
|
||||
deadLetterTargetArn: !GetAtt PayrollBatchDLQ.Arn
|
||||
maxReceiveCount: 3
|
||||
|
||||
# Audit L-15: payroll-batch messages were lost after max receives. 14-day
|
||||
# retention so a failure on Friday survives the weekend.
|
||||
PayrollBatchDLQ:
|
||||
Type: AWS::SQS::Queue
|
||||
Properties:
|
||||
QueueName: payments-payroll-batch-dlq
|
||||
MessageRetentionPeriod: 1209600
|
||||
|
||||
PayrollBatchDLQAlarm:
|
||||
Type: AWS::CloudWatch::Alarm
|
||||
Properties:
|
||||
AlarmName: payments-payroll-batch-dlq-messages
|
||||
AlarmDescription: Failed payroll-batch messages landed in the DLQ
|
||||
Namespace: AWS/SQS
|
||||
MetricName: ApproximateNumberOfMessagesVisible
|
||||
Dimensions:
|
||||
- Name: QueueName
|
||||
Value: !GetAtt PayrollBatchDLQ.QueueName
|
||||
Statistic: Maximum
|
||||
Period: 300
|
||||
EvaluationPeriods: 1
|
||||
Threshold: 0
|
||||
ComparisonOperator: GreaterThanThreshold
|
||||
TreatMissingData: notBreaching
|
||||
# ALARM-only notification by convention — no OK/recovery action
|
||||
AlarmActions:
|
||||
- !Sub arn:aws:sns:${AWS::Region}:${AWS::AccountId}:site-alerts
|
||||
|
||||
ProcessPayrollEmailLogGroup:
|
||||
Type: AWS::Logs::LogGroup
|
||||
|
|
|
|||
Loading…
Add table
Reference in a new issue