mirror of
https://github.com/Sea-Haven-Industries/payments-dashboard.git
synced 2026-10-06 11:12:05 +00:00
Add S3/DDB gateway endpoints and payroll-batch DLQ
Audit M-22: S3 and DynamoDB traffic from the VPC was billed through the NAT gateway; gateway endpoints are free and keep it on the AWS backbone. Audit L-15: payroll-batch messages were silently lost after max receives. Adds a 14-day DLQ with maxReceiveCount 3 and an ALARM-only notification to site-alerts so a caught failure is actually seen.
This commit is contained in:
parent
c8a55060a9
commit
b73e2065e8
1 changed files with 53 additions and 0 deletions
|
|
@ -110,6 +110,28 @@ Resources:
|
||||||
DestinationCidrBlock: 0.0.0.0/0
|
DestinationCidrBlock: 0.0.0.0/0
|
||||||
NatGatewayId: !Ref NatGateway
|
NatGatewayId: !Ref NatGateway
|
||||||
|
|
||||||
|
# Gateway endpoints (audit M-22): keep S3/DynamoDB traffic off the NAT
|
||||||
|
# gateway — free, and removes per-GB NAT data-processing charges.
|
||||||
|
S3GatewayEndpoint:
|
||||||
|
Type: AWS::EC2::VPCEndpoint
|
||||||
|
Properties:
|
||||||
|
VpcId: !Ref Vpc
|
||||||
|
ServiceName: !Sub com.amazonaws.${AWS::Region}.s3
|
||||||
|
VpcEndpointType: Gateway
|
||||||
|
RouteTableIds:
|
||||||
|
- !Ref PublicRouteTable
|
||||||
|
- !Ref PrivateRouteTable
|
||||||
|
|
||||||
|
DynamoDbGatewayEndpoint:
|
||||||
|
Type: AWS::EC2::VPCEndpoint
|
||||||
|
Properties:
|
||||||
|
VpcId: !Ref Vpc
|
||||||
|
ServiceName: !Sub com.amazonaws.${AWS::Region}.dynamodb
|
||||||
|
VpcEndpointType: Gateway
|
||||||
|
RouteTableIds:
|
||||||
|
- !Ref PublicRouteTable
|
||||||
|
- !Ref PrivateRouteTable
|
||||||
|
|
||||||
PrivateSubnetRouteTableAssociation:
|
PrivateSubnetRouteTableAssociation:
|
||||||
Type: AWS::EC2::SubnetRouteTableAssociation
|
Type: AWS::EC2::SubnetRouteTableAssociation
|
||||||
Properties:
|
Properties:
|
||||||
|
|
@ -196,6 +218,37 @@ Resources:
|
||||||
DelaySeconds: 600
|
DelaySeconds: 600
|
||||||
MessageRetentionPeriod: 86400
|
MessageRetentionPeriod: 86400
|
||||||
VisibilityTimeout: 60
|
VisibilityTimeout: 60
|
||||||
|
RedrivePolicy:
|
||||||
|
deadLetterTargetArn: !GetAtt PayrollBatchDLQ.Arn
|
||||||
|
maxReceiveCount: 3
|
||||||
|
|
||||||
|
# Audit L-15: payroll-batch messages were lost after max receives. 14-day
|
||||||
|
# retention so a failure on Friday survives the weekend.
|
||||||
|
PayrollBatchDLQ:
|
||||||
|
Type: AWS::SQS::Queue
|
||||||
|
Properties:
|
||||||
|
QueueName: payments-payroll-batch-dlq
|
||||||
|
MessageRetentionPeriod: 1209600
|
||||||
|
|
||||||
|
PayrollBatchDLQAlarm:
|
||||||
|
Type: AWS::CloudWatch::Alarm
|
||||||
|
Properties:
|
||||||
|
AlarmName: payments-payroll-batch-dlq-messages
|
||||||
|
AlarmDescription: Failed payroll-batch messages landed in the DLQ
|
||||||
|
Namespace: AWS/SQS
|
||||||
|
MetricName: ApproximateNumberOfMessagesVisible
|
||||||
|
Dimensions:
|
||||||
|
- Name: QueueName
|
||||||
|
Value: !GetAtt PayrollBatchDLQ.QueueName
|
||||||
|
Statistic: Maximum
|
||||||
|
Period: 300
|
||||||
|
EvaluationPeriods: 1
|
||||||
|
Threshold: 0
|
||||||
|
ComparisonOperator: GreaterThanThreshold
|
||||||
|
TreatMissingData: notBreaching
|
||||||
|
# ALARM-only notification by convention — no OK/recovery action
|
||||||
|
AlarmActions:
|
||||||
|
- !Sub arn:aws:sns:${AWS::Region}:${AWS::AccountId}:site-alerts
|
||||||
|
|
||||||
ProcessPayrollEmailLogGroup:
|
ProcessPayrollEmailLogGroup:
|
||||||
Type: AWS::Logs::LogGroup
|
Type: AWS::Logs::LogGroup
|
||||||
|
|
|
||||||
Loading…
Add table
Reference in a new issue