diff --git a/template.yaml b/template.yaml index 965f2ab..42404cd 100644 --- a/template.yaml +++ b/template.yaml @@ -82,6 +82,23 @@ Resources: SubnetId: !Ref PublicSubnet RouteTableId: !Ref PublicRouteTable + PublicSubnetB: + Type: AWS::EC2::Subnet + Properties: + VpcId: !Ref Vpc + CidrBlock: 10.20.3.0/24 + AvailabilityZone: !Select [1, !GetAZs ""] + MapPublicIpOnLaunch: true + Tags: + - Key: Name + Value: payments-dashboard-public-b + + PublicSubnetBRouteTableAssociation: + Type: AWS::EC2::SubnetRouteTableAssociation + Properties: + SubnetId: !Ref PublicSubnetB + RouteTableId: !Ref PublicRouteTable + PrivateRouteTable: Type: AWS::EC2::RouteTable Properties: @@ -109,6 +126,55 @@ Resources: - IpProtocol: "-1" CidrIp: 0.0.0.0/0 + # Aurora Serverless v2 PostgreSQL (Dataddo → payroll data) + AuroraSecurityGroup: + Type: AWS::EC2::SecurityGroup + Properties: + GroupDescription: Aurora PostgreSQL access + VpcId: !Ref Vpc + SecurityGroupIngress: + - IpProtocol: tcp + FromPort: 5432 + ToPort: 5432 + SourceSecurityGroupId: !Ref LambdaSecurityGroup + - IpProtocol: tcp + FromPort: 5432 + ToPort: 5432 + CidrIp: 0.0.0.0/0 + + AuroraSubnetGroup: + Type: AWS::RDS::DBSubnetGroup + Properties: + DBSubnetGroupDescription: Public subnets for Aurora PostgreSQL + SubnetIds: + - !Ref PublicSubnet + - !Ref PublicSubnetB + + AuroraCluster: + Type: AWS::RDS::DBCluster + Properties: + Engine: aurora-postgresql + EngineVersion: "16.4" + DatabaseName: payroll + MasterUsername: payroll_admin + ManageMasterUserPassword: true + ServerlessV2ScalingConfiguration: + MinCapacity: 0.5 + MaxCapacity: 2 + VpcSecurityGroupIds: + - !Ref AuroraSecurityGroup + DBSubnetGroupName: !Ref AuroraSubnetGroup + EnableHttpEndpoint: true + StorageEncrypted: true + + AuroraInstance: + Type: AWS::RDS::DBInstance + Properties: + DBClusterIdentifier: !Ref AuroraCluster + DBInstanceClass: db.serverless + Engine: aurora-postgresql + PubliclyAccessible: true + PaymentsCsvBucket: Type: AWS::S3::Bucket Properties: @@ -274,3 +340,12 @@ Outputs: StaticOutboundIp: Description: Static IP for BoA API whitelist Value: !Ref NatEip + AuroraEndpoint: + Description: Aurora PostgreSQL cluster endpoint + Value: !GetAtt AuroraCluster.Endpoint.Address + AuroraPort: + Description: Aurora PostgreSQL port + Value: !GetAtt AuroraCluster.Endpoint.Port + AuroraSecretArn: + Description: Secrets Manager ARN for Aurora master credentials + Value: !GetAtt AuroraCluster.MasterUserSecret.SecretArn