mirror of
https://github.com/Sea-Haven-Industries/payments-dashboard.git
synced 2026-10-05 11:52:05 +00:00
* refactor(iam): forget in-repo HCP exec roles Org-baseline owns the apply and plan roles, so this workspace can assume them without a bootstrap window. Prod state forgets the old addresses without destroying the live roles. * ci(terraform): pin the isolation check to v1.0.21 The pre-release pin cloned the private .github repo with the caller token and the Terraform job failed. v1.0.21 loads the checker from the workflow commit.
72 lines
2.7 KiB
HCL
72 lines
2.7 KiB
HCL
resource "aws_apigatewayv2_api" "http" {
|
|
name = local.project
|
|
protocol_type = "HTTP"
|
|
description = "payments-dashboard Slack App Home and expense bot API"
|
|
}
|
|
|
|
resource "aws_apigatewayv2_integration" "slack_app_home" {
|
|
api_id = aws_apigatewayv2_api.http.id
|
|
integration_type = "AWS_PROXY"
|
|
integration_method = "POST"
|
|
integration_uri = aws_lambda_function.this["slack_app_home"].invoke_arn
|
|
payload_format_version = "2.0"
|
|
timeout_milliseconds = 30000
|
|
}
|
|
|
|
resource "aws_apigatewayv2_integration" "expense_receiver" {
|
|
api_id = aws_apigatewayv2_api.http.id
|
|
integration_type = "AWS_PROXY"
|
|
integration_method = "POST"
|
|
integration_uri = aws_lambda_function.this["expense_receiver"].invoke_arn
|
|
payload_format_version = "2.0"
|
|
timeout_milliseconds = 5000
|
|
}
|
|
|
|
resource "aws_apigatewayv2_route" "slack_events" {
|
|
api_id = aws_apigatewayv2_api.http.id
|
|
route_key = "POST /slack/events"
|
|
target = "integrations/${aws_apigatewayv2_integration.slack_app_home.id}"
|
|
}
|
|
|
|
resource "aws_apigatewayv2_route" "expense_events" {
|
|
api_id = aws_apigatewayv2_api.http.id
|
|
route_key = "POST /slack/expense-events"
|
|
target = "integrations/${aws_apigatewayv2_integration.expense_receiver.id}"
|
|
}
|
|
|
|
resource "aws_apigatewayv2_stage" "default" {
|
|
api_id = aws_apigatewayv2_api.http.id
|
|
name = "$default"
|
|
auto_deploy = true
|
|
|
|
access_log_settings {
|
|
destination_arn = aws_cloudwatch_log_group.api_access.arn
|
|
format = "{\"requestId\":\"$context.requestId\",\"ip\":\"$context.identity.sourceIp\",\"requestTime\":\"$context.requestTime\",\"method\":\"$context.httpMethod\",\"routeKey\":\"$context.routeKey\",\"status\":\"$context.status\",\"protocol\":\"$context.protocol\",\"responseLength\":\"$context.responseLength\",\"integrationError\":\"$context.integrationErrorMessage\"}"
|
|
}
|
|
|
|
default_route_settings {
|
|
throttling_burst_limit = 50
|
|
throttling_rate_limit = 100
|
|
}
|
|
|
|
depends_on = [
|
|
aws_apigatewayv2_route.slack_events,
|
|
aws_apigatewayv2_route.expense_events,
|
|
]
|
|
}
|
|
|
|
resource "aws_lambda_permission" "api_slack_app_home" {
|
|
statement_id = "AllowApiGatewayInvokeSlackAppHome"
|
|
action = "lambda:InvokeFunction"
|
|
function_name = aws_lambda_function.this["slack_app_home"].function_name
|
|
principal = "apigateway.amazonaws.com"
|
|
source_arn = "${aws_apigatewayv2_api.http.execution_arn}/*/*"
|
|
}
|
|
|
|
resource "aws_lambda_permission" "api_expense_receiver" {
|
|
statement_id = "AllowApiGatewayInvokeExpenseReceiver"
|
|
action = "lambda:InvokeFunction"
|
|
function_name = aws_lambda_function.this["expense_receiver"].function_name
|
|
principal = "apigateway.amazonaws.com"
|
|
source_arn = "${aws_apigatewayv2_api.http.execution_arn}/*/*"
|
|
}
|