mirror of
https://github.com/Sea-Haven-Industries/procurement-ingest.git
synced 2026-09-30 09:33:15 +00:00
97 lines
2.4 KiB
HCL
97 lines
2.4 KiB
HCL
resource "aws_s3_bucket" "wo_emails" {
|
|
bucket = local.wo_email_bucket_name
|
|
|
|
lifecycle {
|
|
prevent_destroy = true
|
|
}
|
|
}
|
|
|
|
resource "aws_s3_bucket_public_access_block" "wo_emails" {
|
|
bucket = aws_s3_bucket.wo_emails.id
|
|
|
|
block_public_acls = true
|
|
block_public_policy = true
|
|
ignore_public_acls = true
|
|
restrict_public_buckets = true
|
|
}
|
|
|
|
resource "aws_s3_bucket_lifecycle_configuration" "wo_emails" {
|
|
bucket = aws_s3_bucket.wo_emails.id
|
|
|
|
rule {
|
|
id = "expire-90-days"
|
|
status = "Enabled"
|
|
|
|
filter {}
|
|
|
|
expiration {
|
|
days = 90
|
|
}
|
|
}
|
|
}
|
|
|
|
resource "aws_s3_bucket_policy" "wo_emails" {
|
|
bucket = aws_s3_bucket.wo_emails.id
|
|
policy = jsonencode({
|
|
Version = "2012-10-17"
|
|
Statement = [
|
|
{
|
|
Effect = "Allow"
|
|
Principal = { Service = "ses.amazonaws.com" }
|
|
Action = "s3:PutObject"
|
|
Resource = "${aws_s3_bucket.wo_emails.arn}/inbound/*"
|
|
Condition = {
|
|
StringEquals = {
|
|
"aws:SourceAccount" = local.account_id
|
|
"aws:SourceArn" = aws_ses_receipt_rule.wo_email.arn
|
|
}
|
|
}
|
|
}
|
|
]
|
|
})
|
|
}
|
|
|
|
resource "aws_s3_bucket_notification" "wo_emails" {
|
|
bucket = aws_s3_bucket.wo_emails.id
|
|
|
|
lambda_function {
|
|
id = "wo-email-processor-inbound"
|
|
lambda_function_arn = aws_lambda_function.wo_email_processor.arn
|
|
events = ["s3:ObjectCreated:*"]
|
|
filter_prefix = "inbound/"
|
|
}
|
|
|
|
depends_on = [aws_lambda_permission.wo_emails_invoke]
|
|
}
|
|
|
|
resource "aws_lambda_permission" "wo_emails_invoke" {
|
|
statement_id = "AllowS3InvokeWoEmailProcessor"
|
|
action = "lambda:InvokeFunction"
|
|
function_name = aws_lambda_function.wo_email_processor.function_name
|
|
principal = "s3.amazonaws.com"
|
|
source_arn = aws_s3_bucket.wo_emails.arn
|
|
}
|
|
|
|
resource "aws_sqs_queue" "wo_email_processor_dlq" {
|
|
name = local.wo_email_processor_dlq_name
|
|
message_retention_seconds = 1209600
|
|
sqs_managed_sse_enabled = true
|
|
}
|
|
|
|
resource "aws_sqs_queue_policy" "wo_email_processor_dlq" {
|
|
queue_url = aws_sqs_queue.wo_email_processor_dlq.id
|
|
policy = jsonencode({
|
|
Version = "2012-10-17"
|
|
Statement = [
|
|
{
|
|
Effect = "Deny"
|
|
Principal = { AWS = "*" }
|
|
Action = "sqs:*"
|
|
Resource = aws_sqs_queue.wo_email_processor_dlq.arn
|
|
Condition = {
|
|
Bool = { "aws:SecureTransport" = "false" }
|
|
}
|
|
}
|
|
]
|
|
})
|
|
}
|