Add API access logging (audit Day 3: M-18) (#23)

Access logging to /aws/apigateway/door-unlock-api (90d) on the HTTP API default
stage. Throttling (5 burst / 2 rps) was already present.
This commit is contained in:
Adam Moussa 2026-06-02 17:42:13 -04:00 • committed by GitHub
parent 1aef1ca16c
commit b0b2444799

View file

@ -184,6 +184,27 @@ export class DoorUnlockStack extends cdk.Stack {
ThrottlingRateLimit: 2,
});
// Access logging (audit M-18). Throttling above was already present.
const apiAccessLogGroup = new logs.LogGroup(this, "ApiAccessLogGroup", {
logGroupName: "/aws/apigateway/door-unlock-api",
retention: logs.RetentionDays.THREE_MONTHS,
removalPolicy: cdk.RemovalPolicy.DESTROY,
});
defaultStage.addPropertyOverride("AccessLogSettings", {
DestinationArn: apiAccessLogGroup.logGroupArn,
Format: JSON.stringify({
requestId: "$context.requestId",
ip: "$context.identity.sourceIp",
requestTime: "$context.requestTime",
method: "$context.httpMethod",
routeKey: "$context.routeKey",
status: "$context.status",
protocol: "$context.protocol",
responseLength: "$context.responseLength",
integrationError: "$context.integrationErrorMessage",
}),
});
httpApi.addRoutes({
path: "/unlock",
methods: [apigwv2.HttpMethod.GET],