import * as cdk from "aws-cdk-lib"; import * as ses from "aws-cdk-lib/aws-ses"; import { Construct } from "constructs"; /** * SES configuration set capturing bounce/complaint events (audit M-13). * * Gives reputation visibility beyond the suppression list by emitting bounce, * complaint, and reject events to CloudWatch metrics (dimensioned by config * set). Associating this set as the default on the live sending identities is a * follow-up CLI step (documented in the README) — creating it here does not * change current sending behaviour. */ export class SesMonitoring extends Construct { constructor(scope: Construct, id: string) { super(scope, id); const configSetName = "seahaven-email-events"; const configSet = new ses.CfnConfigurationSet(this, "ConfigSet", { name: configSetName, reputationOptions: { reputationMetricsEnabled: true }, }); const eventDest = new ses.CfnConfigurationSetEventDestination( this, "BounceComplaintDest", { configurationSetName: configSetName, eventDestination: { name: "bounce-complaint-cw", enabled: true, matchingEventTypes: ["bounce", "complaint", "reject"], cloudWatchDestination: { dimensionConfigurations: [ { defaultDimensionValue: "none", dimensionName: "ses:configuration-set", dimensionValueSource: "messageTag", }, ], }, }, } ); eventDest.node.addDependency(configSet); new cdk.CfnOutput(this, "SesConfigSetName", { value: configSetName }); } }