feat(api): add access logging and throttling to webhook HTTP API (#46)

Adds an access log group (/aws/apigateway/seahaven-slack-webhook, 90-day
retention) with JSON access-log format and DefaultRouteSettings throttling
(rate 2 rps, burst 5) on the seahaven-slack-webhook HTTP API default stage,
applied via CfnStage property overrides. Matches the pattern landed on
seahaven-door-unlock-api.

Refs INFRA-29 (AWS audit M-18)
This commit is contained in:
Adam Moussa 2026-06-05 17:47:44 -04:00 • committed by GitHub
parent cacda7c57b
commit de55c0eeca
No known key found for this signature in database
GPG key ID: B5690EEEBB952194

View file

@ -138,6 +138,33 @@ export class SlackHandlerConstruct extends Construct {
});
}
// ── Access logging + throttling (audit M-18) ──────────────────────────────
const defaultStage = this.api.defaultStage!.node.defaultChild as apigatewayv2.CfnStage;
defaultStage.addPropertyOverride('DefaultRouteSettings', {
ThrottlingBurstLimit: 50,
ThrottlingRateLimit: 100,
});
const apiAccessLogGroup = new logs.LogGroup(this, 'ApiAccessLogGroup', {
logGroupName: '/aws/apigateway/seahaven-slack-webhook',
retention: logs.RetentionDays.THREE_MONTHS,
removalPolicy: cdk.RemovalPolicy.DESTROY,
});
defaultStage.addPropertyOverride('AccessLogSettings', {
DestinationArn: apiAccessLogGroup.logGroupArn,
Format: JSON.stringify({
requestId: '$context.requestId',
ip: '$context.identity.sourceIp',
requestTime: '$context.requestTime',
method: '$context.httpMethod',
routeKey: '$context.routeKey',
status: '$context.status',
protocol: '$context.protocol',
responseLength: '$context.responseLength',
integrationError: '$context.integrationErrorMessage',
}),
});
// ── Custom domain: bot.seahaven.com ───────────────────────────────────────
const certificate = acm.Certificate.fromCertificateArn(
this, 'WildcardCert', props.wildcardCertArn,