INFRA-29: API access logging + throttling (audit M-18) #46

Merged
amoussa1229 merged 1 commit from infra-29-api-access-logging into main 2026-06-05 21:47:44 +00:00
amoussa1229 commented 2026-06-05 21:36:59 +00:00 (Migrated from github.com)

Summary

  • Access logging on the seahaven-slack-webhook HTTP API to /aws/apigateway/seahaven-slack-webhook (90-day retention)
  • DefaultRouteSettings throttle: 100 rps / 50 burst (matches payments-dashboard; door-unlock's 2/5 is deliberately tight for phones and unsuitable for Slack event volume)
  • Implemented via CfnStage property overrides (L2 HttpApi lacks native props), same approach as door-unlock-api

Testing

  • tsc --noEmit clean; cdk synth verified log group + throttle values in the template

Jira: INFRA-29

## Summary - Access logging on the seahaven-slack-webhook HTTP API to /aws/apigateway/seahaven-slack-webhook (90-day retention) - DefaultRouteSettings throttle: 100 rps / 50 burst (matches payments-dashboard; door-unlock's 2/5 is deliberately tight for phones and unsuitable for Slack event volume) - Implemented via CfnStage property overrides (L2 HttpApi lacks native props), same approach as door-unlock-api ## Testing - tsc --noEmit clean; cdk synth verified log group + throttle values in the template Jira: INFRA-29
This repo is archived. You cannot comment on pull requests.
No description provided.