INFRA-29: API access logging + throttling (audit M-18) #46

Merged
amoussa1229 merged 1 commit from infra-29-api-access-logging into main 2026-06-05 21:47:44 +00:00

View file

@ -138,6 +138,33 @@ export class SlackHandlerConstruct extends Construct {
});
}
// ── Access logging + throttling (audit M-18) ──────────────────────────────
const defaultStage = this.api.defaultStage!.node.defaultChild as apigatewayv2.CfnStage;
defaultStage.addPropertyOverride('DefaultRouteSettings', {
ThrottlingBurstLimit: 50,
ThrottlingRateLimit: 100,
});
const apiAccessLogGroup = new logs.LogGroup(this, 'ApiAccessLogGroup', {
logGroupName: '/aws/apigateway/seahaven-slack-webhook',
retention: logs.RetentionDays.THREE_MONTHS,
removalPolicy: cdk.RemovalPolicy.DESTROY,
});
defaultStage.addPropertyOverride('AccessLogSettings', {
DestinationArn: apiAccessLogGroup.logGroupArn,
Format: JSON.stringify({
requestId: '$context.requestId',
ip: '$context.identity.sourceIp',
requestTime: '$context.requestTime',
method: '$context.httpMethod',
routeKey: '$context.routeKey',
status: '$context.status',
protocol: '$context.protocol',
responseLength: '$context.responseLength',
integrationError: '$context.integrationErrorMessage',
}),
});
// ── Custom domain: bot.seahaven.com ───────────────────────────────────────
const certificate = acm.Certificate.fromCertificateArn(
this, 'WildcardCert', props.wildcardCertArn,