fix(cdk): keep the auto-delete Lambda description off the site bucket (SH-300) (#179)
Some checks are pending
Frontend checks / Build and test (push) Waiting to run
Frontend checks / governance (push) Waiting to run
Frontend checks / Visual regression (push) Waiting to run

* fix(cdk): keep the auto-delete Lambda description off the site bucket

* style(cdk): format the auto-delete Lambda path check
This commit is contained in:
Adam Moussa 2026-09-11 12:21:00 -04:00 • committed by GitHub
parent 5b08bfa57b
commit b24e6f3b9a
No known key found for this signature in database
GPG key ID: B5690EEEBB952194
2 changed files with 24 additions and 1 deletions

View file

@ -369,9 +369,25 @@ export class FrontendStack extends Stack {
node.cfnResourceType === "AWS::IAM::Role" &&
node.node.path.endsWith("/Custom::S3AutoDeleteObjectsCustomResourceProvider/Role"),
);
if (!rolePolicy || !autoDeleteProviderRole) {
const autoDeleteProviderHandler = this.node
.findAll()
.find(
(node): node is CfnResource =>
node instanceof CfnResource &&
node.cfnResourceType === "AWS::Lambda::Function" &&
node.node.path.endsWith("/Custom::S3AutoDeleteObjectsCustomResourceProvider/Handler"),
);
if (!rolePolicy || !autoDeleteProviderRole || !autoDeleteProviderHandler) {
throw new Error("Terraform adoption outputs require deploy and auto-delete roles.");
}
// The provider Lambda stays unconditioned so it remains after
// ManageSiteInfrastructure=false. Its generated Description Refs the
// conditioned bucket and CloudFormation rejects that when the condition
// is false. Keep a static description.
autoDeleteProviderHandler.addPropertyOverride(
"Description",
"Lambda function for auto-deleting objects in the site S3 bucket.",
);
const recordName = domainNames[0];
gateOutput(

View file

@ -189,6 +189,13 @@ test("adoption mode requires ManageSiteInfrastructure and gates transferred reso
for (const [outputName, output] of Object.entries(template.Outputs)) {
assert.equal(output.Condition, CONDITION, outputName);
}
const [, autoDeleteHandler] = entriesByType(template, "AWS::Lambda::Function")[0];
assert.equal(
autoDeleteHandler.Properties.Description,
"Lambda function for auto-deleting objects in the site S3 bucket.",
);
assert.equal(typeof autoDeleteHandler.Properties.Description, "string");
});
test("normal mode is unchanged: destructive cleanup, StringLike trust, no boundary, tag, or parameter", () => {