diff --git a/infra/cdk/lib/frontend-stack.ts b/infra/cdk/lib/frontend-stack.ts index bce19e98..88ccb6d9 100644 --- a/infra/cdk/lib/frontend-stack.ts +++ b/infra/cdk/lib/frontend-stack.ts @@ -369,9 +369,25 @@ export class FrontendStack extends Stack { node.cfnResourceType === "AWS::IAM::Role" && node.node.path.endsWith("/Custom::S3AutoDeleteObjectsCustomResourceProvider/Role"), ); - if (!rolePolicy || !autoDeleteProviderRole) { + const autoDeleteProviderHandler = this.node + .findAll() + .find( + (node): node is CfnResource => + node instanceof CfnResource && + node.cfnResourceType === "AWS::Lambda::Function" && + node.node.path.endsWith("/Custom::S3AutoDeleteObjectsCustomResourceProvider/Handler"), + ); + if (!rolePolicy || !autoDeleteProviderRole || !autoDeleteProviderHandler) { throw new Error("Terraform adoption outputs require deploy and auto-delete roles."); } + // The provider Lambda stays unconditioned so it remains after + // ManageSiteInfrastructure=false. Its generated Description Refs the + // conditioned bucket and CloudFormation rejects that when the condition + // is false. Keep a static description. + autoDeleteProviderHandler.addPropertyOverride( + "Description", + "Lambda function for auto-deleting objects in the site S3 bucket.", + ); const recordName = domainNames[0]; gateOutput( diff --git a/infra/cdk/test/frontend-stack.test.mjs b/infra/cdk/test/frontend-stack.test.mjs index f285557d..8bcd607c 100644 --- a/infra/cdk/test/frontend-stack.test.mjs +++ b/infra/cdk/test/frontend-stack.test.mjs @@ -189,6 +189,13 @@ test("adoption mode requires ManageSiteInfrastructure and gates transferred reso for (const [outputName, output] of Object.entries(template.Outputs)) { assert.equal(output.Condition, CONDITION, outputName); } + + const [, autoDeleteHandler] = entriesByType(template, "AWS::Lambda::Function")[0]; + assert.equal( + autoDeleteHandler.Properties.Description, + "Lambda function for auto-deleting objects in the site S3 bucket.", + ); + assert.equal(typeof autoDeleteHandler.Properties.Description, "string"); }); test("normal mode is unchanged: destructive cleanup, StringLike trust, no boundary, tag, or parameter", () => {