-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathlambda.tf
More file actions
90 lines (75 loc) · 3.03 KB
/
lambda.tf
File metadata and controls
90 lines (75 loc) · 3.03 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
# lambda.tf: Terraform configuration file
# Purpose: Defines AWS infrastructure components for the Coffee Tracker project
data "archive_file" "lambda_zip" {
type = "zip"
source_dir = "${path.module}/lambda"
output_path = "${path.module}/lambda.zip"
}
resource "aws_lambda_function" "track_coffee" {
function_name = var.lambda_names.track_coffee
role = aws_iam_role.lambda_exec.arn
handler = "track_coffee.lambda_handler"
runtime = "python3.13"
filename = data.archive_file.lambda_zip.output_path
source_code_hash = data.archive_file.lambda_zip.output_base64sha256
environment {
variables = {
LOG_LEVEL = var.log_level
TABLE_NAME = aws_dynamodb_table.coffee_tracker.name
TOPIC_ARN = aws_sns_topic.coffee_topic.arn
}
}
depends_on = [data.archive_file.lambda_zip, aws_cloudwatch_log_group.lambda_logs]
}
resource "aws_lambda_function" "notify_teams" {
function_name = var.lambda_names.notify_teams
role = aws_iam_role.lambda_exec.arn
handler = "notify_teams.lambda_handler"
runtime = "python3.13"
filename = data.archive_file.lambda_zip.output_path
source_code_hash = data.archive_file.lambda_zip.output_base64sha256
environment {
variables = {
LOG_LEVEL = var.log_level
TEAMS_WEBHOOK_URL = var.teams_webhook_url
TEAMS_DEDUPE_TABLE = aws_dynamodb_table.teams_dedupe.name
}
}
depends_on = [data.archive_file.lambda_zip, aws_cloudwatch_log_group.lambda_logs]
}
resource "aws_lambda_function" "get_user_entries" {
function_name = var.lambda_names.get_user_entries
role = aws_iam_role.lambda_exec.arn
handler = "get_user_entries.lambda_handler"
runtime = "python3.13"
filename = data.archive_file.lambda_zip.output_path
source_code_hash = data.archive_file.lambda_zip.output_base64sha256
environment {
variables = {
LOG_LEVEL = var.log_level
TABLE_NAME = aws_dynamodb_table.coffee_tracker.name
}
}
depends_on = [data.archive_file.lambda_zip, aws_cloudwatch_log_group.lambda_logs]
}
resource "aws_lambda_permission" "allow_sns" {
statement_id = "AllowExecutionFromSNS"
action = "lambda:InvokeFunction"
function_name = aws_lambda_function.notify_teams.function_name
principal = "sns.amazonaws.com"
source_arn = aws_sns_topic.coffee_topic.arn
}
resource "aws_lambda_permission" "api_gateway" {
statement_id = "AllowAPIGatewayInvoke"
action = "lambda:InvokeFunction"
function_name = aws_lambda_function.track_coffee.function_name
principal = "apigateway.amazonaws.com"
source_arn = "${aws_api_gateway_rest_api.coffee_api.execution_arn}/*/*"
}
resource "aws_lambda_permission" "apigw_get_user_entries" {
statement_id = "AllowExecutionFromAPIGatewayGetUser"
action = "lambda:InvokeFunction"
function_name = aws_lambda_function.get_user_entries.function_name
principal = "apigateway.amazonaws.com"
source_arn = "${aws_api_gateway_rest_api.coffee_api.execution_arn}/*/*"
}