diff --git a/rest-api-dynamodb/README.md b/rest-api-dynamodb/README.md index e91f722..61efc32 100644 --- a/rest-api-dynamodb/README.md +++ b/rest-api-dynamodb/README.md @@ -1,15 +1,16 @@ # REST API + DynamoDB Independent AWS CDK Python example that builds a REST API backed by a real -DynamoDB table named `Orders`. The five functions are grouped by resource in -`lambdas/orders.py`, while shared runtime code is provided by the `orders` -AWS Lambda Layer. +DynamoDB table named `Orders`. It also creates an audit bucket whose read +permissions demonstrate role configuration. The five functions are grouped by +resource in `lambdas/orders.py`, while shared runtime code is provided by the +`orders` AWS Lambda Layer. ## Architecture The stack contains one API Gateway REST API, one on-demand DynamoDB table with -string partition key `id`, and five independent Lambda functions. Each -function declares exactly one route: +string partition key `id`, one S3 audit bucket, and five independent Lambda +functions. Each function declares exactly one route: | Method | Path | Access | | --- | --- | --- | @@ -46,7 +47,8 @@ published Layer directory is discovered and attached to each function. The POST function demonstrates named configuration with Python 3.12, 1024 MB, 15 seconds, `STAGE` and `TABLE_NAME`, the mutable `api-role`, and the function name `configured-handler`. Other functions use independent CDK-created roles -and the default Python 3.14 runtime. +and the default Python 3.14 runtime. `api-role` receives read access to the +audit bucket through `grant_read`; the handlers do not use that bucket. ## Prerequisites diff --git a/rest-api-dynamodb/rest_api_dynamodb/rest_api_dynamodb_stack.py b/rest-api-dynamodb/rest_api_dynamodb/rest_api_dynamodb_stack.py index 186bc7b..381a358 100644 --- a/rest-api-dynamodb/rest_api_dynamodb/rest_api_dynamodb_stack.py +++ b/rest-api-dynamodb/rest_api_dynamodb/rest_api_dynamodb_stack.py @@ -2,6 +2,7 @@ from aws_cdk import aws_dynamodb as dynamodb from aws_cdk import aws_iam as iam from aws_cdk import aws_lambda as lambda_ +from aws_cdk import aws_s3 as s3 from constructs import Construct from lambda_api_decorators_cdk import LambdaApi, LambdaApiConfig @@ -21,6 +22,12 @@ def __init__(self, scope: Construct, construct_id: str, **kwargs) -> None: removal_policy=RemovalPolicy.DESTROY, ) + audit_bucket = s3.Bucket( + self, + "OrdersAudit", + removal_policy=RemovalPolicy.DESTROY, + ) + api_role = iam.Role( self, "ApiRole", @@ -31,6 +38,7 @@ def __init__(self, scope: Construct, construct_id: str, **kwargs) -> None: ) ], ) + audit_bucket.grant_read(api_role) config = LambdaApiConfig( default_runtime="python3.14",