Skip to content

Commit 0fdb97b

Browse files
committed
CCM-12937 Letter updates transformer lambda
1 parent 089b325 commit 0fdb97b

40 files changed

+2605
-365
lines changed

infrastructure/terraform/components/api/README.md

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -45,6 +45,7 @@ No requirements.
4545
| <a name="module_kms"></a> [kms](#module\_kms) | https://github.com/NHSDigital/nhs-notify-shared-modules/releases/download/v2.0.26/terraform-kms.zip | n/a |
4646
| <a name="module_letter_status_update"></a> [letter\_status\_update](#module\_letter\_status\_update) | https://github.com/NHSDigital/nhs-notify-shared-modules/releases/download/v2.0.24/terraform-lambda.zip | n/a |
4747
| <a name="module_letter_status_updates_queue"></a> [letter\_status\_updates\_queue](#module\_letter\_status\_updates\_queue) | https://github.com/NHSDigital/nhs-notify-shared-modules/releases/download/v2.0.24/terraform-sqs.zip | n/a |
48+
| <a name="module_letter_stream_forwarder"></a> [letter\_stream\_forwarder](#module\_letter\_stream\_forwarder) | https://github.com/NHSDigital/nhs-notify-shared-modules/releases/download/v2.0.26/terraform-lambda.zip | n/a |
4849
| <a name="module_letter_updates_transformer"></a> [letter\_updates\_transformer](#module\_letter\_updates\_transformer) | https://github.com/NHSDigital/nhs-notify-shared-modules/releases/download/v2.0.26/terraform-lambda.zip | n/a |
4950
| <a name="module_logging_bucket"></a> [logging\_bucket](#module\_logging\_bucket) | https://github.com/NHSDigital/nhs-notify-shared-modules/releases/download/v2.0.26/terraform-s3bucket.zip | n/a |
5051
| <a name="module_patch_letter"></a> [patch\_letter](#module\_patch\_letter) | https://github.com/NHSDigital/nhs-notify-shared-modules/releases/download/v2.0.26/terraform-lambda.zip | n/a |

infrastructure/terraform/components/api/ddb_table_letters.tf

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,8 @@
11
resource "aws_dynamodb_table" "letters" {
22
name = "${local.csi}-letters"
33
billing_mode = "PAY_PER_REQUEST"
4+
stream_enabled = true
5+
stream_view_type = "NEW_AND_OLD_IMAGES"
46

57
hash_key = "supplierId"
68
range_key = "id"
Lines changed: 23 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,23 @@
1+
resource "aws_lambda_event_source_mapping" "letter_stream_forwarder_dynamodb" {
2+
event_source_arn = aws_dynamodb_table.letters.stream_arn
3+
function_name = module.letter_stream_forwarder.function_arn
4+
starting_position = "LATEST"
5+
batch_size = 10
6+
maximum_batching_window_in_seconds = 1
7+
8+
depends_on = [
9+
module.letter_stream_forwarder # ensures stream forwarder exists
10+
]
11+
}
12+
13+
resource "aws_lambda_event_source_mapping" "letter_updates_transformer_kinesis" {
14+
event_source_arn = aws_kinesis_stream.letter_change_stream.arn
15+
function_name = module.letter_updates_transformer.function_arn
16+
starting_position = "LATEST"
17+
batch_size = 10
18+
maximum_batching_window_in_seconds = 1
19+
20+
depends_on = [
21+
module.letter_updates_transformer # ensures updates transformer exists
22+
]
23+
}
Lines changed: 5 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,5 @@
1+
resource "aws_kinesis_stream" "letter_change_stream" {
2+
name = "${local.csi}-letter-change-stream"
3+
shard_count = 1
4+
retention_period = 24
5+
}
Lines changed: 74 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,74 @@
1+
module "letter_stream_forwarder" {
2+
source = "https://github.com/NHSDigital/nhs-notify-shared-modules/releases/download/v2.0.26/terraform-lambda.zip"
3+
4+
function_name = "letter-stream-forwarder"
5+
description = "Kinesis stream forwarder for DDB letter status updates"
6+
7+
aws_account_id = var.aws_account_id
8+
component = var.component
9+
environment = var.environment
10+
project = var.project
11+
region = var.region
12+
group = var.group
13+
14+
log_retention_in_days = var.log_retention_in_days
15+
kms_key_arn = module.kms.key_arn
16+
17+
iam_policy_document = {
18+
body = data.aws_iam_policy_document.letter_stream_forwarder_lambda.json
19+
}
20+
21+
function_s3_bucket = local.acct.s3_buckets["lambda_function_artefacts"]["id"]
22+
function_code_base_path = local.aws_lambda_functions_dir_path
23+
function_code_dir = "letter-stream-forwarder/dist"
24+
function_include_common = true
25+
handler_function_name = "handler"
26+
runtime = "nodejs22.x"
27+
memory = 128
28+
timeout = 5
29+
log_level = var.log_level
30+
31+
force_lambda_code_deploy = var.force_lambda_code_deploy
32+
enable_lambda_insights = false
33+
34+
send_to_firehose = true
35+
log_destination_arn = local.destination_arn
36+
log_subscription_role_arn = local.acct.log_subscription_role_arn
37+
38+
lambda_env_vars = merge(local.common_lambda_env_vars, {
39+
LETTER_CHANGE_STREAM_ARN = "${aws_kinesis_stream.letter_change_stream.arn}"
40+
})
41+
}
42+
43+
data "aws_iam_policy_document" "letter_stream_forwarder_lambda" {
44+
45+
statement {
46+
sid = "AllowDynamoDBStream"
47+
effect = "Allow"
48+
49+
actions = [
50+
"dynamodb:GetRecords",
51+
"dynamodb:GetShardIterator",
52+
"dynamodb:DescribeStream",
53+
"dynamodb:ListStreams",
54+
]
55+
56+
resources = [
57+
"${aws_dynamodb_table.letters.arn}/stream/*"
58+
]
59+
}
60+
61+
statement {
62+
sid = "AllowKinesisPut"
63+
effect = "Allow"
64+
65+
actions = [
66+
"kinesis:DescribeStream",
67+
"kinesis:PutRecord",
68+
]
69+
70+
resources = [
71+
aws_kinesis_stream.letter_change_stream.arn
72+
]
73+
}
74+
}

infrastructure/terraform/components/api/module_lambda_letter_updates_transformer.tf

Lines changed: 12 additions & 8 deletions
Original file line numberDiff line numberDiff line change
@@ -36,35 +36,39 @@ module "letter_updates_transformer" {
3636
log_subscription_role_arn = local.acct.log_subscription_role_arn
3737

3838
lambda_env_vars = merge(local.common_lambda_env_vars, {
39-
EVENTPUB_SNS_TOPIC_ARN = module.eventpub.sns_topic.arn
39+
EVENTPUB_SNS_TOPIC_ARN = "${module.eventpub.sns_topic.arn}"
4040
})
4141
}
4242

4343
data "aws_iam_policy_document" "letter_updates_transformer_lambda" {
4444
statement {
45-
sid = "KMSPermissions"
45+
sid = "AllowSNSPublish"
4646
effect = "Allow"
4747

4848
actions = [
49-
"kms:Decrypt",
50-
"kms:GenerateDataKey",
49+
"sns:Publish"
5150
]
5251

5352
resources = [
54-
module.kms.key_arn,
53+
module.eventpub.sns_topic.arn
5554
]
5655
}
5756

5857
statement {
59-
sid = "AllowSNSPublish"
58+
sid = "AllowKinesisGet"
6059
effect = "Allow"
6160

6261
actions = [
63-
"sns:Publish"
62+
"kinesis:GetRecords",
63+
"kinesis:GetShardIterator",
64+
"kinesis:DescribeStream",
65+
"kinesis:DescribeStreamSummary",
66+
"kinesis:ListShards",
67+
"kinesis:ListStreams",
6468
]
6569

6670
resources = [
67-
module.eventpub.sns_topic.arn
71+
aws_kinesis_stream.letter_change_stream.arn
6872
]
6973
}
7074
}

internal/events/package.json

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -50,5 +50,5 @@
5050
"typecheck": "tsc --noEmit"
5151
},
5252
"types": "dist/index.d.ts",
53-
"version": "1.0.3"
53+
"version": "1.0.4"
5454
}

internal/events/src/events/__tests__/event-envelope.test.ts

Lines changed: 9 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -8,12 +8,15 @@ describe("EventEnvelope schema validation", () => {
88
const baseValidEnvelope: Envelope = {
99
dataschema:
1010
"https://notify.nhs.uk/cloudevents/schemas/supplier-api/order.READ.1.0.0.schema.json",
11+
dataschemaversion: "1.0.0",
1112
specversion: "1.0",
1213
id: "6f1c2a53-3d54-4a0a-9a0b-0e9ae2d4c111",
1314
source: "/data-plane/supplier-api/ordering",
1415
subject: "order/769acdd4",
1516
type: "uk.nhs.notify.supplier-api.order.READ.v1",
17+
plane: "data-plane",
1618
time: "2025-10-01T10:15:30.000Z",
19+
datacontenttype: "application/json",
1720
data: {
1821
"notify-payload": {
1922
"notify-data": { nhsNumber: "9434765919" },
@@ -241,10 +244,13 @@ describe("EventEnvelope schema validation", () => {
241244
specversion: "1.0" as const,
242245
id: "6f1c2a53-3d54-4a0a-9a0b-0e02b2c3d479",
243246
type: "uk.nhs.notify.supplier-api.letter.CREATED.v1" as const,
247+
plane: "data-plane",
244248
dataschema:
245249
"https://notify.nhs.uk/cloudevents/schemas/supplier-api/letter.CREATED.1.0.0.schema.json",
250+
dataschemaversion: "1.0.0",
246251
source: "/data-plane/supplier-api/letters",
247252
time: "2025-10-01T10:15:30.000Z",
253+
datacontenttype: "application/json",
248254
data: { status: "CREATED" },
249255
traceparent: "00-0af7651916cd43dd8448eb211c80319c-b7ad6b7169203331-01",
250256
recordedtime: "2025-10-01T10:15:30.250Z",
@@ -294,11 +300,14 @@ describe("EventEnvelope schema validation", () => {
294300
specversion: "1.0" as const,
295301
id: "6f1c2a53-3d54-4a0a-9a0b-0e9ae2d4c111",
296302
type: "uk.nhs.notify.supplier-api.order.READ.v1" as const,
303+
plane: "data-plane",
297304
dataschema:
298305
"https://notify.nhs.uk/cloudevents/schemas/supplier-api/order.READ.1.0.0.schema.json",
306+
dataschemaversion: "1.0.0",
299307
source: "/data-plane/supplier-api/ordering",
300308
subject: "order/769acdd4",
301309
time: "2025-10-01T10:15:30.000Z",
310+
datacontenttype: "application/json",
302311
data: { status: "READ" },
303312
traceparent: "00-0af7651916cd43dd8448eb211c80319c-b7ad6b7169203331-01",
304313
recordedtime: "2025-10-01T10:15:30.250Z",

internal/events/src/events/__tests__/mi-events.test.ts

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -18,13 +18,15 @@ describe("MI event validations", () => {
1818
expect(event).toEqual(
1919
expect.objectContaining({
2020
type: "uk.nhs.notify.supplier-api.mi.SUBMITTED.v1",
21+
plane: "data-plane",
2122
specversion: "1.0",
2223
source: "/data-plane/supplier-api/prod/submit-mi",
2324
id: "8f2c3b44-4e65-5b1b-a678-1f0bf3d4d222",
2425
time: "2025-11-16T10:30:00.000Z",
2526
datacontenttype: "application/json",
2627
dataschema:
2728
"https://notify.nhs.uk/cloudevents/schemas/supplier-api/mi.SUBMITTED.1.0.0.schema.json",
29+
dataschemaversion: "1.0.0",
2830
subject: "mi/mi-test-001",
2931
data: expect.objectContaining({
3032
id: "mi-test-001",

internal/events/src/events/__tests__/testData/letter.ACCEPTED-with-invalid-major-version.json

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -13,7 +13,9 @@
1313
},
1414
"datacontenttype": "application/json",
1515
"dataschema": "https://notify.nhs.uk/cloudevents/schemas/supplier-api/letter.ACCEPTED.0.1.0.schema.json",
16+
"dataschemaversion": "1.0.0",
1617
"id": "23f1f09c-a555-4d9b-8405-0b33490bc920",
18+
"plane": "data-plane",
1719
"recordedtime": "2025-08-28T08:45:00.000Z",
1820
"severitynumber": 2,
1921
"severitytext": "INFO",

0 commit comments

Comments
 (0)