Skip to content

Commit fa1b1bc

Browse files
Added terraform and stream forwarder
1 parent 39c023b commit fa1b1bc

17 files changed

+401
-2
lines changed

infrastructure/terraform/components/api/README.md

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -48,6 +48,8 @@ No requirements.
4848
| <a name="module_letter_stream_forwarder"></a> [letter\_stream\_forwarder](#module\_letter\_stream\_forwarder) | https://github.com/NHSDigital/nhs-notify-shared-modules/releases/download/v2.0.26/terraform-lambda.zip | n/a |
4949
| <a name="module_letter_updates_transformer"></a> [letter\_updates\_transformer](#module\_letter\_updates\_transformer) | https://github.com/NHSDigital/nhs-notify-shared-modules/releases/download/v2.0.26/terraform-lambda.zip | n/a |
5050
| <a name="module_logging_bucket"></a> [logging\_bucket](#module\_logging\_bucket) | https://github.com/NHSDigital/nhs-notify-shared-modules/releases/download/v2.0.26/terraform-s3bucket.zip | n/a |
51+
| <a name="module_mi_stream_forwarder"></a> [mi\_stream\_forwarder](#module\_mi\_stream\_forwarder) | https://github.com/NHSDigital/nhs-notify-shared-modules/releases/download/v2.0.26/terraform-lambda.zip | n/a |
52+
| <a name="module_mi_updates_transformer"></a> [mi\_updates\_transformer](#module\_mi\_updates\_transformer) | https://github.com/NHSDigital/nhs-notify-shared-modules/releases/download/v2.0.26/terraform-lambda.zip | n/a |
5153
| <a name="module_patch_letter"></a> [patch\_letter](#module\_patch\_letter) | https://github.com/NHSDigital/nhs-notify-shared-modules/releases/download/v2.0.26/terraform-lambda.zip | n/a |
5254
| <a name="module_post_letters"></a> [post\_letters](#module\_post\_letters) | https://github.com/NHSDigital/nhs-notify-shared-modules/releases/download/v2.0.24/terraform-lambda.zip | n/a |
5355
| <a name="module_post_mi"></a> [post\_mi](#module\_post\_mi) | https://github.com/NHSDigital/nhs-notify-shared-modules/releases/download/v2.0.26/terraform-lambda.zip | n/a |

infrastructure/terraform/components/api/ddb_table_mi.tf

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,8 @@
11
resource "aws_dynamodb_table" "mi" {
22
name = "${local.csi}-mi"
33
billing_mode = "PAY_PER_REQUEST"
4+
stream_enabled = true
5+
stream_view_type = "NEW_IMAGE"
46

57
hash_key = "supplierId"
68
range_key = "id"
Lines changed: 23 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,23 @@
1+
resource "aws_lambda_event_source_mapping" "mi_stream_forwarder_dynamodb" {
2+
event_source_arn = aws_dynamodb_table.mi.stream_arn
3+
function_name = module.mi_stream_forwarder.function_arn
4+
starting_position = "LATEST"
5+
batch_size = 10
6+
maximum_batching_window_in_seconds = 1
7+
8+
depends_on = [
9+
module.mi_stream_forwarder # ensures stream forwarder exists
10+
]
11+
}
12+
13+
resource "aws_lambda_event_source_mapping" "mi_updates_transformer_kinesis" {
14+
event_source_arn = aws_kinesis_stream.mi_change_stream.arn
15+
function_name = module.mi_updates_transformer.function_arn
16+
starting_position = "LATEST"
17+
batch_size = 10
18+
maximum_batching_window_in_seconds = 1
19+
20+
depends_on = [
21+
module.mi_updates_transformer # ensures updates transformer exists
22+
]
23+
}
Lines changed: 5 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,5 @@
1+
resource "aws_kinesis_stream" "mi_change_stream" {
2+
name = "mi-change-stream"
3+
shard_count = 1
4+
retention_period = 24
5+
}
Lines changed: 73 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,73 @@
1+
module "mi_stream_forwarder" {
2+
source = "https://github.com/NHSDigital/nhs-notify-shared-modules/releases/download/v2.0.26/terraform-lambda.zip"
3+
4+
function_name = "mi-stream-forwarder"
5+
description = "Kinesis stream forwarder for DDB mi status updates"
6+
7+
aws_account_id = var.aws_account_id
8+
component = var.component
9+
environment = var.environment
10+
project = var.project
11+
region = var.region
12+
group = var.group
13+
14+
log_retention_in_days = var.log_retention_in_days
15+
kms_key_arn = module.kms.key_arn
16+
17+
iam_policy_document = {
18+
body = data.aws_iam_policy_document.mi_stream_forwarder_lambda.json
19+
}
20+
21+
function_s3_bucket = local.acct.s3_buckets["lambda_function_artefacts"]["id"]
22+
function_code_base_path = local.aws_lambda_functions_dir_path
23+
function_code_dir = "mi-stream-forwarder/dist"
24+
function_include_common = true
25+
handler_function_name = "handler"
26+
runtime = "nodejs22.x"
27+
memory = 128
28+
timeout = 5
29+
log_level = var.log_level
30+
31+
force_lambda_code_deploy = var.force_lambda_code_deploy
32+
enable_lambda_insights = false
33+
34+
send_to_firehose = true
35+
log_destination_arn = local.destination_arn
36+
log_subscription_role_arn = local.acct.log_subscription_role_arn
37+
38+
lambda_env_vars = merge(local.common_lambda_env_vars, {
39+
MI_CHANGE_STREAM_NAME = "mi_change_stream"
40+
})
41+
}
42+
43+
data "aws_iam_policy_document" "mi_stream_forwarder_lambda" {
44+
45+
statement {
46+
sid = "AllowDynamoDBStream"
47+
effect = "Allow"
48+
49+
actions = [
50+
"dynamodb:GetRecords",
51+
"dynamodb:GetShardIterator",
52+
"dynamodb:DescribeStream",
53+
"dynamodb:ListStreams",
54+
]
55+
56+
resources = [
57+
"${aws_dynamodb_table.mi.arn}/stream/*"
58+
]
59+
}
60+
61+
statement {
62+
sid = "AllowKinesisPut"
63+
effect = "Allow"
64+
65+
actions = [
66+
"kinesis:*"
67+
]
68+
69+
resources = [
70+
aws_kinesis_stream.mi_change_stream.arn
71+
]
72+
}
73+
}
Lines changed: 74 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,74 @@
1+
module "mi_updates_transformer" {
2+
source = "https://github.com/NHSDigital/nhs-notify-shared-modules/releases/download/v2.0.26/terraform-lambda.zip"
3+
4+
function_name = "mi-updates-transformer"
5+
description = "MI Update Filter/Producer"
6+
7+
aws_account_id = var.aws_account_id
8+
component = var.component
9+
environment = var.environment
10+
project = var.project
11+
region = var.region
12+
group = var.group
13+
14+
log_retention_in_days = var.log_retention_in_days
15+
kms_key_arn = module.kms.key_arn
16+
17+
iam_policy_document = {
18+
body = data.aws_iam_policy_document.mi_updates_transformer_lambda.json
19+
}
20+
21+
function_s3_bucket = local.acct.s3_buckets["lambda_function_artefacts"]["id"]
22+
function_code_base_path = local.aws_lambda_functions_dir_path
23+
function_code_dir = "mi-updates-transformer/dist"
24+
function_include_common = true
25+
handler_function_name = "handler"
26+
runtime = "nodejs22.x"
27+
memory = 128
28+
timeout = 5
29+
log_level = var.log_level
30+
31+
force_lambda_code_deploy = var.force_lambda_code_deploy
32+
enable_lambda_insights = false
33+
34+
send_to_firehose = true
35+
log_destination_arn = local.destination_arn
36+
log_subscription_role_arn = local.acct.log_subscription_role_arn
37+
38+
lambda_env_vars = merge(local.common_lambda_env_vars, {
39+
EVENTPUB_SNS_TOPIC_ARN = module.eventpub.sns_topic.arn
40+
})
41+
}
42+
43+
data "aws_iam_policy_document" "mi_updates_transformer_lambda" {
44+
statement {
45+
sid = "AllowSNSPublish"
46+
effect = "Allow"
47+
48+
actions = [
49+
"sns:Publish"
50+
]
51+
52+
resources = [
53+
module.eventpub.sns_topic.arn
54+
]
55+
}
56+
57+
statement {
58+
sid = "AllowKinesisGet"
59+
effect = "Allow"
60+
61+
actions = [
62+
"kinesis:GetRecords",
63+
"kinesis:GetShardIterator",
64+
"kinesis:DescribeStream",
65+
"kinesis:DescribeStreamSummary",
66+
"kinesis:ListShards",
67+
"kinesis:ListStreams",
68+
]
69+
70+
resources = [
71+
aws_kinesis_stream.mi_change_stream.arn
72+
]
73+
}
74+
}
Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1 @@
1+
dist
Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,4 @@
1+
coverage
2+
node_modules
3+
dist
4+
.reports
Lines changed: 60 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,60 @@
1+
import type { Config } from 'jest';
2+
3+
export const baseJestConfig: Config = {
4+
preset: 'ts-jest',
5+
6+
// Automatically clear mock calls, instances, contexts and results before every test
7+
clearMocks: true,
8+
9+
// Indicates whether the coverage information should be collected while executing the test
10+
collectCoverage: true,
11+
12+
// The directory where Jest should output its coverage files
13+
coverageDirectory: './.reports/unit/coverage',
14+
15+
// Indicates which provider should be used to instrument code for coverage
16+
coverageProvider: 'babel',
17+
18+
coverageThreshold: {
19+
global: {
20+
branches: 100,
21+
functions: 100,
22+
lines: 100,
23+
statements: -10,
24+
},
25+
},
26+
27+
coveragePathIgnorePatterns: ['/__tests__/'],
28+
transform: { '^.+\\.ts$': 'ts-jest' },
29+
testPathIgnorePatterns: ['.build'],
30+
testMatch: ['**/?(*.)+(spec|test).[jt]s?(x)'],
31+
32+
// Use this configuration option to add custom reporters to Jest
33+
reporters: [
34+
'default',
35+
[
36+
'jest-html-reporter',
37+
{
38+
pageTitle: 'Test Report',
39+
outputPath: './.reports/unit/test-report.html',
40+
includeFailureMsg: true,
41+
},
42+
],
43+
],
44+
45+
// The test environment that will be used for testing
46+
testEnvironment: 'jsdom',
47+
};
48+
49+
const utilsJestConfig = {
50+
...baseJestConfig,
51+
52+
testEnvironment: 'node',
53+
54+
coveragePathIgnorePatterns: [
55+
...(baseJestConfig.coveragePathIgnorePatterns ?? []),
56+
'zod-validators.ts',
57+
],
58+
};
59+
60+
export default utilsJestConfig;
Lines changed: 21 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,21 @@
1+
{
2+
"dependencies": {
3+
"@aws-sdk/client-kinesis": "^3.0.0",
4+
"aws-lambda": "^1.0.7"
5+
},
6+
"devDependencies": {
7+
"@types/aws-lambda": "^8.10.119",
8+
"typescript": "^5.0.0"
9+
},
10+
"main": "src/index.ts",
11+
"name": "mi-stream-forwarder",
12+
"private": true,
13+
"scripts": {
14+
"lambda-build": "rm -rf dist && npx esbuild --bundle --minify --sourcemap --target=es2020 --platform=node --loader:.node=file --entry-names=[name] --outdir=dist src/index.ts",
15+
"lint": "eslint .",
16+
"lint:fix": "eslint . --fix",
17+
"test:unit": "jest",
18+
"typecheck": "tsc --noEmit"
19+
},
20+
"version": "0.1.0"
21+
}

0 commit comments

Comments
 (0)