Skip to content

Feature/secure serverless arch - #18

Merged
IsaacTai13 merged 15 commits into
T13Forge:mainfrom
IsaacTai13:feature/secure_serverlessArch
Nov 13, 2025
Merged

Feature/secure serverless arch#18
IsaacTai13 merged 15 commits into
T13Forge:mainfrom
IsaacTai13:feature/secure_serverlessArch

Conversation

@IsaacTai13

Copy link
Copy Markdown
Contributor

No description provided.

- Created IAM role and attached least privilege policies for Lambda
(logs, SES, secrets)
- Created SNS topic 'user-signup-topic' and subscribed Lambda as
subscriber
- Added Lambda permission allowing SNS to invoke the function
- data source to zip lambda source from ../serverless
- created lambda func using Node.js 20 runtime
- config env vars (FROM_EMAIL, VERIFY_URL_BASE)
- Included source_code_hash for automatic function update when zip
content changes
- Created DynamoDB table 'SentEmails' with messageId as primary key
- Added IAM policy to grant Lambda dynamodb:GetItem and dynamodb:PutItem
permissions
- Inserted messageId after successful delivery to avoid duplicates
- using `terraform init -upgrade` cmd
- Updated .terraform.lock.hcl to latest compatible provider versions
- Ensures consistent provider versions across environments
    - RDS, EC2, SecretManager, S3
    - Avoid using AWS-managed default keys and instead use customer-managed keys
	- to control all encryption and description for our resources
…Manager

- Stored Mailgun API key securely in Secrets Manager instead of Lambda
env vars
- Correct KMS decrypt target resources
- Updated Lambda IAM role to allow `secretsmanager:GetSecretValue` and
`kms:Decrypt`
- change SNS topic using arn instead of name
- fetch AWS account ID via aws_caller_identity
- pass it into user_data for runtime configuration
- Adjust format
- Add comment
- Added HTTPS listener on port 443 using ACM certificate
- Ensured ALB forwards only HTTPS requests to target group
@IsaacTai13
IsaacTai13 merged commit b19121e into T13Forge:main Nov 13, 2025
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant