irongit
58 lines1.5 KB
1resource "aws_iam_role" "lambda_role" {
2 name = "${var.function_name}-role"
3
4 assume_role_policy = jsonencode({
5 Version = "2012-10-17",
6 Statement = [{
7 Action = "sts:AssumeRole",
8 Effect = "Allow",
9 Principal = { Service = "lambda.amazonaws.com" }
10 }]
11 })
12}
13
14resource "aws_iam_role_policy_attachment" "lambda_logging" {
15 role = aws_iam_role.lambda_role.name
16 policy_arn = "arn:aws:iam::aws:policy/service-role/AWSLambdaBasicExecutionRole"
17}
18
19resource "aws_iam_policy" "lambda_secret_access" {
20 name = "lambda-secret-access"
21 policy = jsonencode({
22 Version = "2012-10-17",
23 Statement = [
24 {
25 Effect = "Allow",
26 Action = [
27 "secretsmanager:GetSecretValue"
28 ],
29 Resource = [
30 "arn:aws:secretsmanager:us-west-1:036487096349:secret:rfl-secrets-ztW9tp"
31 ]
32 }
33 ]
34 })
35}
36
37resource "aws_iam_role_policy_attachment" "lambda_secret_access" {
38 role = aws_iam_role.lambda_role.name
39 policy_arn = aws_iam_policy.lambda_secret_access.arn
40}
41
42
43resource "aws_lambda_function" "api" {
44 function_name = var.function_name
45 role = aws_iam_role.lambda_role.arn
46 handler = "bootstrap" # Rust binary handler
47 runtime = "provided.al2023" # custom runtime for Rust
48 filename = var.lambda_zip
49 source_code_hash = filebase64sha256(var.lambda_zip)
50 memory_size = 128
51 timeout = 30
52
53 environment {
54 variables = {
55 RUST_LOG = "info"
56 }
57 }
58}