-
Notifications
You must be signed in to change notification settings - Fork 4k
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
feat: support API Gateway enrichment
- Loading branch information
Showing
15 changed files
with
40,688 additions
and
0 deletions.
There are no files selected for viewing
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
111 changes: 111 additions & 0 deletions
111
packages/@aws-cdk/aws-pipes-enrichments-alpha/lib/api-gateway.ts
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,111 @@ | ||
import { EnrichmentParametersConfig, IEnrichment, IPipe, InputTransformation } from '@aws-cdk/aws-pipes-alpha'; | ||
import { IRestApi } from 'aws-cdk-lib/aws-apigateway'; | ||
import { IRole, PolicyStatement } from 'aws-cdk-lib/aws-iam'; | ||
import { CfnPipe } from 'aws-cdk-lib/aws-pipes'; | ||
|
||
/** | ||
* Properties for a ApiGatewayEnrichment | ||
*/ | ||
export interface ApiGatewayEnrichmentProps { | ||
/** | ||
* The input transformation for the enrichment | ||
* @see https://docs.aws.amazon.com/eventbridge/latest/userguide/eb-pipes-input-transformation.html | ||
* @default - None | ||
*/ | ||
readonly inputTransformation?: InputTransformation; | ||
|
||
/** | ||
* The method for API Gateway resource. | ||
* | ||
* @default '*' - ANY | ||
*/ | ||
readonly method?: string; | ||
|
||
/** | ||
* The path for the API Gateway resource. | ||
* | ||
* @default '/' | ||
*/ | ||
readonly path?: string; | ||
|
||
/** | ||
* The deployment stage for the API Gateway resource. | ||
* | ||
* @default - the value of `deploymentStage.stageName` of target API Gateway resource. | ||
*/ | ||
readonly stage?: string; | ||
|
||
/** | ||
* The headers that need to be sent as part of request invoking the API Gateway REST API. | ||
* | ||
* @default - none | ||
*/ | ||
readonly headerParameters?: Record<string, string>; | ||
|
||
/** | ||
* The path parameter values used to populate the API Gateway REST API path wildcards ("*"). | ||
* | ||
* @default - none | ||
*/ | ||
readonly pathParameterValues?: string[]; | ||
|
||
/** | ||
* The query string keys/values that need to be sent as part of request invoking the EventBridge API destination. | ||
* | ||
* @default - none | ||
*/ | ||
readonly queryStringParameters?: Record<string, string>; | ||
} | ||
|
||
/** | ||
* An API Gateway enrichment for a pipe | ||
*/ | ||
export class ApiGatewayEnrichment implements IEnrichment { | ||
public readonly enrichmentArn: string; | ||
|
||
private readonly inputTransformation?: InputTransformation; | ||
private readonly headerParameters?: Record<string, string>; | ||
private readonly pathParameterValues?: string[]; | ||
private readonly queryStringParameters?: Record<string, string>; | ||
|
||
constructor(private readonly restApi: IRestApi, props?: ApiGatewayEnrichmentProps) { | ||
this.enrichmentArn = restApi.arnForExecuteApi( | ||
props?.method, | ||
props?.path || '/', | ||
props?.stage || this.restApi.deploymentStage.stageName, | ||
); | ||
this.inputTransformation = props?.inputTransformation; | ||
this.headerParameters = props?.headerParameters; | ||
this.queryStringParameters = props?.queryStringParameters; | ||
this.pathParameterValues = props?.pathParameterValues; | ||
} | ||
|
||
bind(pipe: IPipe): EnrichmentParametersConfig { | ||
|
||
const httpParameters: CfnPipe.PipeEnrichmentHttpParametersProperty | undefined = | ||
this.headerParameters ?? | ||
this.pathParameterValues ?? | ||
this.queryStringParameters | ||
? { | ||
headerParameters: this.headerParameters, | ||
pathParameterValues: this.pathParameterValues, | ||
queryStringParameters: this.queryStringParameters, | ||
} | ||
: undefined; | ||
|
||
return { | ||
enrichmentParameters: { | ||
inputTemplate: this.inputTransformation?.bind(pipe).inputTemplate, | ||
httpParameters, | ||
}, | ||
}; | ||
} | ||
|
||
grantInvoke(pipeRole: IRole): void { | ||
pipeRole.addToPrincipalPolicy(new PolicyStatement({ | ||
resources: [this.enrichmentArn], | ||
actions: ['execute-api:Invoke'], | ||
})); | ||
} | ||
} | ||
|
1 change: 1 addition & 0 deletions
1
packages/@aws-cdk/aws-pipes-enrichments-alpha/rosetta/default.ts-fixture
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
109 changes: 109 additions & 0 deletions
109
packages/@aws-cdk/aws-pipes-enrichments-alpha/test/__snapshots__/api-gateway.test.ts.snap
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,109 @@ | ||
// Jest Snapshot v1, https://goo.gl/fbAQLP | ||
|
||
exports[`api-destination should grant pipe role invoke access 1`] = ` | ||
{ | ||
"MyPipeRoleCBC8E9AB": { | ||
"Properties": { | ||
"AssumeRolePolicyDocument": { | ||
"Statement": [ | ||
{ | ||
"Action": "sts:AssumeRole", | ||
"Effect": "Allow", | ||
"Principal": { | ||
"Service": "pipes.amazonaws.com", | ||
}, | ||
}, | ||
], | ||
"Version": "2012-10-17", | ||
}, | ||
}, | ||
"Type": "AWS::IAM::Role", | ||
}, | ||
"RestApiCloudWatchRoleE3ED6605": { | ||
"DeletionPolicy": "Retain", | ||
"Properties": { | ||
"AssumeRolePolicyDocument": { | ||
"Statement": [ | ||
{ | ||
"Action": "sts:AssumeRole", | ||
"Effect": "Allow", | ||
"Principal": { | ||
"Service": "apigateway.amazonaws.com", | ||
}, | ||
}, | ||
], | ||
"Version": "2012-10-17", | ||
}, | ||
"ManagedPolicyArns": [ | ||
{ | ||
"Fn::Join": [ | ||
"", | ||
[ | ||
"arn:", | ||
{ | ||
"Ref": "AWS::Partition", | ||
}, | ||
":iam::aws:policy/service-role/AmazonAPIGatewayPushToCloudWatchLogs", | ||
], | ||
], | ||
}, | ||
], | ||
}, | ||
"Type": "AWS::IAM::Role", | ||
"UpdateReplacePolicy": "Retain", | ||
}, | ||
} | ||
`; | ||
|
||
exports[`api-destination should grant pipe role invoke access 2`] = ` | ||
{ | ||
"MyPipeRoleDefaultPolicy31387C20": { | ||
"Properties": { | ||
"PolicyDocument": { | ||
"Statement": [ | ||
{ | ||
"Action": "execute-api:Invoke", | ||
"Effect": "Allow", | ||
"Resource": { | ||
"Fn::Join": [ | ||
"", | ||
[ | ||
"arn:", | ||
{ | ||
"Ref": "AWS::Partition", | ||
}, | ||
":execute-api:", | ||
{ | ||
"Ref": "AWS::Region", | ||
}, | ||
":", | ||
{ | ||
"Ref": "AWS::AccountId", | ||
}, | ||
":", | ||
{ | ||
"Ref": "RestApi0C43BF4B", | ||
}, | ||
"/", | ||
{ | ||
"Ref": "RestApiDeploymentStageprod3855DE66", | ||
}, | ||
"/*/", | ||
], | ||
], | ||
}, | ||
}, | ||
], | ||
"Version": "2012-10-17", | ||
}, | ||
"PolicyName": "MyPipeRoleDefaultPolicy31387C20", | ||
"Roles": [ | ||
{ | ||
"Ref": "MyPipeRoleCBC8E9AB", | ||
}, | ||
], | ||
}, | ||
"Type": "AWS::IAM::Policy", | ||
}, | ||
} | ||
`; |
Oops, something went wrong.