Skip to content

Commit b98b811

Browse files
authored
Merge pull request #16337 from guardian/aa/gucdk-64.0.0
chore(deps): Update GuCDK from 63.6.2 to 64.0.0
2 parents 006c956 + a529578 commit b98b811

6 files changed

Lines changed: 50 additions & 63 deletions

File tree

ab-testing/cdk/lib/__snapshots__/abTestingConfig.test.ts.snap

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -2,7 +2,7 @@ exports[`The ID5 Baton Lambda stack > matches the CODE snapshot 1`] = `
22
{
33
"Metadata": {
44
"gu:cdk:constructs": [],
5-
"gu:cdk:version": "63.6.2"
5+
"gu:cdk:version": "64.0.0"
66
},
77
"Parameters": {
88
"BuildId": {
@@ -46,7 +46,7 @@ exports[`The ID5 Baton Lambda stack > matches the PROD snapshot 1`] = `
4646
{
4747
"Metadata": {
4848
"gu:cdk:constructs": [],
49-
"gu:cdk:version": "63.6.2"
49+
"gu:cdk:version": "64.0.0"
5050
},
5151
"Parameters": {
5252
"BuildId": {

ab-testing/cdk/lib/__snapshots__/deploymentLambda.test.ts.snap

Lines changed: 6 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -5,7 +5,7 @@ exports[`The AB testing deployment lambda stack > matches the CODE snapshot 1`]
55
"GuDistributionBucketParameter",
66
"GuLambdaFunction"
77
],
8-
"gu:cdk:version": "63.6.2"
8+
"gu:cdk:version": "64.0.0"
99
},
1010
"Parameters": {
1111
"SsmParameterValueaccountservicesdotcomstorebucketC96584B6F00A464EAD1953AFF4B05118Parameter": {
@@ -55,7 +55,7 @@ exports[`The AB testing deployment lambda stack > matches the CODE snapshot 1`]
5555
},
5656
{
5757
"Key": "gu:cdk:version",
58-
"Value": "63.6.2"
58+
"Value": "64.0.0"
5959
},
6060
{
6161
"Key": "gu:repo",
@@ -294,7 +294,7 @@ exports[`The AB testing deployment lambda stack > matches the CODE snapshot 1`]
294294
},
295295
{
296296
"Key": "gu:cdk:version",
297-
"Value": "63.6.2"
297+
"Value": "64.0.0"
298298
},
299299
{
300300
"Key": "gu:repo",
@@ -327,7 +327,7 @@ exports[`The AB testing deployment lambda stack > matches the PROD snapshot 1`]
327327
"GuDistributionBucketParameter",
328328
"GuLambdaFunction"
329329
],
330-
"gu:cdk:version": "63.6.2"
330+
"gu:cdk:version": "64.0.0"
331331
},
332332
"Parameters": {
333333
"SsmParameterValueaccountservicesdotcomstorebucketC96584B6F00A464EAD1953AFF4B05118Parameter": {
@@ -377,7 +377,7 @@ exports[`The AB testing deployment lambda stack > matches the PROD snapshot 1`]
377377
},
378378
{
379379
"Key": "gu:cdk:version",
380-
"Value": "63.6.2"
380+
"Value": "64.0.0"
381381
},
382382
{
383383
"Key": "gu:repo",
@@ -616,7 +616,7 @@ exports[`The AB testing deployment lambda stack > matches the PROD snapshot 1`]
616616
},
617617
{
618618
"Key": "gu:cdk:version",
619-
"Value": "63.6.2"
619+
"Value": "64.0.0"
620620
},
621621
{
622622
"Key": "gu:repo",

ab-testing/cdk/lib/__snapshots__/notificationLambda.test.ts.snap

Lines changed: 13 additions & 13 deletions
Original file line numberDiff line numberDiff line change
@@ -10,7 +10,7 @@ exports[`The AB testing notification lambda stack > matches the CODE snapshot 1`
1010
"GuScheduledLambda",
1111
"GuLambdaErrorPercentageAlarm"
1212
],
13-
"gu:cdk:version": "63.6.2"
13+
"gu:cdk:version": "64.0.0"
1414
},
1515
"Resources": {
1616
"EmailIdentityAbtestingnotificationlambdaE053C648": {
@@ -24,7 +24,7 @@ exports[`The AB testing notification lambda stack > matches the CODE snapshot 1`
2424
},
2525
{
2626
"Key": "gu:cdk:version",
27-
"Value": "63.6.2"
27+
"Value": "64.0.0"
2828
},
2929
{
3030
"Key": "gu:repo",
@@ -113,7 +113,7 @@ exports[`The AB testing notification lambda stack > matches the CODE snapshot 1`
113113
"Tags": [
114114
{
115115
"Key": "gu:cdk:version",
116-
"Value": "63.6.2"
116+
"Value": "64.0.0"
117117
},
118118
{
119119
"Key": "gu:repo",
@@ -166,7 +166,7 @@ exports[`The AB testing notification lambda stack > matches the CODE snapshot 1`
166166
},
167167
{
168168
"Key": "gu:cdk:version",
169-
"Value": "63.6.2"
169+
"Value": "64.0.0"
170170
},
171171
{
172172
"Key": "gu:repo",
@@ -340,7 +340,7 @@ exports[`The AB testing notification lambda stack > matches the CODE snapshot 1`
340340
},
341341
{
342342
"Key": "gu:cdk:version",
343-
"Value": "63.6.2"
343+
"Value": "64.0.0"
344344
},
345345
{
346346
"Key": "gu:repo",
@@ -452,7 +452,7 @@ exports[`The AB testing notification lambda stack > matches the CODE snapshot 1`
452452
"Tags": [
453453
{
454454
"Key": "gu:cdk:version",
455-
"Value": "63.6.2"
455+
"Value": "64.0.0"
456456
},
457457
{
458458
"Key": "gu:repo",
@@ -494,7 +494,7 @@ exports[`The AB testing notification lambda stack > matches the PROD snapshot 1`
494494
"GuScheduledLambda",
495495
"GuLambdaErrorPercentageAlarm"
496496
],
497-
"gu:cdk:version": "63.6.2"
497+
"gu:cdk:version": "64.0.0"
498498
},
499499
"Resources": {
500500
"EmailIdentityAbtestingnotificationlambdaE053C648": {
@@ -508,7 +508,7 @@ exports[`The AB testing notification lambda stack > matches the PROD snapshot 1`
508508
},
509509
{
510510
"Key": "gu:cdk:version",
511-
"Value": "63.6.2"
511+
"Value": "64.0.0"
512512
},
513513
{
514514
"Key": "gu:repo",
@@ -597,7 +597,7 @@ exports[`The AB testing notification lambda stack > matches the PROD snapshot 1`
597597
"Tags": [
598598
{
599599
"Key": "gu:cdk:version",
600-
"Value": "63.6.2"
600+
"Value": "64.0.0"
601601
},
602602
{
603603
"Key": "gu:repo",
@@ -660,7 +660,7 @@ exports[`The AB testing notification lambda stack > matches the PROD snapshot 1`
660660
},
661661
{
662662
"Key": "gu:cdk:version",
663-
"Value": "63.6.2"
663+
"Value": "64.0.0"
664664
},
665665
{
666666
"Key": "gu:repo",
@@ -834,7 +834,7 @@ exports[`The AB testing notification lambda stack > matches the PROD snapshot 1`
834834
},
835835
{
836836
"Key": "gu:cdk:version",
837-
"Value": "63.6.2"
837+
"Value": "64.0.0"
838838
},
839839
{
840840
"Key": "gu:repo",
@@ -869,7 +869,7 @@ exports[`The AB testing notification lambda stack > matches the PROD snapshot 1`
869869
},
870870
{
871871
"Key": "gu:cdk:version",
872-
"Value": "63.6.2"
872+
"Value": "64.0.0"
873873
},
874874
{
875875
"Key": "gu:repo",
@@ -1006,7 +1006,7 @@ exports[`The AB testing notification lambda stack > matches the PROD snapshot 1`
10061006
"Tags": [
10071007
{
10081008
"Key": "gu:cdk:version",
1009-
"Value": "63.6.2"
1009+
"Value": "64.0.0"
10101010
},
10111011
{
10121012
"Key": "gu:repo",

dotcom-rendering/cdk/lib/renderingStack.ts

Lines changed: 21 additions & 34 deletions
Original file line numberDiff line numberDiff line change
@@ -216,47 +216,34 @@ export class RenderingCDKStack extends CDKStack {
216216
certificateProps: { domainName },
217217
healthcheck: { path: '/_healthcheck' },
218218
monitoringConfiguration,
219+
additionalPolicies: [
220+
new GuAllowPolicy(this, 'AllowPolicyCloudwatchLogs', {
221+
actions: ['cloudwatch:*', 'logs:*'],
222+
resources: ['*'],
223+
}),
224+
new GuAllowPolicy(this, 'AllowPolicyDescribeDecryptKms', {
225+
actions: ['kms:Decrypt', 'kms:DescribeKey'],
226+
resources: [
227+
`arn:aws:kms:${region}:${account}:FrontendConfigKey`,
228+
],
229+
}),
230+
new GuAllowPolicy(this, 'AllowPolicyGetSsmParamsByPath', {
231+
actions: ['ssm:GetParametersByPath', 'ssm:GetParameter'],
232+
resources: [
233+
// This is for backwards compatibility reasons with frontend apps and an old SSM naming system
234+
// TODO - ideally we should convert these params to use the newer naming style for consistency
235+
`arn:aws:ssm:${region}:${this.account}:parameter/frontend/*`,
236+
`arn:aws:ssm:${region}:${this.account}:parameter/dotcom/*`,
237+
],
238+
}),
239+
],
219240
ec2Props: {
220241
instanceMetricGranularity: '1Minute',
221242
applicationLogging: {
222243
enabled: true,
223244
systemdUnitName: guApp,
224245
},
225246
instanceType,
226-
roleConfiguration: {
227-
additionalPolicies: [
228-
new GuAllowPolicy(this, 'AllowPolicyCloudwatchLogs', {
229-
actions: ['cloudwatch:*', 'logs:*'],
230-
resources: ['*'],
231-
}),
232-
new GuAllowPolicy(
233-
this,
234-
'AllowPolicyDescribeDecryptKms',
235-
{
236-
actions: ['kms:Decrypt', 'kms:DescribeKey'],
237-
resources: [
238-
`arn:aws:kms:${region}:${account}:FrontendConfigKey`,
239-
],
240-
},
241-
),
242-
new GuAllowPolicy(
243-
this,
244-
'AllowPolicyGetSsmParamsByPath',
245-
{
246-
actions: [
247-
'ssm:GetParametersByPath',
248-
'ssm:GetParameter',
249-
],
250-
resources: [
251-
// This is for backwards compatibility reasons with frontend apps and an old SSM naming system
252-
// TODO - ideally we should convert these params to use the newer naming style for consistency
253-
`arn:aws:ssm:${region}:${this.account}:parameter/frontend/*`,
254-
`arn:aws:ssm:${region}:${this.account}:parameter/dotcom/*`,
255-
],
256-
},
257-
),
258-
],
259-
},
260247
scaling,
261248
userData: getUserData({
262249
guApp,

pnpm-lock.yaml

Lines changed: 7 additions & 7 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

pnpm-workspace.yaml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -11,7 +11,7 @@ blockExoticSubdeps: true
1111
catalog:
1212
'@aws-sdk/client-s3': 3.995.0
1313
'@aws-sdk/client-ssm': 3.995.0
14-
'@guardian/cdk': 63.6.2
14+
'@guardian/cdk': 64.0.0
1515
'@guardian/eslint-config': 14.0.1
1616
'@guardian/tsconfig': 1.0.1
1717
'@rollup/plugin-commonjs': 29.0.0

0 commit comments

Comments
 (0)