Serverless Infrastructure Design with Terraform and AWS
This repository implements a serverless REST API for simple items management. The solution uses AWS Lambda (Node.js 22), API Gateway REST API (proxy integration), DynamoDB, S3, IAM, and CloudWatch. Terraform is used for all infrastructure as code and is modularized for maintainability.
modules/- Terraform modules for reusable componentslambda/- Lambda moduleapi-gateway/- API Gateway moduledynamodb/- DynamoDB module
functions/- Lambda function source code (Node.js 22 ES Modules)items-api/- handler, package.json and README
- Root Terraform files: provider, variables, outputs and top-level module wiring
- S3 bucket with versioning for Lambda packages (
s3.tf) - DynamoDB table with server-side encryption (
modules/dynamodb) - Least-privilege IAM policies for Lambda (
iam.tf) - CloudWatch Log Group for Lambda (
cloudwatch.tf) - Lambda function implemented using Node.js 22 ES Modules.
See
functions/items-api/index.jsfor the handler implementation. - API Gateway REST API with proxy integration and CORS configured in
modules/api-gateway - Terraform variables include validation rules where appropriate.
- Outputs expose key identifiers in
outputs.tf. Examples include the API endpoint, Lambda ARN, DynamoDB ARN, and S3 bucket. - GitHub Actions workflows are provided to validate Terraform and build
Lambda artifacts. See
.github/workflows/for workflow definitions.
Prerequisites:
- Terraform >= 1.0
- AWS CLI configured with appropriate credentials
- Node.js 22 (for building functions)
Build the Lambda package and run the lightweight handler tests:
cd functions/items-api
npm ci
npm test # runs simple local handler tests
npm run buildThis creates items-api.zip, which can be uploaded via Terraform archive or
an aws_s3_object resource.
Deploy with Terraform:
terraform init
terraform plan
terraform applyAfter apply, view outputs:
terraform output api_endpoint
terraform output lambda_function_arn
terraform output dynamodb_table_arn
terraform output s3_bucket_nameWorkflows are provided to run on PRs and pushes:
terraform.yml- runsterraform fmt -check. It runsterraform init -backend=falseandterraform validate. The workflow also performstfsecsecurity scans.nodejs.yml- sets up Node.js 22, installs dependencies, and builds the Lambda package.markdownlint.yml- validates Markdown formatting.
You can run a single, offline validation that checks formatting, Terraform configuration, Node build/packaging and simple repository conventions without needing AWS credentials.
- Install dev dependencies:
npm install- Run the combined validation:
npm run validateWhat npm run validate does:
terraform fmt -check -recursiveandterraform init -backend=false && terraform validate(no AWS access required)- Builds the function package (
functions/items-api) and verifies the produced ZIP containsindex.js - Runs a lightweight conventions checker (no tabs, no trailing whitespace, Markdown files start with
#)
These checks are designed to be run locally and in CI (workflows can call npm run validate).
These workflows run without AWS credentials.
See functions/items-api/README.md for function-specific details, simple
request/response examples, and an overview of logging and validation.
- Task 1: Terraform structure, S3, DynamoDB, IAM, CloudWatch
- Task 2: Lambda — CRUD handlers (mocked responses), API Gateway, CORS, and IAM
- Task 3: GitHub Actions for validation and build (Terraform & Node.js)
- Add Terraform tests (e.g., using Terratest)
- Add CloudWatch dashboards & alarms for observability (see
MONITORING.md) - Add EventBridge event-driven processors (see
EVENTBRIDGE.md) - Architecture diagram and design notes:
ARCHITECTURE.md
If you'd like, I can now add tests, implement CloudWatch dashboards and alarms, or prepare PR-ready commits. Which should I do next?