/** * CDK output for the serverless (Lambda + OTel extension) estate. * * Emits a single self-contained TypeScript construct file the customer * drops into their own CDK repository — reviewable, forkable, owned by * them. Nothing here executes CDK; this module is a code EMITTER, the * same shape as `forwarderWriteTerraform()` on the Terraform side. The * Terraform path stays; this adds the CDK one. * * Three concerns, one construct file: * 1. The engine in the execution environment — a LayerVersion reference * plus a per-function attach helper (layer + env vars). * 2. The Coralogix TCO policy — a Lambda-backed custom resource doing * READ-MODIFY-WRITE against the real (recovered-from-the-wire) API: * `PUT https://api..coralogix.com/mgmt/openapi/5/dataplans/log-policies/v1` * on the REGIONAL host, which is an ATOMIC WHOLE-LIST OVERWRITE. A * blind PUT clobbers policies the customer created by hand, so the * resource merges by policy name. See `coralogixTcoApiContract()`. * 3. The CloudWatch remainder — SubscriptionFilter per named log group * targeting the receive-role Lambda, plus an EventBridge rule on * `CreateLogGroup` driving a small subscriber function so NEW log * groups are covered by rule, not by remembering. */ export interface LambdaEstateCdkParams { /** AWS region of the estate (used in comments/defaults only). */ region: string; /** Coralogix regional API host segment, e.g. `us2` -> api.us2.coralogix.com. */ coralogixRegion?: string; /** ARN of the engine extension layer once published. Placeholder until then. */ engineLayerArn?: string; /** Log-group name prefix that the auto-subscription rule covers. */ logGroupPrefix?: string; /** subsystem/routeState value the TCO policy tiers down. Default `tier_down`. */ tierDownRoute?: string; } export interface CdkRecipe { language: 'typescript'; /** The construct file, ready to drop into the customer's CDK repo. */ body: string; note: string; prerequisites: string[]; } export declare function lambdaEstateCdkConstruct(p: LambdaEstateCdkParams): CdkRecipe;