This package provides a CDK construct facilitating the connection between a lambda and a Documentdb cluster.
- Instanciate
DocumentdbClusterLambdaConnectionin your stack CDK, by specifying at least the master user for accessing Documentdb. You can also specify the vpc you want your clusters in (otherwise the construct will provision one):
constdocumentdbCluster=newDocumentdbClusterLambdaConnection(this,"MyDocumentDbConnection",masterUser: {username: "yourUsername",secretName: "documentdbSecretName"});- Define the lambdas that will communicate with Documentdb in the same VPC:
constlambda1=newNodejsFunction(this,"MyFirstLambda",{vpc: documentdbCluster.vpc,
...restOfLambdaConfiguration,});constlambda2=newNodejsFunction(this,"MySecondLambda",{vpc: documentdbCluster.vpc,
...restOfLambdaConfiguration,});- Give your lambdas the rights to communicate with your Documentdb cluster:
documentdbCluster.allowCommunication(lambda1,lambda2);- In the lambda handlers, retrieve the database secrets from SecretsManager, and use them with the Mongo client:
import{SecretsManager}from"aws-sdk";import{MongoClient}from"mongodb";exportconstmain=async()=>{constdbClient=awaitconnectToDatabase();constdb=dbClient.db("db");awaitdb.collection("collection").insertOne({property: "value"});return{statusCode: 200,body: "...",};};constconnectToDatabase=async(): Promise<MongoClient>=>{if(cachedDb){returnPromise.resolve(cachedDb);}constsecretsManager=newSecretsManager({region: "eu-west-1"});constsecret=awaitsecretsManager.getSecretValue({SecretId: "documentdbSecretName"}).promise();constsecretString=secret.SecretString;if(secretString===undefined){thrownewError();}constdocdbsecret=JSON.parse(secretString)as{password: string;host: string;username: string;};const{ password, host, username }=docdbsecret;db=awaitMongoClient.connect(`mongodb://${encodeURIComponent(username)}:${encodeURIComponent(password)}@${host}`,{ssl: true,sslCA: "/opt/rds-combined-ca-bundle.pem",// https://docs.aws.amazon.com/documentdb/latest/developerguide/ca_cert_rotation.html#ca_cert_rotation-updating_application_step1retryWrites: false,connectTimeoutMS: 3000,});cachedDb=db;returncachedDb;};Built by
