feat(exec-aide): CloudWatch alarm coverage (Lambda + DynamoDB + ECS) #59
No reviewers
Labels
No labels
app
bug
ci
compliance
dependencies
docs
documentation
duplicate
enhancement
good first issue
help wanted
infra
invalid
javascript
python
question
wontfix
No milestone
No project
No assignees
1 participant
Due date
No due date set.
Dependencies
No dependencies set.
Reference: adam/exec-aide#59
Loading…
Add table
Reference in a new issue
No description provided.
Delete branch "infra-cloudwatch-alarm-coverage"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Summary
Wave 1 PR H — CloudWatch alarm coverage for the
exec-aideCDK (TypeScript) stack. Adds 14 ALARM-only alarms routed to the sharedsite-alertsSNS topic, mirroring theproposal-systemalarm construct and theseahaven-door-unlock-apisite-alerts import pattern.The
site-alertstopic is imported once at the stack level (sns.Topic.fromTopicArn) and injected into both constructs via props — the same way the DynamoDB table is wired intosocket-mode. Every alarm:SnsAction→site-alerts, no OK / InsufficientData action,treatMissingData: NOT_BREACHING. Names are repo-namespaced kebab-caseexec-aide-<resource>-<signal>.Alarms added
Lambda (fetch-classify, daily-digest, conversation) — 9 alarms:
*-errors(Errors Sum ≥ 1, eval 1)*-throttles(Throttles Sum ≥ 1, eval 1)*-duration(p99, eval 3 / datapoints 2, ~80% of timeout)DynamoDB
exec-aide— 2 alarms:exec-aide-table-throttles(ThrottledRequests)exec-aide-table-system-errors(SystemErrors)ECS
exec-aide-listenerFargate service — 3 alarms:exec-aide-listener-cpu-high(CPU Average > 80%, eval 3 / datapoints 2)exec-aide-listener-memory-high(Memory Average > 80%, eval 3 / datapoints 2)exec-aide-listener-no-running-tasks(RunningTaskCount Min < 1) — gated, see below⚠️ NEEDS ADAM SIGN-OFF
Duration thresholds (p99, eval 3 / datapoints 2, ≈80% of timeout)
exec-aide-fetch-classifyexec-aide-daily-digestexec-aide-conversationContainer Insights cost/config (separate commit
25277f8)exec-aide-listener-no-running-tasksreadsRunningTaskCount, which is only published in theECS/ContainerInsightsnamespace (AWS/ECSdoes not emit it). That commit therefore enables Container Insights on theexec-aidecluster (containerInsightsV2: ENABLED) — a recurring CloudWatch ingestion/storage cost for the cluster. It is isolated to its own commit; the CPU/Memory alarms and all other coverage do not depend on it. Revert that single commit to drop both the cost and the RunningTaskCount alarm.DynamoDB dimension findings
ThrottledRequestsandSystemErrorsare not published at the bareTableNamedimension — AWS keys them by theOperationdimension. CDK confirms this:metricThrottledRequests/metricSystemErrorsare deprecated as "invalid metric." Used the*ForOperationsmath helpers instead. Because an alarm math expression caps at 10 metrics and the default "all operations" set exceeds that (synth failed withTooManyMetricsInMathExpression), the alarms are scoped to the 6 operations this single-table app actually issues (GetItem, PutItem, Query, Scan, UpdateItem, DeleteItem — verified fromsrc/).Validation
npx tsc --noEmit— cleannpx cdk synth— clean; all 14 alarms render with correct thresholds, eval/datapoints,NOT_BREACHING, no OK/INS actions, andAlarmActions = [site-alerts]FargateServicelogical id (SocketModeServiceB6F02D46) is unchanged after assigning it to aconstConfluence map (id 1540098) delta — OUTSTANDING
The "AWS Architecture Map" exec-aide subgraph should gain a CloudWatch alarms node fanning the 3 Lambdas, the
exec-aidetable, and theexec-aide-listenerservice into the sharedsite-alertsSNS topic; annotate thatexec-aide-listener-no-running-tasks+ Container Insights are pending sign-off. Will apply once this PR's approach is confirmed.Notes
No IAM policy/role changes and no Lambda handler-signature changes — the mandatory cross-family review gate does not apply. Per instructions: one PR, base
main, not merged / not deployed.Closing without merge: exec-aide is being deprecated soon, so the alarm suite added here (14 alarms + Container Insights) won't be maintained. Kept as reference on the branch if needed. Per the Wave 1 alarm-coverage rollout decision (2026-06-17).