Commit graph

6 commits

Author SHA1 Message Date
Adam Moussa
7bbdbabe3a
feat(terraform): migrate front-integrations to HCP Terraform (PLAT-72) (#41)
* feat(terraform): migrate front-integrations to HCP Terraform

Freeze SAM CD and add Terraform for seahaven-prod (Lambdas, DynamoDB,
EventBridge, alarms) so HCP becomes the sole deploy path. Include prod
secret ARNs in the tfvars example for workspace wiring.

* fix(terraform): reject symlink sources in Lambda package build
2026-08-05 18:48:16 -04:00
Adam Moussa
4506e3cbf7
Document SAM template as IaC component in README (#23)
Some checks failed
Deploy / deploy (push) Has been cancelled
The README described the deployed AWS resources but never mentioned
template.yaml itself, the SAM project layout, the global function
defaults, the full parameter set, or the stack outputs. Add a
Project Structure section and an Infrastructure section so the
template.yaml infrastructure-as-code component is documented
accurately.
2026-07-10 16:07:12 -04:00
Adam Moussa
f6de2b2e6f
docs: link Confluence AWS Architecture Map (INFRA-53) (#16)
Some checks are pending
Deploy / deploy (push) Waiting to run
2026-07-06 17:44:07 -04:00
Adam Moussa
7dcd2d7ccc
Add CloudWatch alarm coverage for front-integrations (#11)
Some checks failed
Deploy / deploy (push) Has been cancelled
* Add CloudWatch alarm coverage for front-integrations

Both Lambdas and the front-sla-alerts table previously had zero alarm
coverage, so failures or runaway runs went unnoticed until someone
checked logs. Wire a standard alarm set to the shared site-alerts SNS
topic (ALARM-only, TreatMissingData notBreaching) per Wave 1 conventions.

- Lambda Errors + Throttles alarms for front-sla-monitor and
  front-user-sync (Sum, threshold 0).
- Lambda Duration alarms (Max, threshold 270000 = 90% of the shared
  300s timeout) for both functions.
- DynamoDB ThrottledRequests + SystemErrors alarms on front-sla-alerts.

Document the alarm set in the README.

* Fix DynamoDB throttle alarm metric: use Read/WriteThrottleEvents

ThrottledRequests and SystemErrors are not emitted at the TableName-only
dimension (only TableName+Operation), so these table-level alarms would sit
permanently in INSUFFICIENT_DATA and never fire. Replace with
ReadThrottleEvents and WriteThrottleEvents, which AWS/DynamoDB emits at the
TableName dimension.

* Fix README DynamoDB alarm rows to match shipped alarms

Replace stale front-sla-alerts-throttled-requests / -system-errors rows
with the alarms actually shipped: front-sla-alerts-read-throttle
(ReadThrottleEvents) and front-sla-alerts-write-throttle
(WriteThrottleEvents).
2026-06-17 14:45:58 -04:00
Adam Moussa
2bd78abd9b
Repo hygiene: PR labeler + README badges (INFRA-56/57) (#8)
Some checks failed
Deploy / deploy (push) Has been cancelled
2026-06-11 14:13:40 -04:00
Adam Moussa
899f07d09c Add unified Front integrations SAM stack
Consolidates front-sla-monitor (Python SAM) and google-user-sync
(JavaScript CDK) into a single Python SAM repo with two Lambdas:
front-sla-monitor and front-user-sync.
2026-05-12 11:24:41 -04:00