* Add CloudWatch alarm coverage for front-integrations
Both Lambdas and the front-sla-alerts table previously had zero alarm
coverage, so failures or runaway runs went unnoticed until someone
checked logs. Wire a standard alarm set to the shared site-alerts SNS
topic (ALARM-only, TreatMissingData notBreaching) per Wave 1 conventions.
- Lambda Errors + Throttles alarms for front-sla-monitor and
front-user-sync (Sum, threshold 0).
- Lambda Duration alarms (Max, threshold 270000 = 90% of the shared
300s timeout) for both functions.
- DynamoDB ThrottledRequests + SystemErrors alarms on front-sla-alerts.
Document the alarm set in the README.
* Fix DynamoDB throttle alarm metric: use Read/WriteThrottleEvents
ThrottledRequests and SystemErrors are not emitted at the TableName-only
dimension (only TableName+Operation), so these table-level alarms would sit
permanently in INSUFFICIENT_DATA and never fire. Replace with
ReadThrottleEvents and WriteThrottleEvents, which AWS/DynamoDB emits at the
TableName dimension.
* Fix README DynamoDB alarm rows to match shipped alarms
Replace stale front-sla-alerts-throttled-requests / -system-errors rows
with the alarms actually shipped: front-sla-alerts-read-throttle
(ReadThrottleEvents) and front-sla-alerts-write-throttle
(WriteThrottleEvents).
Adds the seahaven-lambda-execution-boundary policy as a
PermissionsBoundary on all auto-generated Lambda execution
roles via Globals.Function, enabling the cfn-execution-role
scope-down from INFRA-97 to safely allow iam:CreateRole.
No explicit AWS::IAM::Role resources exist in this stack;
the Globals entry covers both SlaMonitorFunction and
UserSyncFunction.
Refs: INFRA-103
* Add dependency-review caller workflow
Add a pull_request-triggered caller that invokes the org-level
callable-dependency-review workflow to scan dependency changes and
fail on high-severity advisories.
* chore: retrigger checks
* chore: retrigger dep review (post-fix)
* style: ruff format src
Consolidates front-sla-monitor (Python SAM) and google-user-sync
(JavaScript CDK) into a single Python SAM repo with two Lambdas:
front-sla-monitor and front-user-sync.