* feat(terraform): migrate front-integrations to HCP Terraform
Freeze SAM CD and add Terraform for seahaven-prod (Lambdas, DynamoDB,
EventBridge, alarms) so HCP becomes the sole deploy path. Include prod
secret ARNs in the tfvars example for workspace wiring.
* fix(terraform): reject symlink sources in Lambda package build
The README described the deployed AWS resources but never mentioned
template.yaml itself, the SAM project layout, the global function
defaults, the full parameter set, or the stack outputs. Add a
Project Structure section and an Infrastructure section so the
template.yaml infrastructure-as-code component is documented
accurately.
* Add CloudWatch alarm coverage for front-integrations
Both Lambdas and the front-sla-alerts table previously had zero alarm
coverage, so failures or runaway runs went unnoticed until someone
checked logs. Wire a standard alarm set to the shared site-alerts SNS
topic (ALARM-only, TreatMissingData notBreaching) per Wave 1 conventions.
- Lambda Errors + Throttles alarms for front-sla-monitor and
front-user-sync (Sum, threshold 0).
- Lambda Duration alarms (Max, threshold 270000 = 90% of the shared
300s timeout) for both functions.
- DynamoDB ThrottledRequests + SystemErrors alarms on front-sla-alerts.
Document the alarm set in the README.
* Fix DynamoDB throttle alarm metric: use Read/WriteThrottleEvents
ThrottledRequests and SystemErrors are not emitted at the TableName-only
dimension (only TableName+Operation), so these table-level alarms would sit
permanently in INSUFFICIENT_DATA and never fire. Replace with
ReadThrottleEvents and WriteThrottleEvents, which AWS/DynamoDB emits at the
TableName dimension.
* Fix README DynamoDB alarm rows to match shipped alarms
Replace stale front-sla-alerts-throttled-requests / -system-errors rows
with the alarms actually shipped: front-sla-alerts-read-throttle
(ReadThrottleEvents) and front-sla-alerts-write-throttle
(WriteThrottleEvents).
Consolidates front-sla-monitor (Python SAM) and google-user-sync
(JavaScript CDK) into a single Python SAM repo with two Lambdas:
front-sla-monitor and front-user-sync.