Both Lambdas and the front-sla-alerts table previously had zero alarm
coverage, so failures or runaway runs went unnoticed until someone
checked logs. Wire a standard alarm set to the shared site-alerts SNS
topic (ALARM-only, TreatMissingData notBreaching) per Wave 1 conventions.
- Lambda Errors + Throttles alarms for front-sla-monitor and
front-user-sync (Sum, threshold 0).
- Lambda Duration alarms (Max, threshold 270000 = 90% of the shared
300s timeout) for both functions.
- DynamoDB ThrottledRequests + SystemErrors alarms on front-sla-alerts.
Document the alarm set in the README.
Adds the seahaven-lambda-execution-boundary policy as a
PermissionsBoundary on all auto-generated Lambda execution
roles via Globals.Function, enabling the cfn-execution-role
scope-down from INFRA-97 to safely allow iam:CreateRole.
No explicit AWS::IAM::Role resources exist in this stack;
the Globals entry covers both SlaMonitorFunction and
UserSyncFunction.
Refs: INFRA-103
Consolidates front-sla-monitor (Python SAM) and google-user-sync
(JavaScript CDK) into a single Python SAM repo with two Lambdas:
front-sla-monitor and front-user-sync.