mirror of
https://github.com/Sea-Haven-Industries/front-integrations.git
synced 2026-09-30 16:33:13 +00:00
Some checks are pending
Deploy / deploy (push) Waiting to run
Adds the seahaven-lambda-execution-boundary policy as a PermissionsBoundary on all auto-generated Lambda execution roles via Globals.Function, enabling the cfn-execution-role scope-down from INFRA-97 to safely allow iam:CreateRole. No explicit AWS::IAM::Role resources exist in this stack; the Globals entry covers both SlaMonitorFunction and UserSyncFunction. Refs: INFRA-103
167 lines
5.4 KiB
YAML
167 lines
5.4 KiB
YAML
AWSTemplateFormatVersion: '2010-09-09'
|
|
Transform: AWS::Serverless-2016-10-31
|
|
Description: Front platform integrations — SLA monitoring and Google Workspace user sync
|
|
|
|
Parameters:
|
|
FrontApiTokenSecretArn:
|
|
Type: String
|
|
Description: ARN of the Secrets Manager secret containing the Front API token
|
|
SlackBotTokenSecretArn:
|
|
Type: String
|
|
Description: ARN of the Secrets Manager secret containing the Slack bot token
|
|
GoogleServiceAccountSecretArn:
|
|
Type: String
|
|
Description: ARN of the Secrets Manager secret containing the Google service account JSON key
|
|
SlackAlertChannel:
|
|
Type: String
|
|
Description: Slack channel ID for the front-sla-alerts channel
|
|
AdamEmail:
|
|
Type: String
|
|
Default: adam@seahavenind.com
|
|
Description: Email address for Tier 2 escalation
|
|
AckSlaMinutes:
|
|
Type: Number
|
|
Default: 60
|
|
Description: Business minutes before Tier 1 alert (1 hour)
|
|
ActionSlaMinutes:
|
|
Type: Number
|
|
Default: 1440
|
|
Description: Business minutes before Tier 2 alert (1 business day)
|
|
MonitorInboxes:
|
|
Type: String
|
|
Default: "Triage,California,West Coast,Central,East Coast,Vendors"
|
|
Description: Comma-separated inbox names to monitor (empty = all shared)
|
|
SlaMonitorStartDate:
|
|
Type: String
|
|
Default: "2026-05-14"
|
|
Description: Date when SLA monitoring begins (YYYY-MM-DD, Eastern time)
|
|
GoogleAdminEmail:
|
|
Type: String
|
|
Default: adam@seahavenind.com
|
|
Description: Google Workspace admin email to impersonate for Directory API
|
|
GoogleOrgUnits:
|
|
Type: String
|
|
Default: "/Office/Scheduling,/Office/Operations"
|
|
Description: Comma-separated Google Workspace org unit paths to sync
|
|
|
|
Globals:
|
|
Function:
|
|
Runtime: python3.12
|
|
Timeout: 300
|
|
MemorySize: 256
|
|
Architectures:
|
|
- arm64
|
|
PermissionsBoundary: arn:aws:iam::328440206208:policy/seahaven-lambda-execution-boundary
|
|
|
|
Resources:
|
|
# ---------------------------------------------------------------------------
|
|
# SLA Monitor
|
|
# ---------------------------------------------------------------------------
|
|
AlertsTable:
|
|
Type: AWS::DynamoDB::Table
|
|
Properties:
|
|
TableName: front-sla-alerts
|
|
BillingMode: PAY_PER_REQUEST
|
|
AttributeDefinitions:
|
|
- AttributeName: conversationId
|
|
AttributeType: S
|
|
KeySchema:
|
|
- AttributeName: conversationId
|
|
KeyType: HASH
|
|
TimeToLiveSpecification:
|
|
AttributeName: ttl
|
|
Enabled: true
|
|
|
|
SlaMonitorLogGroup:
|
|
Type: AWS::Logs::LogGroup
|
|
Properties:
|
|
LogGroupName: /aws/lambda/front-sla-monitor
|
|
RetentionInDays: 60
|
|
|
|
SlaMonitorFunction:
|
|
Type: AWS::Serverless::Function
|
|
DependsOn: SlaMonitorLogGroup
|
|
Properties:
|
|
FunctionName: front-sla-monitor
|
|
Handler: app.handler
|
|
CodeUri: src/sla_monitor/
|
|
Environment:
|
|
Variables:
|
|
FRONT_SECRET_NAME: !Ref FrontApiTokenSecretArn
|
|
SLACK_SECRET_NAME: !Ref SlackBotTokenSecretArn
|
|
SLACK_ALERT_CHANNEL: !Ref SlackAlertChannel
|
|
ADAM_EMAIL: !Ref AdamEmail
|
|
TABLE_NAME: !Ref AlertsTable
|
|
ACK_SLA_MINUTES: !Ref AckSlaMinutes
|
|
ACTION_SLA_MINUTES: !Ref ActionSlaMinutes
|
|
MONITOR_INBOXES: !Ref MonitorInboxes
|
|
START_DATE: !Ref SlaMonitorStartDate
|
|
Policies:
|
|
- DynamoDBCrudPolicy:
|
|
TableName: !Ref AlertsTable
|
|
- Version: '2012-10-17'
|
|
Statement:
|
|
- Effect: Allow
|
|
Action:
|
|
- secretsmanager:GetSecretValue
|
|
Resource:
|
|
- !Ref FrontApiTokenSecretArn
|
|
- !Ref SlackBotTokenSecretArn
|
|
Events:
|
|
SlaCheck:
|
|
Type: Schedule
|
|
Properties:
|
|
Schedule: cron(0/15 12-22 ? * MON-FRI *)
|
|
Description: Check Front conversations for SLA breaches every 15 min during business hours
|
|
Enabled: true
|
|
|
|
# ---------------------------------------------------------------------------
|
|
# Google User Sync
|
|
# ---------------------------------------------------------------------------
|
|
UserSyncLogGroup:
|
|
Type: AWS::Logs::LogGroup
|
|
Properties:
|
|
LogGroupName: /aws/lambda/front-user-sync
|
|
RetentionInDays: 60
|
|
|
|
UserSyncFunction:
|
|
Type: AWS::Serverless::Function
|
|
DependsOn: UserSyncLogGroup
|
|
Properties:
|
|
FunctionName: front-user-sync
|
|
Handler: app.handler
|
|
CodeUri: src/user_sync/
|
|
Timeout: 300
|
|
Environment:
|
|
Variables:
|
|
GOOGLE_SECRET_NAME: !Ref GoogleServiceAccountSecretArn
|
|
FRONT_SECRET_NAME: !Ref FrontApiTokenSecretArn
|
|
GOOGLE_ADMIN_EMAIL: !Ref GoogleAdminEmail
|
|
GOOGLE_OUS: !Ref GoogleOrgUnits
|
|
Policies:
|
|
- Version: '2012-10-17'
|
|
Statement:
|
|
- Effect: Allow
|
|
Action:
|
|
- secretsmanager:GetSecretValue
|
|
Resource:
|
|
- !Ref GoogleServiceAccountSecretArn
|
|
- !Ref FrontApiTokenSecretArn
|
|
Events:
|
|
DailySync:
|
|
Type: Schedule
|
|
Properties:
|
|
Schedule: cron(0 11 ? * MON-FRI *)
|
|
Description: Sync Google Workspace user profiles to Front daily at 6 AM ET
|
|
Enabled: true
|
|
|
|
Outputs:
|
|
SlaMonitorFunctionArn:
|
|
Description: Front SLA Monitor Lambda ARN
|
|
Value: !GetAtt SlaMonitorFunction.Arn
|
|
UserSyncFunctionArn:
|
|
Description: Front User Sync Lambda ARN
|
|
Value: !GetAtt UserSyncFunction.Arn
|
|
AlertsTableName:
|
|
Description: DynamoDB alerts table name
|
|
Value: !Ref AlertsTable
|