AWSTemplateFormatVersion: '2010-09-09' Transform: AWS::Serverless-2016-10-31 Description: Front SLA Monitor - Tiered Slack alerts for conversation SLA breaches Parameters: FrontApiTokenSecretArn: Type: String Description: ARN of the Secrets Manager secret containing the Front API token SlackBotTokenSecretArn: Type: String Description: ARN of the Secrets Manager secret containing the Slack bot token SlackAlertChannel: Type: String Description: Slack channel ID for the front-sla-alerts channel AdamEmail: Type: String Default: adam@seahavenind.com Description: Email address for Tier 2 escalation AckSlaMinutes: Type: Number Default: 60 Description: Business minutes before Tier 1 alert (1 hour) ActionSlaMinutes: Type: Number Default: 1440 Description: Business minutes before Tier 2 alert (1 business day) MonitorInboxes: Type: String Default: "Triage,California,West Coast,Central,East Coast,Vendors" Description: Comma-separated inbox names to monitor (empty = all shared) StartDate: Type: String Default: "2026-05-14" Description: Date when monitoring begins (YYYY-MM-DD, Eastern time) Globals: Function: Runtime: python3.12 Timeout: 300 MemorySize: 128 Architectures: - arm64 Resources: AlertsTable: Type: AWS::DynamoDB::Table Properties: TableName: front-sla-alerts BillingMode: PAY_PER_REQUEST AttributeDefinitions: - AttributeName: conversationId AttributeType: S KeySchema: - AttributeName: conversationId KeyType: HASH TimeToLiveSpecification: AttributeName: ttl Enabled: true MonitorLogGroup: Type: AWS::Logs::LogGroup Properties: LogGroupName: /aws/lambda/front-sla-monitor RetentionInDays: 60 MonitorFunction: Type: AWS::Serverless::Function DependsOn: MonitorLogGroup Properties: FunctionName: front-sla-monitor Handler: app.handler CodeUri: src/monitor/ Environment: Variables: FRONT_SECRET_NAME: !Ref FrontApiTokenSecretArn SLACK_SECRET_NAME: !Ref SlackBotTokenSecretArn SLACK_ALERT_CHANNEL: !Ref SlackAlertChannel ADAM_EMAIL: !Ref AdamEmail TABLE_NAME: !Ref AlertsTable ACK_SLA_MINUTES: !Ref AckSlaMinutes ACTION_SLA_MINUTES: !Ref ActionSlaMinutes MONITOR_INBOXES: !Ref MonitorInboxes START_DATE: !Ref StartDate Policies: - DynamoDBCrudPolicy: TableName: !Ref AlertsTable - Version: '2012-10-17' Statement: - Effect: Allow Action: - secretsmanager:GetSecretValue Resource: - !Ref FrontApiTokenSecretArn - !Ref SlackBotTokenSecretArn Events: SlaCheck: Type: Schedule Properties: Schedule: cron(0/15 12-22 ? * MON-FRI *) Description: Check Front conversations for SLA breaches every 15 min during business hours Enabled: true Outputs: MonitorFunctionArn: Description: Front SLA Monitor Lambda ARN Value: !GetAtt MonitorFunction.Arn AlertsTableName: Description: DynamoDB alerts table name Value: !Ref AlertsTable