# front-sla-monitor Scheduled Lambda that monitors Front conversations for SLA breaches and sends tiered Slack alerts. Runs every 15 minutes on weekdays. ## SLA Rules | Tier | Threshold | Action | |---|---|---| | 1 | 1 business hour without reply | Slack DM the assignee, or post to #front-sla-alerts if unassigned | | 2 | 1 business day without reply | Slack DM Adam | Business time counts weekday hours only (Mon-Fri, Eastern time). The SLA clock pauses on Saturday and Sunday. ## Architecture ``` EventBridge (every 15 min, Mon-Fri) │ ▼ Lambda (Python 3.12, arm64) │ ├── Secrets Manager → front-sla-monitor/front-api-token ├── Secrets Manager → front-sla-monitor/slack-bot-token │ ├── GET Front API /inboxes → list shared inboxes ├── GET Front API /inboxes/{id}/conversations → open conversations │ ├── DynamoDB (front-sla-alerts) → dedup: skip already-alerted conversations │ ├── Tier 1 → Slack DM assignee or #front-sla-alerts └── Tier 2 → Slack DM Adam ``` ## AWS Resources - **Stack:** `front-sla-monitor` (SAM, us-east-1) - **Lambda:** `front-sla-monitor` — Python 3.12, arm64, 128 MB, 120s timeout, 60-day log retention - **DynamoDB:** `front-sla-alerts` — tracks alert history per conversation, 7-day TTL - **EventBridge:** `cron(0/15 * ? * MON-FRI *)` — every 15 min on weekdays ## Setup ### 1. Create the Slack App 1. Go to https://api.slack.com/apps and create **Front SLA Monitor** 2. Add Bot Token Scopes: `chat:write`, `users:read.email` 3. Install the app to your workspace and copy the Bot User OAuth Token 4. Create the `#front-sla-alerts` channel and invite the bot (`/invite @Front SLA Monitor`) 5. Copy the channel ID (right-click channel name > View channel details) ### 2. Create a Front API Token 1. Front > Settings > Developers > API tokens 2. Create a token with conversation read scope 3. Copy the token ### 3. Store Secrets in AWS ```bash aws secretsmanager create-secret \ --name "front-sla-monitor/front-api-token" \ --secret-string "YOUR_FRONT_API_TOKEN" \ --region us-east-1 aws secretsmanager create-secret \ --name "front-sla-monitor/slack-bot-token" \ --secret-string "xoxb-YOUR-SLACK-BOT-TOKEN" \ --region us-east-1 ``` ### 4. Deploy ```bash sam build sam deploy --guided ``` Or push to `main` to trigger the GitHub Actions deploy workflow. ### 5. GitHub Actions Secrets | Secret | Value | |---|---| | `AWS_DEPLOY_ROLE_ARN` | Org-wide OIDC deploy role (already configured) | | `SAM_PARAMETER_OVERRIDES` | `FrontApiTokenSecretArn=arn:... SlackBotTokenSecretArn=arn:... SlackAlertChannel=CXXXXXXXXXX` | ## Manual Testing ```bash aws lambda invoke --function-name front-sla-monitor --payload '{}' /dev/stdout --region us-east-1 ``` Check logs: ```bash aws logs tail /aws/lambda/front-sla-monitor --follow --region us-east-1 ``` ## Configuration | Environment Variable | Default | Description | |---|---|---| | `ACK_SLA_MINUTES` | 60 | Business minutes before Tier 1 alert | | `ACTION_SLA_MINUTES` | 1440 | Business minutes before Tier 2 alert | | `ADAM_EMAIL` | adam@seahavenind.com | Tier 2 escalation recipient | | `SLACK_ALERT_CHANNEL` | — | Channel ID for broadcast alerts |