diff --git a/template.yaml b/template.yaml index c6573ce..b9b643e 100644 --- a/template.yaml +++ b/template.yaml @@ -250,6 +250,65 @@ Resources: AlarmActions: - !Sub arn:aws:sns:${AWS::Region}:${AWS::AccountId}:site-alerts + # Async-invoke OnFailure DLQs (INFRA-41 / H-8). Reconciles the interim + # CLI-created queues into CloudFormation. Names are CFN-generated to avoid + # colliding with the live interim payments--dlq queues (deleted after + # this deploy). 14-day retention mirrors the payments-payroll-batch DLQ so a + # Friday failure survives the weekend. + # Distinct -async-dlq name (not the live interim payments--dlq) so this + # CFN queue does not collide with the queue being deleted post-deploy. + ProcessPaymentCsvDLQ: + Type: AWS::SQS::Queue + Properties: + QueueName: payments-processPaymentCsv-async-dlq + MessageRetentionPeriod: 1209600 # 14d, matches payments-payroll-batch-dlq + + ProcessPayrollEmailDLQ: + Type: AWS::SQS::Queue + Properties: + QueueName: payments-processPayrollEmail-async-dlq + MessageRetentionPeriod: 1209600 # 14d, matches payments-payroll-batch-dlq + + # ALARM-only Lambda Errors alarms (INFRA-41 / H-8). Threshold > 0 on the + # Errors Sum, no OK/recovery action by convention. + ProcessPaymentCsvErrorsAlarm: + Type: AWS::CloudWatch::Alarm + Properties: + AlarmName: payments-processPaymentCsv-errors + AlarmDescription: payments-processPaymentCsv invocation errors + Namespace: AWS/Lambda + MetricName: Errors + Dimensions: + - Name: FunctionName + Value: !Ref ProcessPaymentCsvFunction + Statistic: Sum + Period: 300 + EvaluationPeriods: 1 + Threshold: 0 + ComparisonOperator: GreaterThanThreshold + TreatMissingData: notBreaching + AlarmActions: + - !Sub arn:aws:sns:${AWS::Region}:${AWS::AccountId}:site-alerts + + ProcessPayrollEmailErrorsAlarm: + Type: AWS::CloudWatch::Alarm + Properties: + AlarmName: payments-processPayrollEmail-errors + AlarmDescription: payments-processPayrollEmail invocation errors + Namespace: AWS/Lambda + MetricName: Errors + Dimensions: + - Name: FunctionName + Value: !Ref ProcessPayrollEmailFunction + Statistic: Sum + Period: 300 + EvaluationPeriods: 1 + Threshold: 0 + ComparisonOperator: GreaterThanThreshold + TreatMissingData: notBreaching + AlarmActions: + - !Sub arn:aws:sns:${AWS::Region}:${AWS::AccountId}:site-alerts + ProcessPayrollEmailLogGroup: Type: AWS::Logs::LogGroup Properties: @@ -292,6 +351,13 @@ Resources: FunctionName: payments-processPayrollEmail Handler: src/processPayrollEmail.handler Timeout: 60 + EventInvokeConfig: + MaximumRetryAttempts: 2 + MaximumEventAgeInSeconds: 21600 + DestinationConfig: + OnFailure: + Type: SQS + Destination: !GetAtt ProcessPayrollEmailDLQ.Arn Environment: Variables: SLACK_BOT_TOKEN_SECRET_NAME: payments-dashboard/slack-bot-token @@ -334,6 +400,13 @@ Resources: FunctionName: payments-processPaymentCsv Handler: src/processPaymentCsv.handler Timeout: 120 + EventInvokeConfig: + MaximumRetryAttempts: 2 + MaximumEventAgeInSeconds: 21600 + DestinationConfig: + OnFailure: + Type: SQS + Destination: !GetAtt ProcessPaymentCsvDLQ.Arn Environment: Variables: BOA_BASE_URL: https://api.bofa.com