From d684e37c3a6fe9066b860f8dba9a008e22a4e042 Mon Sep 17 00:00:00 2001 From: Adam Moussa Date: Wed, 17 Jun 2026 11:44:46 -0400 Subject: [PATCH] Add messages-present alarms on async-invoke DLQs The two async-invoke OnFailure DLQs (payments-processPaymentCsv-async-dlq and payments-processPayrollEmail-async-dlq) had no CloudWatch alarm, so a failed async invocation could sit in the DLQ unnoticed. Add a messages-present alarm for each, mirroring PayrollBatchDLQAlarm exactly: AWS/SQS ApproximateNumberOfMessagesVisible, Maximum, threshold > 0, Period 300, EvaluationPeriods 1, TreatMissingData notBreaching, ALARM-only to the site-alerts SNS topic. --- template.yaml | 42 ++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 42 insertions(+) diff --git a/template.yaml b/template.yaml index e7acb0f..d209385 100644 --- a/template.yaml +++ b/template.yaml @@ -759,6 +759,48 @@ Resources: AlarmActions: - !Sub arn:aws:sns:${AWS::Region}:${AWS::AccountId}:site-alerts + # Messages-present alarms on the async-invoke OnFailure DLQs, mirroring + # PayrollBatchDLQAlarm. Threshold > 0 on the visible-message count, ALARM-only. + ProcessPaymentCsvDLQAlarm: + Type: AWS::CloudWatch::Alarm + Properties: + AlarmName: payments-processPaymentCsv-async-dlq-messages + AlarmDescription: Failed processPaymentCsv async invocations landed in the DLQ + Namespace: AWS/SQS + MetricName: ApproximateNumberOfMessagesVisible + Dimensions: + - Name: QueueName + Value: !GetAtt ProcessPaymentCsvDLQ.QueueName + Statistic: Maximum + Period: 300 + EvaluationPeriods: 1 + Threshold: 0 + ComparisonOperator: GreaterThanThreshold + TreatMissingData: notBreaching + # ALARM-only notification by convention — no OK/recovery action + AlarmActions: + - !Sub arn:aws:sns:${AWS::Region}:${AWS::AccountId}:site-alerts + + ProcessPayrollEmailDLQAlarm: + Type: AWS::CloudWatch::Alarm + Properties: + AlarmName: payments-processPayrollEmail-async-dlq-messages + AlarmDescription: Failed processPayrollEmail async invocations landed in the DLQ + Namespace: AWS/SQS + MetricName: ApproximateNumberOfMessagesVisible + Dimensions: + - Name: QueueName + Value: !GetAtt ProcessPayrollEmailDLQ.QueueName + Statistic: Maximum + Period: 300 + EvaluationPeriods: 1 + Threshold: 0 + ComparisonOperator: GreaterThanThreshold + TreatMissingData: notBreaching + # ALARM-only notification by convention — no OK/recovery action + AlarmActions: + - !Sub arn:aws:sns:${AWS::Region}:${AWS::AccountId}:site-alerts + ProcessPayrollEmailLogGroup: Type: AWS::Logs::LogGroup Properties: