Add DLQ messages-present alarm for workorder-email-processor (#68)
Some checks failed
Deploy / deploy (push) Has been cancelled

The existing workorder-email-processor-errors alarm fires on any errored
async invocation, but a message only reaches the DLQ after Lambda exhausts
its async retries and gives up — a genuinely dropped work-order email that
the errors alarm alone does not distinguish.

Add an ALARM-only CloudWatch alarm (workorder-email-processor-dlq-messages)
on the EmailProcessorDlq ApproximateNumberOfMessagesVisible metric
(Statistic MAXIMUM, period 5m, evaluationPeriods 1, threshold > 0,
treatMissingData NOT_BREACHING). Routes to the same shared site-alerts SNS
topic via SnsAction, mirroring the errors-alarm construct style.

Refs INFRA-41 / audit H-8.
This commit is contained in:
Adam Moussa 2026-06-17 17:31:16 -04:00 • committed by GitHub
parent 0615aa5b77
commit 35dc32390c
No known key found for this signature in database
GPG key ID: B5690EEEBB952194

View file

@ -265,6 +265,26 @@ class WorkorderIngestStack(Stack):
treat_missing_data=cloudwatch.TreatMissingData.NOT_BREACHING,
).add_alarm_action(cw_actions.SnsAction(alarm_topic))
# --- DLQ messages-present alarm (INFRA-41 / audit H-8) ---
# The errors alarm above fires on any errored invocation, but a message
# only lands in the DLQ after Lambda exhausts its async retries and gives
# up — i.e. a genuinely dropped email. ALARM-only (no OK action) to the
# same shared site-alerts topic. MAXIMUM over a 5-min window so a single
# visible message pages even if it is later consumed/redriven.
email_processor_dlq.metric_approximate_number_of_messages_visible(
period=Duration.minutes(5),
statistic="Maximum",
).create_alarm(
self,
"EmailProcessorDlqMessagesAlarm",
alarm_name="workorder-email-processor-dlq-messages",
alarm_description="workorder-email-processor DLQ has visible messages (dropped emails)",
threshold=0,
evaluation_periods=1,
comparison_operator=cloudwatch.ComparisonOperator.GREATER_THAN_THRESHOLD,
treat_missing_data=cloudwatch.TreatMissingData.NOT_BREACHING,
).add_alarm_action(cw_actions.SnsAction(alarm_topic))
# S3 event notification -> Lambda
email_bucket.add_event_notification(
s3.EventType.OBJECT_CREATED,