diff --git a/cdk/wo_stack.py b/cdk/wo_stack.py index 637c0c2..fc8d166 100644 --- a/cdk/wo_stack.py +++ b/cdk/wo_stack.py @@ -265,6 +265,26 @@ class WorkorderIngestStack(Stack): treat_missing_data=cloudwatch.TreatMissingData.NOT_BREACHING, ).add_alarm_action(cw_actions.SnsAction(alarm_topic)) + # --- DLQ messages-present alarm (INFRA-41 / audit H-8) --- + # The errors alarm above fires on any errored invocation, but a message + # only lands in the DLQ after Lambda exhausts its async retries and gives + # up — i.e. a genuinely dropped email. ALARM-only (no OK action) to the + # same shared site-alerts topic. MAXIMUM over a 5-min window so a single + # visible message pages even if it is later consumed/redriven. + email_processor_dlq.metric_approximate_number_of_messages_visible( + period=Duration.minutes(5), + statistic="Maximum", + ).create_alarm( + self, + "EmailProcessorDlqMessagesAlarm", + alarm_name="workorder-email-processor-dlq-messages", + alarm_description="workorder-email-processor DLQ has visible messages (dropped emails)", + threshold=0, + evaluation_periods=1, + comparison_operator=cloudwatch.ComparisonOperator.GREATER_THAN_THRESHOLD, + treat_missing_data=cloudwatch.TreatMissingData.NOT_BREACHING, + ).add_alarm_action(cw_actions.SnsAction(alarm_topic)) + # S3 event notification -> Lambda email_bucket.add_event_notification( s3.EventType.OBJECT_CREATED,