From 35dc32390cd9e9312fcb0ce0bdd65aca51e7bc4d Mon Sep 17 00:00:00 2001 From: Adam Moussa <166072409+amoussa1229@users.noreply.github.com> Date: Wed, 17 Jun 2026 17:31:16 -0400 Subject: [PATCH] Add DLQ messages-present alarm for workorder-email-processor (#68) MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit The existing workorder-email-processor-errors alarm fires on any errored async invocation, but a message only reaches the DLQ after Lambda exhausts its async retries and gives up — a genuinely dropped work-order email that the errors alarm alone does not distinguish. Add an ALARM-only CloudWatch alarm (workorder-email-processor-dlq-messages) on the EmailProcessorDlq ApproximateNumberOfMessagesVisible metric (Statistic MAXIMUM, period 5m, evaluationPeriods 1, threshold > 0, treatMissingData NOT_BREACHING). Routes to the same shared site-alerts SNS topic via SnsAction, mirroring the errors-alarm construct style. Refs INFRA-41 / audit H-8. --- cdk/wo_stack.py | 20 ++++++++++++++++++++ 1 file changed, 20 insertions(+) diff --git a/cdk/wo_stack.py b/cdk/wo_stack.py index 637c0c2..fc8d166 100644 --- a/cdk/wo_stack.py +++ b/cdk/wo_stack.py @@ -265,6 +265,26 @@ class WorkorderIngestStack(Stack): treat_missing_data=cloudwatch.TreatMissingData.NOT_BREACHING, ).add_alarm_action(cw_actions.SnsAction(alarm_topic)) + # --- DLQ messages-present alarm (INFRA-41 / audit H-8) --- + # The errors alarm above fires on any errored invocation, but a message + # only lands in the DLQ after Lambda exhausts its async retries and gives + # up — i.e. a genuinely dropped email. ALARM-only (no OK action) to the + # same shared site-alerts topic. MAXIMUM over a 5-min window so a single + # visible message pages even if it is later consumed/redriven. + email_processor_dlq.metric_approximate_number_of_messages_visible( + period=Duration.minutes(5), + statistic="Maximum", + ).create_alarm( + self, + "EmailProcessorDlqMessagesAlarm", + alarm_name="workorder-email-processor-dlq-messages", + alarm_description="workorder-email-processor DLQ has visible messages (dropped emails)", + threshold=0, + evaluation_periods=1, + comparison_operator=cloudwatch.ComparisonOperator.GREATER_THAN_THRESHOLD, + treat_missing_data=cloudwatch.TreatMissingData.NOT_BREACHING, + ).add_alarm_action(cw_actions.SnsAction(alarm_topic)) + # S3 event notification -> Lambda email_bucket.add_event_notification( s3.EventType.OBJECT_CREATED,