Add CloudWatch alarm coverage (MonitoringConstruct) #61
No reviewers
Labels
No labels
app
bug
ci
compliance
dependencies
docker
docs
documentation
duplicate
enhancement
good first issue
help wanted
infra
invalid
javascript
question
wontfix
No milestone
No project
No assignees
1 participant
Due date
No due date set.
Dependencies
No dependencies set.
Reference: adam/seahaven-slack-bot#61
Loading…
Add table
Reference in a new issue
No description provided.
Delete branch "infra-cw-alarm-coverage"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Summary
Adds CloudWatch alarm coverage for the
seahaven-slack-botCDK stack via a newMonitoringConstruct(lib/constructs/monitoring.ts) wired into the stack. Every alarm:site-alertstopic (arn:aws:sns:us-east-1:328440206208:site-alerts, imported once)NOT_BREACHINGseahaven-<fn>-<signal>36 alarms synthesize cleanly (
npx tsc --noEmit+cdk synthboth pass).Alarm coverage
seahaven-conversations,seahaven-unanswered-questionsseahaven-slack-webhookApiIddim, v2 metric names = 3 alarmsseahaven-socket-modeAWS/ECS(always) + RunningTaskCount (<1, gated) = 3 alarmsExposes
qbo-oauthLambda and the ECS cluster/service aspublic readonlyhandles without changing any logical IDs.Commits
c28d5b1— base alarm coverage (Lambda + DynamoDB + API Gateway + ECS CPU/Mem). No cost/config impact.ea173a0— NEEDS ADAM SIGN-OFF (cost/config) — enables Container Insights on theseahaven-socket-modecluster + adds therunning-tasksalarm. Isolated so it can be dropped if declined.090f2a1— README monitoring section.⚠️ NEEDS ADAM SIGN-OFF
1. Duration thresholds (p99, ~80% of each function's timeout)
2. Container Insights (cost/config) — commit
ea173a0RunningTaskCountis only published when Container Insights is enabled on the cluster, which adds CloudWatch metric + log-ingestion cost. Commit 2 enablescontainerInsightsV2: ENABLEDon theseahaven-socket-modecluster and turns on therunning-tasksalarm. To decline: drop commitea173a0— the CPU/Memory alarms (commit 1) use the standardAWS/ECSnamespace and are unaffected.DynamoDB dimension findings
ThrottledRequestsandSystemErrorshave no validTableName-only aggregate — CDK's baremetricThrottledRequests/metricSystemErrorshelpers are deprecated/invalid. The alarms use the per-operations metric-math helpers (metricThrottledRequestsForOperations/metricSystemErrorsForOperations), which build math expressions across operations at theTableNamedimension.CloudWatch caps an alarm math expression at 10 metrics; DynamoDB defines 14 operations, so the operation set is scoped to the 6 CRUD operations these tables use: GetItem, PutItem, UpdateItem, DeleteItem, Query, BatchWriteItem. (Confirmed via
cdk synth: each DDB alarm = 6-metric math,AWS/DynamoDBnamespace,TableNamedimension.)Note: neither table currently emits these metrics (verified via
cloudwatch list-metrics) — expected, as error/throttle metrics only appear once an error/throttle occurs.NOT_BREACHINGkeeps the alarms OK until then.Confluence map (id 1540098) delta
The AWS Architecture Map "seahaven-slack-bot" subgraph should note the new monitoring layer: a
MonitoringConstructemitting 36 CloudWatch alarms →site-alertsSNS topic. If commit 2 is accepted, also note Container Insights enabled on theseahaven-socket-modecluster. (Documentation update outstanding — to be applied once the PR is merged and the Container Insights decision is made.)Not deployed / not merged
Per Wave 1 rules: one PR, base
main, no merge/deploy.Closing without merge: seahaven-slack-bot is being deprecated soon, so the alarm suite added here (36 alarms + Container Insights) won't be maintained. Kept as reference on the branch if needed. Per the Wave 1 alarm-coverage rollout decision (2026-06-17).