Add CloudWatch alarm coverage (MonitoringConstruct) #61

Closed
amoussa1229 wants to merge 3 commits from infra-cw-alarm-coverage into main

3 commits

Author SHA1 Message Date
090f2a1f12 Document CloudWatch alarm coverage in README 2026-06-17 13:58:12 -04:00
ea173a0966 Enable Container Insights + RunningTaskCount alarm (NEEDS ADAM SIGN-OFF)
Enable Container Insights on the seahaven-socket-mode ECS cluster and add the
seahaven-socket-mode-running-tasks alarm (fires when running tasks < 1 against
desiredCount=1). RunningTaskCount is only published with Container Insights
enabled, which adds CloudWatch metric + log-ingestion cost.

This is isolated in its own commit so it can be dropped if the cost/config
change is declined — revert this commit (cluster containerInsightsV2 +
enableRunningTaskAlarm flag) and the rest of the alarm coverage is unaffected.
2026-06-17 13:57:48 -04:00
c28d5b1170 Add CloudWatch alarm coverage via MonitoringConstruct
Add a MonitoringConstruct (lib/constructs/monitoring.ts) wiring CloudWatch
alarms to the shared site-alerts SNS topic for the seahaven-slack-bot stack.
Every alarm uses an SNS alarm action only (no OK action) and treats missing
data as NOT_BREACHING; alarm names are repo-namespaced kebab-case.

Coverage:
- Lambda (9 fns): Errors, Throttles, Duration (p99, eval3/dp2, ~80% of timeout)
- DynamoDB (seahaven-conversations, seahaven-unanswered-questions):
  ThrottledRequests + SystemErrors via the per-operations metric-math helpers
  (the bare TableName-only helpers are deprecated/invalid); operations scoped
  to 6 CRUD ops to stay under the 10-metric alarm-math cap
- API Gateway v2 (seahaven-slack-webhook): 5xx, 4xx, Latency (ApiId dimension)
- ECS Fargate (seahaven-socket-mode): CPU + Memory utilization (AWS/ECS)

Expose qbo-oauth Lambda and the ECS cluster/service as public readonly handles
without changing logical IDs. RunningTaskCount alarm is gated off pending
Container Insights sign-off (separate commit).
2026-06-17 13:57:07 -04:00