fix(infra): keep no-logs alarm quiet until UniFi cutover

The new prod unifi-syslog group is empty until devices are re-pointed, so treat_missing_data=breaching would page site-alerts on first apply.
This commit is contained in:
Adam Moussa 2026-09-16 17:25:53 -04:00
parent bc85943536
commit ace0a29e25
No known key found for this signature in database
3 changed files with 16 additions and 1 deletions

View file

@ -61,6 +61,10 @@ First apply uses the hcptf-bootstrap window (exact `StringEquals` trust, never
6. Second manual apply as the scoped role. After live-path proof, seal 6. Second manual apply as the scoped role. After live-path proof, seal
auto-apply on. auto-apply on.
`Syslog-NoIncomingLogs` defaults `treat_missing_data` to `notBreaching` so the
empty prod log group does not page `site-alerts` before UniFi is re-pointed.
After devices deliver to the new EIP, set `no_logs_treat_missing_data=breaching`.
HCP outputs to copy: `public_ip`, `instance_id`, `hcptf_apply_role_arn`, HCP outputs to copy: `public_ip`, `instance_id`, `hcptf_apply_role_arn`,
`hcptf_plan_role_arn`. `hcptf_plan_role_arn`.

View file

@ -8,7 +8,7 @@ resource "aws_cloudwatch_metric_alarm" "no_incoming_logs" {
period = 86400 period = 86400
statistic = "Sum" statistic = "Sum"
threshold = 1 threshold = 1
treat_missing_data = "breaching" treat_missing_data = var.no_logs_treat_missing_data
alarm_actions = [local.site_alerts_arn] alarm_actions = [local.site_alerts_arn]
dimensions = { dimensions = {

View file

@ -9,3 +9,14 @@ variable "ami_id" {
type = string type = string
default = "ami-02c114835b4e7739f" default = "ami-02c114835b4e7739f"
} }
variable "no_logs_treat_missing_data" {
description = "CloudWatch treat_missing_data for Syslog-NoIncomingLogs. Keep notBreaching until UniFi points at the new EIP, then set breaching."
type = string
default = "notBreaching"
validation {
condition = contains(["breaching", "notBreaching", "ignore", "missing"], var.no_logs_treat_missing_data)
error_message = "no_logs_treat_missing_data must be breaching, notBreaching, ignore, or missing."
}
}