Skip to content

fix(iac/aws): gate migration-failure alarm to unblock deploys - #1130

Merged
cristim merged 1 commit into
feat/multicloud-web-frontendfrom
fix/migration-alarm-deploy-block
Jun 9, 2026
Merged

cristim merged 1 commit into
feat/multicloud-web-frontendfrom
fix/migration-alarm-deploy-block

Conversation

@cristim

@cristim cristim commented Jun 9, 2026 •

Copy link
Copy Markdown
Member

Problem

#1124's migration-failure CloudWatch metric filter (terraform/modules/compute/aws/lambda/migration-alarm.tf) needs logs:PutMetricFilter, which the CI deploy SA (cudly-terraform-deploy/GitHubActions) does not hold. Every terraform apply now 403s at that resource and all deploys fail (the Lambda code updates first, so the app looks deployed while the pipeline is red).

Fix

Gate the metric filter + alarm behind a new enable_migration_alarm variable (default false), so deploys succeed without the permission. This is the bootstrap-vs-runtime IAM split from CLAUDE.md.

To enable the alarm later

Grant logs:PutMetricFilter/DeleteMetricFilter/DescribeMetricFilters to the deploy SA in terraform/environments/aws/ci-cd-permissions/, re-apply that bootstrap (privileged human), then set enable_migration_alarm=true. (Follow-up.)

Verified: terraform fmt clean; pre-commit hooks pass.

Summary by CodeRabbit

Release Notes

New Features

  • Added optional migration alarm monitoring to track and alert on migration failures
  • Users can now enable CloudWatch metric filtering and alerting for migration events through a new configuration option
  • Migration failure monitoring can be controlled per deployment environment

…to unblock deploys

#1124's migration-failure metric filter requires logs:PutMetricFilter, which the
CI deploy SA lacks until the ci-cd-permissions bootstrap grants it, so every
terraform apply 403s and blocks all deploys (bootstrap-vs-runtime IAM split, see
CLAUDE.md CI/CD IAM). Gate the metric filter and alarm behind a new
enable_migration_alarm variable (default false) so deploys succeed; enable it
later by re-applying the bootstrap with the metric-filter permissions and
setting enable_migration_alarm=true.
@cristim cristim added triaged Item has been triaged priority/p1 Next up; this sprint severity/high Significant harm type/bug Defect labels Jun 9, 2026
@coderabbitai

coderabbitai Bot commented Jun 9, 2026 •

Copy link
Copy Markdown
Contributor

Important

Review skipped

Auto reviews are disabled on base/target branches other than the default branch.

Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro

Run ID: 7129d9bc-9daf-460a-a35e-ae779dce04f5

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • ✅ Review completed - (🔄 Check again to review again)
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch fix/migration-alarm-deploy-block

Comment @coderabbitai help to get the list of available commands and usage tips.

@cristim
cristim merged commit ebfeaed into feat/multicloud-web-frontend Jun 9, 2026
3 of 4 checks passed
@cristim
cristim deleted the fix/migration-alarm-deploy-block branch July 27, 2026 11:10
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

priority/p1 Next up; this sprint severity/high Significant harm triaged Item has been triaged type/bug Defect

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant