Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
13 changes: 11 additions & 2 deletions terraform/modules/compute/aws/lambda/migration-alarm.tf
Original file line number Diff line number Diff line change
Expand Up @@ -22,6 +22,13 @@
# inventing new SNS notification infrastructure here.

resource "aws_cloudwatch_log_metric_filter" "migration_failed" {
# Gated off by default. Creating a metric filter needs logs:PutMetricFilter,
# which the CI deploy SA does not hold until the ci-cd-permissions bootstrap
# grants it (root CLAUDE.md "CI/CD IAM" bootstrap-vs-runtime split). Leaving
# this ungated 403s every terraform apply and blocks all deploys. Set
# enable_migration_alarm=true only after re-applying the bootstrap.
count = var.enable_migration_alarm ? 1 : 0

name = "${var.stack_name}-migration-failed"
log_group_name = aws_cloudwatch_log_group.lambda.name

Expand All @@ -38,11 +45,13 @@ resource "aws_cloudwatch_log_metric_filter" "migration_failed" {
}

resource "aws_cloudwatch_metric_alarm" "migration_failed" {
count = var.enable_migration_alarm ? 1 : 0

alarm_name = "${var.stack_name}-migration-failed"
comparison_operator = "GreaterThanThreshold"
evaluation_periods = 1
metric_name = aws_cloudwatch_log_metric_filter.migration_failed.metric_transformation[0].name
namespace = aws_cloudwatch_log_metric_filter.migration_failed.metric_transformation[0].namespace
metric_name = aws_cloudwatch_log_metric_filter.migration_failed[0].metric_transformation[0].name
namespace = aws_cloudwatch_log_metric_filter.migration_failed[0].metric_transformation[0].namespace
period = 300
statistic = "Sum"
threshold = 0
Expand Down
6 changes: 6 additions & 0 deletions terraform/modules/compute/aws/lambda/variables.tf
Original file line number Diff line number Diff line change
Expand Up @@ -3,6 +3,12 @@ variable "stack_name" {
type = string
}

variable "enable_migration_alarm" {
description = "Create the migration-failure CloudWatch metric filter + alarm. Defaults to false because the metric filter requires logs:PutMetricFilter on the deploy SA, which is granted via the ci-cd-permissions bootstrap (root CLAUDE.md CI/CD IAM split). Leaving it false keeps deploys unblocked when that permission is absent; set true only after re-applying the bootstrap so the deploy role can manage the filter."
type = bool
default = false
}

variable "environment" {
description = "Environment name (dev/staging/prod)"
type = string
Expand Down
Loading