aws-samples / aws-samples/sample-autonomous-cloud-coding-agents
feat(infra): shared SNS alarm-notification plane (wire bare CloudWatch alarms) — AC5 of #284
- Langage dominant
- TypeScript
- Étoiles
- 146
- Forks
- 46
- Merge moyen
- 3 j 10 h
- PR mergées (30 j)
- 24
Description
Parent context: deferred AC5 of #284 (surfaced during PR #674 review by @theagenticguy). **Needs maintainer `approved` before implementation (ADR-003).**
## Finding
Every CloudWatch alarm in `cdk/src` is a **bare alarm with no notification action** — nothing pages an operator; the signal is only visible to someone already watching the CloudWatch console. Current bare alarms:
- `WebhookProcessorDlqDepthAlarm` + `WebhookProcessorErrorAlarm` (`github-screenshot-integration.ts`)
- `FanOutConsumer.dlqDepthAlarm` (`fanout-consumer.ts`)
- `OrchestratorErrorAlarm` (`task-orchestrator.ts`)
- `ApprovalMetricsPublisherConsumer` alarm (`approval-metrics-publisher-consumer.ts`)
#284's AC5 asked for notification. PR #674 deliberately did **not** one-off an SNS topic on the webhook alarm (correct restraint — a per-alarm topic would be the wrong shape), and #674 therefore uses `Refs #284`, leaving #284 open for this.
## Scope
- Stand up a **shared SNS notification plane** (one topic, or a small construct) that alarms across the app can wire an `addAlarmAction` to.
- Retrofit the existing bare alarms above to publish to it.
- Decide subscription delivery (email/chatbot/PagerDuty) as a config input, not hardcoded.
- Consider cdk-nag implications + a documented subscription-management runbook.
## Closes
This satisfies #284's AC5. Once shipped, **#284 can close** (it is currently held open as DONE-NO-CLOSE tracking exactly this gap).
Refs #284
Guide de contribution
Ouvrir le guide de contribution
Piste de recherche
Commencez par lire ADR-003 et les alarmes existantes dans cdk/src : github-screenshot-integration.ts, fanout-consumer.ts, task-orchestrator.ts et approval-metrics-publisher-consumer.ts. Définissez le construct partagé de notification SNS et l’entrée de souscription configurable avant de relier chaque alarme ; le travail est terminé lorsque toutes les alarmes listées publient via celui-ci, que les implications de cdk-nag sont prises en compte et que le runbook de gestion des souscriptions est documenté.
Rédigé par le modèle d'indexation à partir du texte de l'issue.
Évaluation
- Stack technique
- aws, typescript
- Domaine
- cloud, infrastructure, observability
- Type d'issue
- Fonctionnalité
- Difficulté
- 5/5
- Temps estimé
- Plus d'une semaine
- Activité
- Calme
- Clarté
- Plutôt claire
- Accessibilité débutants
- 30/100