This repository has been archived by the owner on Sep 18, 2023. It is now read-only.
-
Notifications
You must be signed in to change notification settings - Fork 30
/
marbot-lambda-function.yml
187 lines (187 loc) · 6.92 KB
/
marbot-lambda-function.yml
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
---
# Copyright widdix GmbH
#
# Licensed under the Apache License, Version 2.0 (the "License");
# you may not use this file except in compliance with the License.
# You may obtain a copy of the License at
#
# http://www.apache.org/licenses/LICENSE-2.0
#
# Unless required by applicable law or agreed to in writing, software
# distributed under the License is distributed on an "AS IS" BASIS,
# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
# See the License for the specific language governing permissions and
# limitations under the License.
AWSTemplateFormatVersion: '2010-09-09'
Description: 'marbot.io: Lambda function monitoring (https://github.com/marbot-io/monitoring-jump-start)'
Metadata:
'AWS::CloudFormation::Interface':
ParameterGroups:
- Label:
default: 'marbot endpoint'
Parameters:
- EndpointId
- Stage
- Label:
default: 'Lambda'
Parameters:
- FunctionName
- Label:
default: 'Thresholds'
Parameters:
- ErrorsThreshold
- ThrottlesThreshold
Parameters:
EndpointId:
Description: 'Your marbot endpoint ID (to get this value: select a channel where marbot belongs to and send a message like this: "@marbot show me my endpoint id").'
Type: String
Stage:
Description: 'marbot stage (never change this!).'
Type: String
Default: v1
AllowedValues: [v1, dev]
FunctionName:
Description: 'The Lambda function name that you want to monitor.'
Type: String
ErrorsThreshold:
Description: 'The maximum errors of a Lambda function (set to -1 to disable).'
Type: Number
Default: 0
MinValue: -1
ThrottlesThreshold:
Description: 'The maximum throttles of a Lambda function (set to -1 to disable).'
Type: Number
Default: 0
MinValue: -1
Conditions:
HasErrorsThreshold: !Not [!Equals [!Ref ErrorsThreshold, '-1']]
HasThrottlesThreshold: !Not [!Equals [!Ref ThrottlesThreshold, '-1']]
Resources:
##########################################################################
# #
# TOPIC #
# #
##########################################################################
Topic:
Type: 'AWS::SNS::Topic'
Properties: {}
TopicPolicy:
Type: 'AWS::SNS::TopicPolicy'
Properties:
PolicyDocument:
Id: Id1
Version: '2012-10-17'
Statement:
- Sid: Sid1
Effect: Allow
Principal:
Service: 'events.amazonaws.com' # Allow EventBridge
Action: 'sns:Publish'
Resource: !Ref Topic
- Sid: Sid2
Effect: Allow
Principal:
AWS: '*' # Allow CloudWatch Alarms
Action: 'sns:Publish'
Resource: !Ref Topic
Condition:
StringEquals:
'AWS:SourceOwner': !Ref 'AWS::AccountId'
Topics:
- !Ref Topic
TopicEndpointSubscription:
DependsOn: TopicPolicy
Type: 'AWS::SNS::Subscription'
Properties:
DeliveryPolicy:
healthyRetryPolicy:
minDelayTarget: 1
maxDelayTarget: 60
numRetries: 100
numNoDelayRetries: 0
backoffFunction: exponential
throttlePolicy:
maxReceivesPerSecond: 1
Endpoint: !Sub 'https://api.marbot.io/${Stage}/endpoint/${EndpointId}'
Protocol: https
TopicArn: !Ref Topic
MonitoringJumpStartEvent:
DependsOn: TopicEndpointSubscription
Type: 'AWS::Events::Rule'
Properties:
Description: 'Monitoring Jump Start connection. (created by marbot)'
ScheduleExpression: 'rate(30 days)'
State: ENABLED
Targets:
- Arn: !Ref Topic
Id: marbot
Input: !Sub |
{
"Type": "monitoring-jump-start-connection",
"StackTemplate": "marbot-lambda-function",
"StackVersion": "1.1.2",
"Partition": "${AWS::Partition}",
"AccountId": "${AWS::AccountId}",
"Region": "${AWS::Region}",
"StackId": "${AWS::StackId}",
"StackName": "${AWS::StackName}"
}
##########################################################################
# #
# ALARMS #
# #
##########################################################################
ErrorsAlarm:
Condition: HasErrorsThreshold
DependsOn: TopicEndpointSubscription
Type: 'AWS::CloudWatch::Alarm'
Properties:
AlarmActions:
- !Ref Topic
AlarmDescription: 'Invocations failed due to errors'
ComparisonOperator: GreaterThanThreshold
DatapointsToAlarm: 1 # We use a 1 out of 18 alarm: if we only look at one period we might miss an error because of the eventual consistent nature of CloudWatch and the fact that Lambda uses the invocation timestamp for metric data
Dimensions:
- Name: FunctionName
Value: !Ref FunctionName
EvaluationPeriods: 18 # We use a 1 out of 18 alarm: if we only look at one period we might miss an error because of the eventual consistent nature of CloudWatch and the fact that Lambda uses the invocation timestamp for metric data
MetricName: Errors
Namespace: 'AWS/Lambda'
OKActions:
- !Ref Topic
Period: 60
Statistic: Sum
Threshold: !Ref ErrorsThreshold
TreatMissingData: notBreaching
ThrottlesAlarm:
Condition: HasThrottlesThreshold
DependsOn: TopicEndpointSubscription
Type: 'AWS::CloudWatch::Alarm'
Properties:
AlarmActions:
- !Ref Topic
AlarmDescription: 'Invocation attempts were throttled due to invocation rates exceeding the concurrent limits'
ComparisonOperator: GreaterThanThreshold
DatapointsToAlarm: 1 # We use a 1 out of 18 alarm: if we only look at one period we might miss an error because of the eventual consistent nature of CloudWatch and the fact that Lambda uses the invocation timestamp for metric data
Dimensions:
- Name: FunctionName
Value: !Ref FunctionName
EvaluationPeriods: 18 # We use a 1 out of 18 alarm: if we only look at one period we might miss an error because of the eventual consistent nature of CloudWatch and the fact that Lambda uses the invocation timestamp for metric data
MetricName: Throttles
Namespace: 'AWS/Lambda'
OKActions:
- !Ref Topic
Period: 60
Statistic: Sum
Threshold: !Ref ThrottlesThreshold
TreatMissingData: notBreaching
Outputs:
StackName:
Description: 'Stack name.'
Value: !Sub '${AWS::StackName}'
StackTemplate:
Description: 'Stack template.'
Value: 'marbot-lambda-function'
StackVersion:
Description: 'Stack version.'
Value: '1.1.2'