cdk-monitoring-constructs
cdk-monitoring-constructs copied to clipboard
[secrets] Add support for secrets count metric
Feature scope
AWS Secrets Manager
Describe your suggested feature
Announced in https://aws.amazon.com/about-aws/whats-new/2022/05/aws-secrets-manager-publishes-usage-metrics-to-amazon-cloudwatch/
Docs: https://docs.aws.amazon.com/secretsmanager/latest/userguide/monitoring-cloudwatch.html
Interesting. Do you have any example of a use case? When I would like to get an alarm?
I personally haven't had a need for it, so I'm not too sure. The announcement does note:
You can also set alarms for an unexpected increase or decrease in number of secrets.
...which may be interesting. If anyone has a need for this, do let us know in this issue!
I was thinking of working on this issue as a first issue on this repository, would the direction for this type of a feature be creating its own module like aws-secretmanager-usage or adding another monitoring ts file under aws-secretsmanager (like how aws-sqs has two monitoring files)?
SecretsManagerSecretMetricFactory and SecretsManagerSecretMonitoring would be appropriate places to do it.
SQS is a bit unique since we'd want slightly different metrics/dashboards for a DLQ vs. a regular queue.
Just for a little more clarity, wouldn't SecretsManagerSecretMonitoring be specifically setting up metrics on a specific secret? A metric like secrets count would be some monitor that does not take in a secret only a scope since its a metric encompassing all secrets. I could make the secret parameter optional for SecretsManagerSecretMonitoring and if no secret is passed to the monitor then it will just do a secrets count, but not sure if that would be the right way to go.
Ah, got it. Yes you're right, it'd seem appropriate to have a separate set of classes to handle these global-level metrics.
Great, thanks for the response! Mind if you assign this to me? I'll get work on it this week.
Comment on the change:
I created an alarm to detect any change on secret counts (addChangeInSecretCountAlarm). It works when set to just checking for an increase or a decrease in count, but when both are enabled it suffers from the same issue as the AnomalyAlarm bug in issue 332.
Let me know what you think about the alarms created and if maybe creating a separate issue than this for the anomaly check when the bug is resolved.