From b6910e1bc1ec48cf8e77e0217fd881a2135eae14 Mon Sep 17 00:00:00 2001 From: Kenny Leung Date: Tue, 3 Sep 2024 08:38:40 -0700 Subject: [PATCH] Revert "Remove laser alerts (#462)" This reverts commit 7c2050515e62e93a27d69e615d9d4167e2c7012c. --- modules/cloudevent-recorder/README.md | 1 + modules/cloudevent-recorder/main.tf | 65 +++++++++++++++++ modules/configmap/README.md | 1 + modules/configmap/main.tf | 52 +++++++++++++ modules/cron/README.md | 2 + modules/cron/main.tf | 101 ++++++++++++++++++++++++++ modules/regional-go-service/main.tf | 5 ++ modules/regional-service/README.md | 1 + modules/regional-service/main.tf | 53 ++++++++++++++ modules/serverless-gclb/README.md | 1 + modules/serverless-gclb/main.tf | 42 +++++++++++ 11 files changed, 324 insertions(+) diff --git a/modules/cloudevent-recorder/README.md b/modules/cloudevent-recorder/README.md index c1911636..f8bc774e 100644 --- a/modules/cloudevent-recorder/README.md +++ b/modules/cloudevent-recorder/README.md @@ -107,6 +107,7 @@ No requirements. | [google_bigquery_table.types](https://registry.terraform.io/providers/hashicorp/google/latest/docs/resources/bigquery_table) | resource | | [google_bigquery_table_iam_binding.import-writes-to-tables](https://registry.terraform.io/providers/hashicorp/google/latest/docs/resources/bigquery_table_iam_binding) | resource | | [google_monitoring_alert_policy.bq_dts](https://registry.terraform.io/providers/hashicorp/google/latest/docs/resources/monitoring_alert_policy) | resource | +| [google_monitoring_alert_policy.bucket-access](https://registry.terraform.io/providers/hashicorp/google/latest/docs/resources/monitoring_alert_policy) | resource | | [google_pubsub_subscription.dead-letter-pull-sub](https://registry.terraform.io/providers/hashicorp/google/latest/docs/resources/pubsub_subscription) | resource | | [google_pubsub_subscription.this](https://registry.terraform.io/providers/hashicorp/google/latest/docs/resources/pubsub_subscription) | resource | | [google_pubsub_subscription_iam_binding.allow-pubsub-to-ack](https://registry.terraform.io/providers/hashicorp/google/latest/docs/resources/pubsub_subscription_iam_binding) | resource | diff --git a/modules/cloudevent-recorder/main.tf b/modules/cloudevent-recorder/main.tf index 4dbf9938..ed7a1237 100644 --- a/modules/cloudevent-recorder/main.tf +++ b/modules/cloudevent-recorder/main.tf @@ -50,3 +50,68 @@ resource "google_storage_bucket" "recorder" { // What identity is deploying this? data "google_client_openid_userinfo" "me" {} +resource "google_monitoring_alert_policy" "bucket-access" { + # In the absence of data, incident will auto-close after an hour + alert_strategy { + auto_close = "3600s" + + notification_rate_limit { + period = "3600s" // re-alert hourly if condition still valid. + } + } + + display_name = "Abnormal Event Bucket Access: ${var.name}" + combiner = "OR" + + conditions { + display_name = "Bucket Access" + + condition_matched_log { + filter = <