AWS integration

Route AWS CloudWatch alarms through signed SNS notifications.

IncidentRelay validates Amazon SNS signatures and exact Topic ARNs before turning CloudWatch state changes into routed incidents.

Signed SNS intake

Each AWS route stores an exact SNS Topic ARN. IncidentRelay checks the SNS envelope, certificate URL, certificate validity and message signature before accepting a notification.

CloudWatch lifecycle

  • ALARM creates or updates a firing incident.
  • OK resolves the incident associated with the same alarm ARN.
  • INSUFFICIENT_DATA is treated as a warning-level firing signal.
  • SNS subscription confirmations are validated and completed automatically.

Useful routing labels

Route by AWS account, region, CloudWatch namespace, metric name, alarm ARN or dimension labels such as an EC2 instance ID. String SNS message attributes are also available as matchers.

Recommended grouping

["cloudwatch_alarm_arn"]