CloudWatch Logs, Alarm & Dashboard
A self-contained CloudWatch observability bundle - an encrypted log group with retention, a metric alarm, and a dashboard - that stands up from just a name and points at any real metric.
Compare Monitoring & Observability across clouds →
Part of: AWS Production Landing Zone, AWS Container Platform (EKS)
Verification
Live-testedReally deployed to a cloud sandbox, verified against its outputs and assertions, then destroyed - with the teardown confirmed.
Conformance
- Static validation (fmt · validate · tflint)
- Security scan clean (Checkov)
- Plan test superseded by live test
Provenance
- SHA-256 checksum
- Cosign signature
Functional
- Live-tested - applied, verified, destroyed
Last verified 2026-06-30 · how we verify
Verify this download
cosign · sha-256Don't take our word for it. Every release is signed with cosign - check the bytes against our pinned public key before you trust them.
# 1. Our pinned public key - fetch once, trust out-of-band
curl -O https://www.iac-bazaar.com/cosign.pub
# 2. This module's Sigstore bundle
curl -o aws-cloudwatch-1.0.0.sigstore.json \
https://www.iac-bazaar.com/api/artifacts/aws-cloudwatch/signature
# 3. Verify the tarball you downloaded
cosign verify-blob \
--key cosign.pub \
--bundle aws-cloudwatch-1.0.0.sigstore.json \
aws-cloudwatch-1.0.0.tar.gz
# → Verified OK
# 4. (optional) confirm the checksum too
echo "5d7ef7d7543ee2cc95d63550d5095a921a84106b681b2de058c6a513b053fb87 aws-cloudwatch-1.0.0.tar.gz" | sha256sum -cUse it from the registry
terraform · opentofumodule "cloudwatch" {
source = "www.iac-bazaar.com/iac-bazaar/aws-cloudwatch/aws"
version = "1.0.0"
}Needs a registry token from /account/tokens. The module itself is free; the account is what identifies you. Full setup: registry docs.
Cite it in your README
badge · attributionPaste this beside the module in the repository that uses it. The badge is rendered from this artifact's verification record, so it reads live-tested because the record says so, and the link lands on this page.
[](https://www.iac-bazaar.com/catalog/aws-cloudwatch?utm_source=syndication&utm_medium=readme&utm_campaign=artifact)
Terraform module 1.0.0, live-tested on IaC Bazaar: [CloudWatch Logs, Alarm & Dashboard](https://www.iac-bazaar.com/catalog/aws-cloudwatch?utm_source=syndication&utm_medium=readme&utm_campaign=artifact)
```hcl
module "cloudwatch" {
source = "www.iac-bazaar.com/iac-bazaar/aws-cloudwatch/aws"
version = "1.0.0"
}
```Preview:
Inputs & outputs
Create a free account to read this module's contract
The declared contract - every input name, type, default and description, plus every output - is shown to signed-in accounts, not to anonymous visitors.
A free account sees the contract of every module in the catalogue. There is no subscription and nothing to buy - the modules are free to download, and they run under Vizier.
Documentation
aws-cloudwatch
A self-contained CloudWatch observability bundle: a log group (retention +
optional CMK encryption), a metric alarm, and a dashboard. Works with
Terraform and OpenTofu (>= 1.6), AWS provider >= 6.0, < 7.0.
Out of the box the alarm and the dashboard target the log group itself
(AWS/Logs / IncomingLogEvents), so the module stands up with nothing but a
name and costs nothing to run. Point alarm_namespace / alarm_metric_name /
alarm_dimensions at any real metric (EC2 CPUUtilization, ALB 5XX, a custom
namespace, ...) when you wire it to a workload.
Secure / cost-aware defaults:
- Log group is encrypted at rest (AWS-owned key by default; set
kms_key_idfor a customer-managed key — the key policy must allowlogs.<region>.amazonaws.com) - Retention defaults to 7 days (never use
0/ never-expire unless you accept unbounded log storage cost) - Alarm
treat_missing_data = "notBreaching"avoids false alarms when no data is flowing - Dashboards are free for the first three per account
Security notes
- For regulated workloads set
kms_key_idto a customer-managed KMS key so logs are encrypted with a key you control and audit; ensure its key policy grantslogs.<region>.amazonaws.comthe usualkms:Encrypt*/Decrypt/GenerateDataKey*permissions scoped bykms:EncryptionContext:aws:logs:arn. - Keep
retention_in_daysfinite —0(never expire) accumulates cost and expands the data-retention surface indefinitely. - Send
alarm_actionsto an SNS topic with confirmed subscribers so alarms are actually actionable.
Requirements
- Terraform or OpenTofu
>= 1.6 hashicorp/aws>= 6.0, < 7.0
License
Commercial — IaC Bazaar EULA. © IaC Bazaar. Original work (not derived from a third-party module).
Usage code & full reference need an account
The complete copy-paste usage, the full input/output reference, and operational notes are free with an account - shown here and bundled in the download. Sign in and this section fills in.
- Usage
- Inputs
- Outputs
Related modules
aws-config
Recorder, delivery channel, service role and managed rules. Starting the recorder is a separate resource people leave out, so a stopped recorder looks identical to a running one until an investigation finds an empty timeline.
aws-grafana
account_access_type ORGANIZATION lets a workspace query observability data in accounts whose owners never approved it, and SERVICE_MANAGED means AWS wrote those data-source policies. Current account, a role you wrote, and an endpoint narrowed to a prefix list rather than the whole internet.
aws-prometheus
Alerting needs BOTH an alert manager definition and a rule group namespace; with either missing the workspace stores metrics and raises nothing while every dashboard reports it healthy. Without logging_configuration a throttled remote_write likewise produces no metrics, no error and no alert.
aws-cloudtrail-lake
A CloudTrail Lake event data store with the retention decided rather than inherited. The aws provider defaults retention to 2555 days; on the default pricing option AWS includes 366 and bills the rest, so the provider default quietly buys 2,189 days of storage. This module defaults to 366, prints the billed days, and keeps termination protection on.
aws-cloudtrail
Multi-region trail with log file validation always on, a bucket that blocks public access, versions, encrypts and denies non-TLS, a policy pinned to this trail, optional CloudWatch delivery and opt-in data events.
aws-vpc-flow-logs
Flow logs for an existing VPC in the extended format an investigation needs (flow direction, TCP flags, packet addresses through NAT), at one minute rather than ten, all traffic rather than rejects, to a CloudWatch log group created with retention and your KMS key, or to S3 as Hive-partitioned Parquet when a bucket is given. Partial traffic and the AWS-managed key are accepted by name.