AWSLive-testedattested

CloudWatch Logs, Alarm & Dashboard

A self-contained CloudWatch observability bundle - an encrypted log group with retention, a metric alarm, and a dashboard - that stands up from just a name and points at any real metric.

terraformAWSaws

Compare Monitoring & Observability across clouds →

Part of: AWS Production Landing Zone, AWS Container Platform (EKS)

aws-cloudwatchvizier v1.2.0

Verification

Live-tested

Really deployed to a cloud sandbox, verified against its outputs and assertions, then destroyed - with the teardown confirmed.

Conformance

  • Static validation (fmt · validate · tflint)
  • Security scan clean (Checkov)
  • Plan test superseded by live test

Provenance

Functional

  • Live-tested - applied, verified, destroyed

Last verified 2026-06-30 · how we verify

Verify this download

cosign · sha-256

Don't take our word for it. Every release is signed with cosign - check the bytes against our pinned public key before you trust them.

# 1. Our pinned public key - fetch once, trust out-of-band
curl -O https://www.iac-bazaar.com/cosign.pub

# 2. This module's Sigstore bundle
curl -o aws-cloudwatch-1.0.0.sigstore.json \
  https://www.iac-bazaar.com/api/artifacts/aws-cloudwatch/signature

# 3. Verify the tarball you downloaded
cosign verify-blob \
  --key cosign.pub \
  --bundle aws-cloudwatch-1.0.0.sigstore.json \
  aws-cloudwatch-1.0.0.tar.gz
# → Verified OK

# 4. (optional) confirm the checksum too
echo "5d7ef7d7543ee2cc95d63550d5095a921a84106b681b2de058c6a513b053fb87  aws-cloudwatch-1.0.0.tar.gz" | sha256sum -c

Use it from the registry

terraform · opentofu
module "cloudwatch" {
  source  = "www.iac-bazaar.com/iac-bazaar/aws-cloudwatch/aws"
  version = "1.0.0"
}

Needs a registry token from /account/tokens. The module itself is free; the account is what identifies you. Full setup: registry docs.

Cite it in your README

badge · attribution

Paste this beside the module in the repository that uses it. The badge is rendered from this artifact's verification record, so it reads live-tested because the record says so, and the link lands on this page.

README.md, GitLab, Gitea
[![IaC Bazaar: live-tested](https://www.iac-bazaar.com/api/artifacts/aws-cloudwatch/badge)](https://www.iac-bazaar.com/catalog/aws-cloudwatch?utm_source=syndication&utm_medium=readme&utm_campaign=artifact)

Terraform module 1.0.0, live-tested on IaC Bazaar: [CloudWatch Logs, Alarm & Dashboard](https://www.iac-bazaar.com/catalog/aws-cloudwatch?utm_source=syndication&utm_medium=readme&utm_campaign=artifact)

```hcl
module "cloudwatch" {
  source  = "www.iac-bazaar.com/iac-bazaar/aws-cloudwatch/aws"
  version = "1.0.0"
}
```

Preview:IaC Bazaar: live-tested

Inputs & outputs

Create a free account to read this module's contract

The declared contract - every input name, type, default and description, plus every output - is shown to signed-in accounts, not to anonymous visitors.

A free account sees the contract of every module in the catalogue. There is no subscription and nothing to buy - the modules are free to download, and they run under Vizier.

Documentation

aws-cloudwatch

A self-contained CloudWatch observability bundle: a log group (retention + optional CMK encryption), a metric alarm, and a dashboard. Works with Terraform and OpenTofu (>= 1.6), AWS provider >= 6.0, < 7.0.

Out of the box the alarm and the dashboard target the log group itself (AWS/Logs / IncomingLogEvents), so the module stands up with nothing but a name and costs nothing to run. Point alarm_namespace / alarm_metric_name / alarm_dimensions at any real metric (EC2 CPUUtilization, ALB 5XX, a custom namespace, ...) when you wire it to a workload.

Secure / cost-aware defaults:

  • Log group is encrypted at rest (AWS-owned key by default; set kms_key_id for a customer-managed key — the key policy must allow logs.<region>.amazonaws.com)
  • Retention defaults to 7 days (never use 0 / never-expire unless you accept unbounded log storage cost)
  • Alarm treat_missing_data = "notBreaching" avoids false alarms when no data is flowing
  • Dashboards are free for the first three per account

Security notes

  • For regulated workloads set kms_key_id to a customer-managed KMS key so logs are encrypted with a key you control and audit; ensure its key policy grants logs.<region>.amazonaws.com the usual kms:Encrypt*/Decrypt/GenerateDataKey* permissions scoped by kms:EncryptionContext:aws:logs:arn.
  • Keep retention_in_days finite — 0 (never expire) accumulates cost and expands the data-retention surface indefinitely.
  • Send alarm_actions to an SNS topic with confirmed subscribers so alarms are actually actionable.

Requirements

  • Terraform or OpenTofu >= 1.6
  • hashicorp/aws >= 6.0, < 7.0

License

Commercial — IaC Bazaar EULA. © IaC Bazaar. Original work (not derived from a third-party module).

Usage code & full reference need an account

The complete copy-paste usage, the full input/output reference, and operational notes are free with an account - shown here and bundled in the download. Sign in and this section fills in.

  • Usage
  • Inputs
  • Outputs

Related modules

Static validatedLive test pending

aws-config

Recorder, delivery channel, service role and managed rules. Starting the recorder is a separate resource people leave out, so a stopped recorder looks identical to a running one until an investigation finds an empty timeline.

View module
Static validatedLive test pending

aws-grafana

account_access_type ORGANIZATION lets a workspace query observability data in accounts whose owners never approved it, and SERVICE_MANAGED means AWS wrote those data-source policies. Current account, a role you wrote, and an endpoint narrowed to a prefix list rather than the whole internet.

View module
Static validatedLive test pending

aws-prometheus

Alerting needs BOTH an alert manager definition and a rule group namespace; with either missing the workspace stores metrics and raises nothing while every dashboard reports it healthy. Without logging_configuration a throttled remote_write likewise produces no metrics, no error and no alert.

View module
Static validatedLive test pending

aws-cloudtrail-lake

A CloudTrail Lake event data store with the retention decided rather than inherited. The aws provider defaults retention to 2555 days; on the default pricing option AWS includes 366 and bills the rest, so the provider default quietly buys 2,189 days of storage. This module defaults to 366, prints the billed days, and keeps termination protection on.

View module
Static validatedLive test pending

aws-cloudtrail

Multi-region trail with log file validation always on, a bucket that blocks public access, versions, encrypts and denies non-TLS, a policy pinned to this trail, optional CloudWatch delivery and opt-in data events.

View module
Static validatedLive test pending

aws-vpc-flow-logs

Flow logs for an existing VPC in the extended format an investigation needs (flow direction, TCP flags, packet addresses through NAT), at one minute rather than ten, all traffic rather than rejects, to a CloudWatch log group created with retention and your KMS key, or to S3 as Hive-partitioned Parquet when a bucket is given. Partial traffic and the AWS-managed key are accepted by name.

View module