Skip to content

About

An AWS CDK (TypeScript) stack that deploys AWS Cost Anomaly Detection monitors with KMS-encrypted SNS alerting and a Lambda filter that suppresses noisy services and reformats alerts into readable email.

Topics

Resources

Stars

0 stars

Watchers

0 watching

Forks

Repository files navigation

AWS Cost Anomaly Detection (CDK)

An AWS CDK (TypeScript) stack that deploys AWS Cost Anomaly Detection monitors with KMS-encrypted SNS alerting and a Lambda filter that suppresses noisy services and reformats alerts into readable email.

What It Does

  • Deploys two dimensional anomaly monitors — one by linked account, one by service.
  • Routes anomaly notifications through a KMS-encrypted SNS topic.
  • Runs a Lambda that filters out configurable services (e.g. AWS Support plan charges) and reformats the raw JSON into a human-readable email.
  • Alerts only when an anomaly clears both a percentage and an absolute-dollar threshold, so small low-spend accounts do not create noise.
Cost Anomaly Monitors ─┐
 (by account, service) │
                       ▼
            Anomaly Subscription  (>= X%  AND  >= $Y)
                       │
                       ▼
            SNS topic (KMS encrypted)
                       │
                       ▼
            Lambda filter  ──►  SNS topic  ──►  email subscription
        (drop excluded services,           (confirmed endpoint)
         reformat message)

Prerequisites

  • Node.js 22.x and npm
  • AWS credentials for the target account
  • CDK bootstrap in us-east-1 (npx cdk bootstrap aws://<ACCOUNT_ID>/us-east-1)

Region: Cost Explorer and Cost Anomaly Detection are global services that operate only in us-east-1. The region is fixed in code; do not change it.

Quick Start

npm ci

# 1. Edit config.yml — set notificationEmail, thresholds, and excludedServices
# 2. Synthesize
npx cdk synth

# 3. Deploy (account comes from your AWS credentials)
npx cdk deploy

# 4. Confirm the SNS subscription: AWS emails a confirmation link to
#    notificationEmail. Alerts are not delivered until you accept it.

Run the tests with npm test.

Configuration

All behaviour is driven by config.yml:

Key Description
notificationEmail Address (or list) that receives formatted alerts. A placeholder is checked in — replace it.
thresholds.impactPercentage Minimum percent above expected spend before alerting.
thresholds.impactAbsolute Minimum dollar impact before alerting.
excludedServices Case-insensitive substring keywords; anomalies whose service name contains any keyword are suppressed.

Both thresholds must be met (AND logic) for an alert to fire.

Project Structure

├── bin/                    CDK app entry point
├── lib/                    Stack definition (monitors, SNS, KMS, Lambda)
├── lambda/                 Cost anomaly filter Lambda source
├── config.yml              Email, thresholds, excluded services
├── test/                   Unit tests
└── cdk.json                CDK configuration and feature flags

License

Licensed under the GNU General Public License v3.0 or later. See LICENSE.

About

An AWS CDK (TypeScript) stack that deploys AWS Cost Anomaly Detection monitors with KMS-encrypted SNS alerting and a Lambda filter that suppresses noisy services and reformats alerts into readable email.

Topics

Resources

Stars

0 stars

Watchers

0 watching

Forks

Contributors

Languages