An AWS CDK (TypeScript) stack that deploys AWS Cost Anomaly Detection monitors with KMS-encrypted SNS alerting and a Lambda filter that suppresses noisy services and reformats alerts into readable email.
- Deploys two dimensional anomaly monitors — one by linked account, one by service.
- Routes anomaly notifications through a KMS-encrypted SNS topic.
- Runs a Lambda that filters out configurable services (e.g. AWS Support plan charges) and reformats the raw JSON into a human-readable email.
- Alerts only when an anomaly clears both a percentage and an absolute-dollar threshold, so small low-spend accounts do not create noise.
Cost Anomaly Monitors ─┐
(by account, service) │
▼
Anomaly Subscription (>= X% AND >= $Y)
│
▼
SNS topic (KMS encrypted)
│
▼
Lambda filter ──► SNS topic ──► email subscription
(drop excluded services, (confirmed endpoint)
reformat message)
- Node.js 22.x and npm
- AWS credentials for the target account
- CDK bootstrap in
us-east-1(npx cdk bootstrap aws://<ACCOUNT_ID>/us-east-1)
Region: Cost Explorer and Cost Anomaly Detection are global services that operate only in
us-east-1. The region is fixed in code; do not change it.
npm ci
# 1. Edit config.yml — set notificationEmail, thresholds, and excludedServices
# 2. Synthesize
npx cdk synth
# 3. Deploy (account comes from your AWS credentials)
npx cdk deploy
# 4. Confirm the SNS subscription: AWS emails a confirmation link to
# notificationEmail. Alerts are not delivered until you accept it.Run the tests with npm test.
All behaviour is driven by config.yml:
| Key | Description |
|---|---|
notificationEmail |
Address (or list) that receives formatted alerts. A placeholder is checked in — replace it. |
thresholds.impactPercentage |
Minimum percent above expected spend before alerting. |
thresholds.impactAbsolute |
Minimum dollar impact before alerting. |
excludedServices |
Case-insensitive substring keywords; anomalies whose service name contains any keyword are suppressed. |
Both thresholds must be met (AND logic) for an alert to fire.
├── bin/ CDK app entry point
├── lib/ Stack definition (monitors, SNS, KMS, Lambda)
├── lambda/ Cost anomaly filter Lambda source
├── config.yml Email, thresholds, excluded services
├── test/ Unit tests
└── cdk.json CDK configuration and feature flags
Licensed under the GNU General Public License v3.0 or later. See LICENSE.