CloudWatch RUM
Real user monitoring for the browser, with a Cognito guest identity to send events.
- Module
- rum
- Layer
- Observability
- Interface
- 6 inputs, 4 outputs
- Used by
- 1 Kaizen app
Why it matters
Server logs miss what users actually see: slow page loads, JavaScript errors, and failed requests in the browser. This module sets up CloudWatch RUM so the front end can report those events to AWS without a third party analytics tool. It records every session by default, so plan the sample rate before launch.
Use it when
- A public web app needs front end error and performance data.
Reach for something else when
- The app runs in GovCloud. Confirm that CloudWatch RUM is offered in the target region before you plan the stack.
- You want server logs, metrics, and traces. Use openobserve.
What it creates
aws_cognito_identity_pool(unauthenticated identities allowed)aws_iam_roleand aws_iam_role_policy (rum:PutRumEvents on this monitor only)aws_cognito_identity_pool_roles_attachmentaws_rum_app_monitor(errors, performance, and http telemetry)
Secure by default
- The guest role can call rum:PutRumEvents on this app monitor and nothing else.
- X-Ray tracing is off.
Commercial and GovCloud
module "rum" {
source = "git::ssh://git@github.com/the-kaizen-labs/terraform-modules.git//rum?ref=v1.7.0"
app_name = local.app_name
domain = "my-app.kaizenlabs.co"
session_sample_rate = 0.25
tags = local.tags
}How it connects
- To ecs-service: app_monitor_id, identity_pool_id (as environment_variables)
Inputs
| Name | Type | Default | Required | Description |
|---|---|---|---|---|
app_name | string | yes | Application name used in resource naming | |
domain | string | yes | Domain the RUM app monitor is attached to (e.g. "app.example.com") | |
environment | string | "" | no | Environment suffix. Leave empty for accounts with no env concept. |
session_sample_rate | number | 1 | no | Fraction of sessions to sample (0.0-1.0). 1 = all sessions. |
tags | map(string) | {} | no | Tags to apply to all resources |
telemetries | list(string) | ["errors","performance","http"] | no | Which telemetry types to collect |
Outputs
| Name | Description |
|---|---|
app_monitor_arn | Value: aws_rum_app_monitor.main.arn |
app_monitor_id | RUM app monitor ID: pass to browser clients as RUM_APP_MONITOR_ID |
guest_role_arn | Value: aws_iam_role.rum_unauthenticated.arn |
identity_pool_id | Cognito identity pool ID: pass to browser clients as RUM_IDENTITY_POOL_ID |
Used by
| App | Pinned ref |
|---|---|
| evergreen | v1.0.0 |