Kaizen

CloudWatch RUM

Real user monitoring for the browser, with a Cognito guest identity to send events.

Module
rum
Layer
Observability
Interface
6 inputs, 4 outputs
Used by
1 Kaizen app

Why it matters

Server logs miss what users actually see: slow page loads, JavaScript errors, and failed requests in the browser. This module sets up CloudWatch RUM so the front end can report those events to AWS without a third party analytics tool. It records every session by default, so plan the sample rate before launch.

Use it when

  • A public web app needs front end error and performance data.

Reach for something else when

  • The app runs in GovCloud. Confirm that CloudWatch RUM is offered in the target region before you plan the stack.
  • You want server logs, metrics, and traces. Use openobserve.

What it creates

  • aws_cognito_identity_pool (unauthenticated identities allowed)
  • aws_iam_role and aws_iam_role_policy (rum:PutRumEvents on this monitor only)
  • aws_cognito_identity_pool_roles_attachment
  • aws_rum_app_monitor (errors, performance, and http telemetry)

Secure by default

  • The guest role can call rum:PutRumEvents on this app monitor and nothing else.
  • X-Ray tracing is off.

Commercial and GovCloud

main.tf
module "rum" {
  source = "git::ssh://git@github.com/the-kaizen-labs/terraform-modules.git//rum?ref=v1.7.0"

  app_name            = local.app_name
  domain              = "my-app.kaizenlabs.co"
  session_sample_rate = 0.25

  tags = local.tags
}

How it connects

  • To ecs-service: app_monitor_id, identity_pool_id (as environment_variables)

Inputs

NameTypeDefaultRequiredDescription
app_namestringyesApplication name used in resource naming
domainstringyesDomain the RUM app monitor is attached to (e.g. "app.example.com")
environmentstring""noEnvironment suffix. Leave empty for accounts with no env concept.
session_sample_ratenumber1noFraction of sessions to sample (0.0-1.0). 1 = all sessions.
tagsmap(string){}noTags to apply to all resources
telemetrieslist(string)["errors","performance","http"]noWhich telemetry types to collect

Outputs

NameDescription
app_monitor_arnValue: aws_rum_app_monitor.main.arn
app_monitor_idRUM app monitor ID: pass to browser clients as RUM_APP_MONITOR_ID
guest_role_arnValue: aws_iam_role.rum_unauthenticated.arn
identity_pool_idCognito identity pool ID: pass to browser clients as RUM_IDENTITY_POOL_ID

Used by

AppPinned ref
evergreenv1.0.0

On this page