Skip to content

Reconcile four retained failure queues after a successful replacement deploy #137

Description

@alexeygrigorev

Reconcile four retained failure queues after a successful replacement deploy

Status: blocked — awaiting #136 successful replacement deployment, then authorized HUMAN read-only reconciliation; evidence collection only
Tags: bug, infra, testing, P1
Depends on: #130 and #140 completed; #136 successful final deployment after #143 ownership remediation; #141 is not a blocker
Blocks: None
Next owner: On-Call to complete #136 deployment, then the authorized HUMAN queue-reconciliation owner
Resume condition: sanitized evidence that #136 reached terminal-success normal deployment and records the exact active replacement queue identities needed for the two separated read-only checks
Evidence: #128 On-Call retained-resource report

Exact retained inventory

Two failed deployment attempts left four generated-name queues outside the restored stack:

  • dataops-v1-ConversationalExecutionFailureQueue-5tIXadG96UPw
  • dataops-v1-ConversationalExecutionFailureQueue-uaUHwrRVO3KW
  • dataops-v1-SponsorCommunicationFailureQueue-8iVYd6AmknFS
  • dataops-v1-SponsorCommunicationFailureQueue-wtudxiKwXhgF

Initial read-only evidence found every queue at approximate available/in-flight/delayed 0/0/0, 14-day retention, no queue or redrive policy, no Lambda event-source mapping, and no current stack ownership. Sponsor queues use alias/aws/sqs; conversational queues use SQS-managed encryption.

This issue records a later reconciliation gate only. It does not authorize deletion, purge, policy changes, redrive, message receive, encryption changes, or any other queue mutation.

Acceptance Criteria

  • [HUMAN] First obtain a successful Migrate Sponsor CRM GSIs in a protected stage-only workflow #136 application deployment and terminal stack success. Record the exact active replacement failure-queue physical names/ARNs/URLs from the current stack and prove none equals an old queue.
  • [HUMAN] Resolve only the four exact old queue names above—never a prefix, wildcard, search result, or inferred URL—and record sanitized ARN/name hashes plus creation timestamps.
  • [HUMAN] For each old queue, perform two read-only checks separated by at least that queue's configured visibility timeout. Both checks must show available/in-flight/delayed 0/0/0.
  • [HUMAN] Both checks prove no queue policy, redrive policy, redrive-allow relationship, Lambda event-source mapping, EventBridge Pipe/target, SNS subscription, current CloudFormation stack reference, or active application configuration reference.
  • [HUMAN] Verify retention and encryption remain as observed and compare exact old identities against the active replacement queues. Do not inspect/log message bodies or expose queue URLs, account IDs, policies, tags, or private metadata publicly.
  • [HUMAN] Attach a sanitized read-only reconciliation report with timestamps, visibility-timeout separation, exact checks performed, terminal deployment reference, and reviewer verdict.
  • Stop after evidence collection. Any later deletion requires explicit new authorization or regrooming with a separately reviewed exact-resource deletion/rollback plan. This issue currently grants none.

Failure handling

Any message count, ownership/reference, policy, redrive relation, mapping/target/subscription, identity ambiguity, missing active replacement, non-terminal stack, or inconsistent observation blocks reconciliation. Do not purge, move, receive, redrive, detach, retag, or delete anything to make a check pass.

Out of scope

Prefix/glob cleanup, deletion or purge, application deployment, GSI migration, IAM edits, provider/Telegram calls, message-body inspection, active replacement queue changes, or cleanup of any resource not named exactly above.

Metadata

Metadata

Assignees

No one assigned

    Labels

    P1ImportantbugSomething is brokeninfraDeployment and infrastructuretestingTests and QA

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions