aws_sdk_client allowlist, so the integration cannot send, consume, or delete messages.
Why this exists
Queue state lives in queue attributes, not in logs or metrics. A consumer that hangs without raising an exception writes no error line anywhere — so log search comes back clean while the queue quietly stops draining. The specific failure this surfaces: a message that causes a consumer to hang past itsVisibilityTimeout becomes visible again and is redelivered to the next consumer, which also hangs. Every consumer ends up holding the same message. Nothing errors, so nothing reaches the logs, and without a RedrivePolicy there is no receive-count ceiling to break the cycle. Reading two attributes — in_flight_count pinned at the consumer count and has_dlq: false — identifies it immediately.
Prerequisites
- AWS credentials configured per the AWS integration (role ARN recommended) — SQS reuses the same account credentials and region, so no extra setup is needed
- IAM permissions for the two read-only SQS actions listed below
How it works
SQS inspection is account-wide, so the tool becomes available to the planner whenever the AWS integration is configured — there is nothing queue-specific to set up. The region comes from the AWS integration (orAWS_REGION, defaulting to us-east-1).
The tool calls ListQueues to discover queues, then GetQueueAttributes for each one, so a prefix filter and a queue cap keep the fan-out bounded.
Tools
Parameters
Output fields
Reading the output
A missing numeric attribute is reported as
null, not 0. An absent measurement and a genuinely empty queue are different findings, and collapsing them would let a metrics gap read as “the queue is drained”.Attributes prefixed
Approximate are eventually consistent and can lag by around a minute. The field names keep the approximate semantics in mind — use them for shape and direction, not for exact reconciliation.If one queue’s attributes cannot be read (for example a per-queue policy denying
GetQueueAttributes), that queue is returned with an attributes_error field and the remaining queues are still inspected — a single unreadable queue never sinks the whole investigation.IAM permissions
ReadOnlyAccess policy, both actions are already covered.
Execution identity: the AWS integration’s
role_arn / credentials gate availability and supply the region, but the calls themselves run through boto3’s standard credential chain (environment variables, shared config, or the host’s instance role) — the configured role is not assumed for the call. Ensure the identity the OpenSRE process runs as can perform these actions. This matches the other AWS tools (RDS/EKS/CloudTrail).