Afi.ai backup monitoring - auto-protect users & weekly health digest via Slack
Find a file
Adam Moussa 3c0a8f38fc
docs(agents): drop security review gates (#71)
Agents no longer treat a security review or a cross-family review as a merge gate.
2026-09-26 17:17:09 -04:00
.github/workflows chore(deps): remove dependabot version updates (#66) 2026-08-25 11:51:56 -04:00
src chore(deps): bump boto3 (#58) 2026-08-18 20:12:13 +00:00
terraform feat(iam): import hcptf roles into app Terraform (PLAT-146) (#68) 2026-09-02 18:32:07 +00:00
.gitignore feat(iac): add hcp terraform config for prod migration 2026-08-05 12:01:05 -04:00
AGENTS.md docs(agents): drop security review gates (#71) 2026-09-26 17:17:09 -04:00
README.md docs(readme): record HCP VCS trigger patterns (PLAT-183) (#69) 2026-09-10 21:00:43 +00:00

Afi Backup Monitor

CI Python Terraform Slack

HCP Terraform stack with two Lambda functions that integrate the Afi.ai backup API with Slack. Deployed to seahaven-prod via workspace afi-backup-monitor-prod (PLAT-56). The workspace working directory is terraform/. VCS file triggers use trigger-patterns = [terraform/**/*, src/**/*] because terraform/lambda.tf zips src/. A src/-only merge must still queue a run.

Functions

afi-auto-protect — Runs weekly. Compares tenant resources against active protections and automatically applies the configured backup policy to any unprotected users. Posts a summary to Slack.

afi-health-digest — Runs weekly. Pulls task statistics (last 7 days), storage quotas, and resource coverage, then posts a formatted digest to Slack.

Architecture

  • Runtime: Python 3.12 (arm64)
  • IaC: Terraform under terraform/ (HCP remote apply, Manual until sealed)
  • Shared Layer: Afi API client + Slack webhook helper
  • Secrets: Afi API key and Slack webhook URL in Secrets Manager (ARNs as Terraform variables; values never in state)
  • Scheduling: EventBridge cron rules (default: Mondays 10am ET)
  • IAM: Execution roles under path /tf-managed/ with seahaven-lambda-execution-boundary

Repository Structure

terraform/                  # HCP Terraform config (sole deploy path)
src/
  auto_protect/app.py       # afi-auto-protect handler
  health_digest/app.py      # afi-health-digest handler
  shared/python/            # shared layer
    afi_client.py           # Afi.ai backup API client
    slack.py                # Slack webhook helper

Workspace Terraform variables: secret ARNs, tenant ID, policy ID (see terraform/terraform.tfvars.example).

Documentation

The canonical map of Sea Haven's AWS infrastructure lives in Confluence. This project's afi-backup-monitor stack is represented there as a Mermaid subgraph.

Setup

  1. Create secrets in seahaven-prod (exact ARNs are wired into the Lambda boundary and Terraform variables):

    aws secretsmanager create-secret --name afi-api-key --secret-string "appkey-YOUR_KEY"
    aws secretsmanager create-secret --name afi-slack-webhook --secret-string "https://hooks.slack.com/services/YOUR/WEBHOOK/URL"
    
  2. Set workspace variables in HCP (afi-backup-monitor-prod) from terraform/terraform.tfvars.example.

  3. Apply from the HCP workspace (Manual apply until the stack is sealed). Do not use local terraform apply against prod.

Manual Testing

aws lambda invoke --function-name afi-auto-protect --payload '{}' /dev/stdout
aws lambda invoke --function-name afi-health-digest --payload '{}' /dev/stdout