diff --git a/.github/dependabot.yml b/.github/dependabot.yml index b0274c1..41496cb 100644 --- a/.github/dependabot.yml +++ b/.github/dependabot.yml @@ -33,3 +33,14 @@ updates: update-types: - "minor" - "patch" + - package-ecosystem: "terraform" + directory: "/terraform" + schedule: + interval: "weekly" + commit-message: + prefix: "chore(deps)" + groups: + minor-and-patch: + update-types: + - "minor" + - "patch" diff --git a/.github/workflows/ci.yaml b/.github/workflows/ci.yaml index 0e1f041..113a557 100644 --- a/.github/workflows/ci.yaml +++ b/.github/workflows/ci.yaml @@ -11,3 +11,5 @@ jobs: uses: Sea-Haven-Industries/.github/.github/workflows/ci-python-sam.yaml@3f746774229d41770727e2e4fd63ed5f5555a8b3 # v1.0.3 with: source-dirs: "src" + # Deploy path is HCP Terraform; reusable name still covers Python lint/tests. + run-sam-validate: false diff --git a/README.md b/README.md index cbf6444..29735d3 100644 --- a/README.md +++ b/README.md @@ -7,8 +7,6 @@ HCP Terraform stack with two Lambda functions that integrate the Afi.ai backup API with Slack. Deployed to **seahaven-prod** via workspace `afi-backup-monitor-prod` (PLAT-56). -`template.yaml` remains as the historical SAM reference for the mgmt stack during cutover; deploy path is HCP Terraform only. - ## Functions **afi-auto-protect** — Runs weekly. Compares tenant resources against active protections and automatically applies the configured backup policy to any unprotected users. Posts a summary to Slack. @@ -28,7 +26,6 @@ HCP Terraform stack with two Lambda functions that integrate the Afi.ai backup A ``` terraform/ # HCP Terraform config (sole deploy path) -template.yaml # Historical SAM reference (mgmt cutover / rollback) src/ auto_protect/app.py # afi-auto-protect handler health_digest/app.py # afi-health-digest handler diff --git a/template.yaml b/template.yaml deleted file mode 100644 index 413243f..0000000 --- a/template.yaml +++ /dev/null @@ -1,112 +0,0 @@ -AWSTemplateFormatVersion: '2010-09-09' -Transform: AWS::Serverless-2016-10-31 -Description: Afi.ai Backup Monitor - Auto-protect new users and weekly health digest - -Parameters: - AfiApiKeySecretArn: - Type: String - Description: ARN of the Secrets Manager secret containing the Afi API key - AfiTenantId: - Type: String - Description: Afi tenant ID for your Google Workspace - AfiPolicyId: - Type: String - Description: Afi backup policy ID to assign to new users - SlackWebhookSecretArn: - Type: String - Description: ARN of the Secrets Manager secret containing the Slack webhook URL - AutoProtectSchedule: - Type: String - Default: 'cron(0 14 ? * MON *)' - Description: Schedule for auto-protect check (default Monday 10am ET) - HealthDigestSchedule: - Type: String - Default: 'cron(0 14 ? * MON *)' - Description: Schedule for weekly health digest (default Monday 10am ET) - -Globals: - Function: - Runtime: python3.12 - Timeout: 120 - MemorySize: 256 - Architectures: - - arm64 - PermissionsBoundary: arn:aws:iam::328440206208:policy/seahaven-lambda-execution-boundary - Environment: - Variables: - AFI_API_KEY_SECRET_ARN: !Ref AfiApiKeySecretArn - AFI_TENANT_ID: !Ref AfiTenantId - SLACK_WEBHOOK_SECRET_ARN: !Ref SlackWebhookSecretArn - -Resources: - SharedLayer: - Type: AWS::Serverless::LayerVersion - Properties: - LayerName: afi-shared - Description: Shared Afi API client and utilities - ContentUri: src/shared/ - CompatibleRuntimes: - - python3.12 - CompatibleArchitectures: - - arm64 - - AutoProtectFunction: - Type: AWS::Serverless::Function - Properties: - FunctionName: afi-auto-protect - Handler: app.handler - CodeUri: src/auto_protect/ - Layers: - - !Ref SharedLayer - Environment: - Variables: - AFI_POLICY_ID: !Ref AfiPolicyId - Policies: - - Version: '2012-10-17' - Statement: - - Effect: Allow - Action: - - secretsmanager:GetSecretValue - Resource: - - !Ref AfiApiKeySecretArn - - !Ref SlackWebhookSecretArn - Events: - WeeklySchedule: - Type: Schedule - Properties: - Schedule: !Ref AutoProtectSchedule - Description: Weekly check for unprotected users - Enabled: true - - HealthDigestFunction: - Type: AWS::Serverless::Function - Properties: - FunctionName: afi-health-digest - Handler: app.handler - CodeUri: src/health_digest/ - Layers: - - !Ref SharedLayer - Policies: - - Version: '2012-10-17' - Statement: - - Effect: Allow - Action: - - secretsmanager:GetSecretValue - Resource: - - !Ref AfiApiKeySecretArn - - !Ref SlackWebhookSecretArn - Events: - WeeklySchedule: - Type: Schedule - Properties: - Schedule: !Ref HealthDigestSchedule - Description: Weekly backup health digest to Slack - Enabled: true - -Outputs: - AutoProtectFunctionArn: - Description: Auto-protect Lambda ARN - Value: !GetAtt AutoProtectFunction.Arn - HealthDigestFunctionArn: - Description: Health digest Lambda ARN - Value: !GetAtt HealthDigestFunction.Arn diff --git a/terraform/.terraform.lock.hcl b/terraform/.terraform.lock.hcl index 9e09f82..e079cf2 100644 --- a/terraform/.terraform.lock.hcl +++ b/terraform/.terraform.lock.hcl @@ -6,6 +6,9 @@ provider "registry.terraform.io/hashicorp/archive" { constraints = "~> 2.0" hashes = [ "h1:WB6H5ksIZiyq1lQlD/PWeh+tn4FLsbSjVnRW3+4xe2Y=", + "h1:cMBtvdHEgvTmglbioVehZCaOIPocumu9+vlGw5Dsaro=", + "h1:jdmKm+xl6ZcQrijxapnZ94RVuz/G4vk7hsIa1N0VT5Q=", + "h1:oRWx6ZDIdlNBF90L8TzV9X7pQ+P403hoCDiBfmUfhC0=", "zh:0d14713fdc259fb377d0b899ad3c650a34194bd52194c863303ef22a65a580e2", "zh:369b56040c7a8085d04e7e8ffac1e2b321a3170e502f788819bc34b868ec016f", "zh:4d1a3b983ed6af5a52bfe12794674ae55cbadfa6021b37106ade68b433ad216a", @@ -27,6 +30,9 @@ provider "registry.terraform.io/hashicorp/aws" { constraints = "~> 5.0" hashes = [ "h1:Ijt7pOlB7Tr7maGQIqtsLFbl7pSMIj06TVdkoSBcYOw=", + "h1:edXOJWE4ORX8Fm+dpVpICzMZJat4AX0VRCAy/xkcOc0=", + "h1:hd45qFU5cFuJMpFGdUniU9mVIr5LYVWP1uMeunBpYYs=", + "h1:wOhTPz6apLBuF7/FYZuCoXRK/MLgrNprZ3vXmq83g5k=", "zh:054b8dd49f0549c9a7cc27d159e45327b7b65cf404da5e5a20da154b90b8a644", "zh:0b97bf8d5e03d15d83cc40b0530a1f84b459354939ba6f135a0086c20ebbe6b2", "zh:1589a2266af699cbd5d80737a0fe02e54ec9cf2ca54e7e00ac51c7359056f274",