docs: document template.yaml and repo structure in README

Daily security sweep flagged that the README omitted template.yaml (the
SAM stack) as an existing component. Add a Repository Structure section
naming template.yaml and the src layout.

Also fix a related setup gap: the Slack webhook Secrets Manager secret
(SlackWebhookSecretArn, required by slack.py via SLACK_WEBHOOK_SECRET_ARN)
was not covered by the setup instructions.
This commit is contained in:
Adam Moussa 2026-07-10 15:37:44 -04:00
parent c898a18226
commit 670f308553
No known key found for this signature in database

View file

@ -17,9 +17,24 @@ AWS SAM stack with two Lambda functions that integrate the Afi.ai backup API wit
- **Runtime:** Python 3.12 (arm64)
- **Shared Layer:** Afi API client + Slack webhook helper
- **Secrets:** Afi API key stored in AWS Secrets Manager
- **Secrets:** Afi API key and Slack webhook URL stored in AWS Secrets Manager
- **Scheduling:** EventBridge cron rules (default: Mondays 10am ET)
## Repository Structure
```
template.yaml # SAM stack: Lambdas, shared layer, IAM, EventBridge schedules
src/
auto_protect/app.py # afi-auto-protect handler
health_digest/app.py # afi-health-digest handler
shared/python/ # shared layer
afi_client.py # Afi.ai backup API client
slack.py # Slack webhook helper
```
Deployment parameters (secret ARNs, tenant ID, policy ID, schedules) are defined in
`template.yaml` and supplied at deploy time via `samconfig.toml`.
## Documentation
The canonical map of Sea Haven's AWS infrastructure lives in Confluence. This project's `afi-backup-monitor` stack is represented there as a Mermaid subgraph.
@ -28,12 +43,13 @@ The canonical map of Sea Haven's AWS infrastructure lives in Confluence. This pr
## Setup
1. Store the Afi API key in Secrets Manager:
1. Store the Afi API key and Slack webhook URL in Secrets Manager:
```bash
aws secretsmanager create-secret --name afi-api-key --secret-string "appkey-YOUR_KEY"
aws secretsmanager create-secret --name afi-slack-webhook --secret-string "https://hooks.slack.com/services/YOUR/WEBHOOK/URL"
```
2. Update `samconfig.toml` with your Secret ARN, Tenant ID, and Policy ID.
2. Update `samconfig.toml` with your Secret ARNs (`AfiApiKeySecretArn`, `SlackWebhookSecretArn`), Tenant ID, and Policy ID.
3. Build and deploy:
```bash