From 670f308553ca76e591f0a3a8a20f3f1f2e88ef41 Mon Sep 17 00:00:00 2001 From: Adam Moussa Date: Fri, 10 Jul 2026 15:37:44 -0400 Subject: [PATCH] docs: document template.yaml and repo structure in README Daily security sweep flagged that the README omitted template.yaml (the SAM stack) as an existing component. Add a Repository Structure section naming template.yaml and the src layout. Also fix a related setup gap: the Slack webhook Secrets Manager secret (SlackWebhookSecretArn, required by slack.py via SLACK_WEBHOOK_SECRET_ARN) was not covered by the setup instructions. --- README.md | 22 +++++++++++++++++++--- 1 file changed, 19 insertions(+), 3 deletions(-) diff --git a/README.md b/README.md index 55a6ac6..8b9e9b1 100644 --- a/README.md +++ b/README.md @@ -17,9 +17,24 @@ AWS SAM stack with two Lambda functions that integrate the Afi.ai backup API wit - **Runtime:** Python 3.12 (arm64) - **Shared Layer:** Afi API client + Slack webhook helper -- **Secrets:** Afi API key stored in AWS Secrets Manager +- **Secrets:** Afi API key and Slack webhook URL stored in AWS Secrets Manager - **Scheduling:** EventBridge cron rules (default: Mondays 10am ET) +## Repository Structure + +``` +template.yaml # SAM stack: Lambdas, shared layer, IAM, EventBridge schedules +src/ + auto_protect/app.py # afi-auto-protect handler + health_digest/app.py # afi-health-digest handler + shared/python/ # shared layer + afi_client.py # Afi.ai backup API client + slack.py # Slack webhook helper +``` + +Deployment parameters (secret ARNs, tenant ID, policy ID, schedules) are defined in +`template.yaml` and supplied at deploy time via `samconfig.toml`. + ## Documentation The canonical map of Sea Haven's AWS infrastructure lives in Confluence. This project's `afi-backup-monitor` stack is represented there as a Mermaid subgraph. @@ -28,12 +43,13 @@ The canonical map of Sea Haven's AWS infrastructure lives in Confluence. This pr ## Setup -1. Store the Afi API key in Secrets Manager: +1. Store the Afi API key and Slack webhook URL in Secrets Manager: ```bash aws secretsmanager create-secret --name afi-api-key --secret-string "appkey-YOUR_KEY" + aws secretsmanager create-secret --name afi-slack-webhook --secret-string "https://hooks.slack.com/services/YOUR/WEBHOOK/URL" ``` -2. Update `samconfig.toml` with your Secret ARN, Tenant ID, and Policy ID. +2. Update `samconfig.toml` with your Secret ARNs (`AfiApiKeySecretArn`, `SlackWebhookSecretArn`), Tenant ID, and Policy ID. 3. Build and deploy: ```bash