Merge pull request #1 from Sea-Haven-Industries/feature/move-webhook-to-secrets-manager

Move Slack webhook URL to Secrets Manager
This commit is contained in:
Adam Moussa 2026-04-28 15:15:31 -04:00 • committed by GitHub
commit e5cfc94009
No known key found for this signature in database
GPG key ID: B5690EEEBB952194
2 changed files with 23 additions and 7 deletions

View file

@ -4,10 +4,23 @@ import json
import os
from urllib import request, error
_webhook_url = None
def _get_webhook_url():
global _webhook_url
if _webhook_url is None:
import boto3
client = boto3.client("secretsmanager")
secret_arn = os.environ["SLACK_WEBHOOK_SECRET_ARN"]
response = client.get_secret_value(SecretId=secret_arn)
_webhook_url = response["SecretString"]
return _webhook_url
def post_message(blocks, text="Afi Backup Monitor"):
"""Post a Block Kit message to Slack via webhook."""
webhook_url = os.environ["SLACK_WEBHOOK_URL"]
webhook_url = _get_webhook_url()
payload = json.dumps({"text": text, "blocks": blocks}).encode()
req = request.Request(

View file

@ -12,10 +12,9 @@ Parameters:
AfiPolicyId:
Type: String
Description: Afi backup policy ID to assign to new users
SlackWebhookUrl:
SlackWebhookSecretArn:
Type: String
Description: Slack incoming webhook URL
NoEcho: true
Description: ARN of the Secrets Manager secret containing the Slack webhook URL
AutoProtectSchedule:
Type: String
Default: 'cron(0 14 ? * MON *)'
@ -36,7 +35,7 @@ Globals:
Variables:
AFI_API_KEY_SECRET_ARN: !Ref AfiApiKeySecretArn
AFI_TENANT_ID: !Ref AfiTenantId
SLACK_WEBHOOK_URL: !Ref SlackWebhookUrl
SLACK_WEBHOOK_SECRET_ARN: !Ref SlackWebhookSecretArn
Resources:
SharedLayer:
@ -67,7 +66,9 @@ Resources:
- Effect: Allow
Action:
- secretsmanager:GetSecretValue
Resource: !Ref AfiApiKeySecretArn
Resource:
- !Ref AfiApiKeySecretArn
- !Ref SlackWebhookSecretArn
Events:
WeeklySchedule:
Type: Schedule
@ -90,7 +91,9 @@ Resources:
- Effect: Allow
Action:
- secretsmanager:GetSecretValue
Resource: !Ref AfiApiKeySecretArn
Resource:
- !Ref AfiApiKeySecretArn
- !Ref SlackWebhookSecretArn
Events:
WeeklySchedule:
Type: Schedule