diff --git a/src/shared/python/slack.py b/src/shared/python/slack.py index a712933..29215df 100644 --- a/src/shared/python/slack.py +++ b/src/shared/python/slack.py @@ -4,10 +4,23 @@ import json import os from urllib import request, error +_webhook_url = None + + +def _get_webhook_url(): + global _webhook_url + if _webhook_url is None: + import boto3 + client = boto3.client("secretsmanager") + secret_arn = os.environ["SLACK_WEBHOOK_SECRET_ARN"] + response = client.get_secret_value(SecretId=secret_arn) + _webhook_url = response["SecretString"] + return _webhook_url + def post_message(blocks, text="Afi Backup Monitor"): """Post a Block Kit message to Slack via webhook.""" - webhook_url = os.environ["SLACK_WEBHOOK_URL"] + webhook_url = _get_webhook_url() payload = json.dumps({"text": text, "blocks": blocks}).encode() req = request.Request( diff --git a/template.yaml b/template.yaml index 5a7c0d6..fc4a9fa 100644 --- a/template.yaml +++ b/template.yaml @@ -12,10 +12,9 @@ Parameters: AfiPolicyId: Type: String Description: Afi backup policy ID to assign to new users - SlackWebhookUrl: + SlackWebhookSecretArn: Type: String - Description: Slack incoming webhook URL - NoEcho: true + Description: ARN of the Secrets Manager secret containing the Slack webhook URL AutoProtectSchedule: Type: String Default: 'cron(0 14 ? * MON *)' @@ -36,7 +35,7 @@ Globals: Variables: AFI_API_KEY_SECRET_ARN: !Ref AfiApiKeySecretArn AFI_TENANT_ID: !Ref AfiTenantId - SLACK_WEBHOOK_URL: !Ref SlackWebhookUrl + SLACK_WEBHOOK_SECRET_ARN: !Ref SlackWebhookSecretArn Resources: SharedLayer: @@ -67,7 +66,9 @@ Resources: - Effect: Allow Action: - secretsmanager:GetSecretValue - Resource: !Ref AfiApiKeySecretArn + Resource: + - !Ref AfiApiKeySecretArn + - !Ref SlackWebhookSecretArn Events: WeeklySchedule: Type: Schedule @@ -90,7 +91,9 @@ Resources: - Effect: Allow Action: - secretsmanager:GetSecretValue - Resource: !Ref AfiApiKeySecretArn + Resource: + - !Ref AfiApiKeySecretArn + - !Ref SlackWebhookSecretArn Events: WeeklySchedule: Type: Schedule