# Afi Backup Monitor ![CI](https://github.com/Sea-Haven-Industries/afi-backup-monitor/actions/workflows/ci.yaml/badge.svg) ![Python](https://img.shields.io/badge/Python-3776AB?logo=python&logoColor=white) ![AWS SAM](https://img.shields.io/badge/AWS-SAM-FF9900?logo=amazonaws&logoColor=white) ![Slack](https://img.shields.io/badge/Slack-integration-4A154B?logo=slack&logoColor=white) AWS SAM stack with two Lambda functions that integrate the Afi.ai backup API with Slack. ## Functions **afi-auto-protect** — Runs weekly. Compares tenant resources against active protections and automatically applies the configured backup policy to any unprotected users. Posts a summary to Slack. **afi-health-digest** — Runs weekly. Pulls task statistics (last 7 days), storage quotas, and resource coverage, then posts a formatted digest to Slack. ## Architecture - **Runtime:** Python 3.12 (arm64) - **Shared Layer:** Afi API client + Slack webhook helper - **Secrets:** Afi API key and Slack webhook URL stored in AWS Secrets Manager - **Scheduling:** EventBridge cron rules (default: Mondays 10am ET) ## Repository Structure ``` template.yaml # SAM stack: Lambdas, shared layer, IAM, EventBridge schedules src/ auto_protect/app.py # afi-auto-protect handler health_digest/app.py # afi-health-digest handler shared/python/ # shared layer afi_client.py # Afi.ai backup API client slack.py # Slack webhook helper ``` Deployment parameters (secret ARNs, tenant ID, policy ID, schedules) are defined in `template.yaml` and supplied at deploy time via `samconfig.toml`. ## Documentation The canonical map of Sea Haven's AWS infrastructure lives in Confluence. This project's `afi-backup-monitor` stack is represented there as a Mermaid subgraph. - **[AWS Architecture Map](https://seahaven.atlassian.net/wiki/spaces/IT/pages/1540098)** (Confluence, IT space, page 1540098) ## Setup 1. Store the Afi API key and Slack webhook URL in Secrets Manager: ```bash aws secretsmanager create-secret --name afi-api-key --secret-string "appkey-YOUR_KEY" aws secretsmanager create-secret --name afi-slack-webhook --secret-string "https://hooks.slack.com/services/YOUR/WEBHOOK/URL" ``` 2. Update `samconfig.toml` with your Secret ARNs (`AfiApiKeySecretArn`, `SlackWebhookSecretArn`), Tenant ID, and Policy ID. 3. Build and deploy: ```bash sam build && sam deploy ``` ## Manual Testing ```bash aws lambda invoke --function-name afi-auto-protect --payload '{}' /dev/stdout aws lambda invoke --function-name afi-health-digest --payload '{}' /dev/stdout ```