afi-backup-monitor/README.md
Adam Moussa 7fb5758194
Some checks failed
Deploy / deploy (push) Has been cancelled
Add PR labeler caller + README badges (INFRA-56, INFRA-57) (#18)
Add the org reusable labeler caller (callable-labeler.yaml@main) and a
static badge block (CI status, Python, AWS SAM, Slack) under the README
H1. Part of the INFRA-47 GitHub-hygiene rollout.
2026-06-11 14:13:08 -04:00

42 lines
1.5 KiB
Markdown

# Afi Backup Monitor
![CI](https://github.com/Sea-Haven-Industries/afi-backup-monitor/actions/workflows/ci.yaml/badge.svg)
![Python](https://img.shields.io/badge/Python-3776AB?logo=python&logoColor=white)
![AWS SAM](https://img.shields.io/badge/AWS-SAM-FF9900?logo=amazonaws&logoColor=white)
![Slack](https://img.shields.io/badge/Slack-integration-4A154B?logo=slack&logoColor=white)
AWS SAM stack with two Lambda functions that integrate the Afi.ai backup API with Slack.
## Functions
**afi-auto-protect** — Runs weekly. Compares tenant resources against active protections and automatically applies the configured backup policy to any unprotected users. Posts a summary to Slack.
**afi-health-digest** — Runs weekly. Pulls task statistics (last 7 days), storage quotas, and resource coverage, then posts a formatted digest to Slack.
## Architecture
- **Runtime:** Python 3.12 (arm64)
- **Shared Layer:** Afi API client + Slack webhook helper
- **Secrets:** Afi API key stored in AWS Secrets Manager
- **Scheduling:** EventBridge cron rules (default: Mondays 10am ET)
## Setup
1. Store the Afi API key in Secrets Manager:
```bash
aws secretsmanager create-secret --name afi-api-key --secret-string "appkey-YOUR_KEY"
```
2. Update `samconfig.toml` with your Secret ARN, Tenant ID, and Policy ID.
3. Build and deploy:
```bash
sam build && sam deploy
```
## Manual Testing
```bash
aws lambda invoke --function-name afi-auto-protect --payload '{}' /dev/stdout
aws lambda invoke --function-name afi-health-digest --payload '{}' /dev/stdout
```