Afi.ai backup monitoring - auto-protect users & weekly health digest via Slack
Find a file
dependabot[bot] 3c80276c5b
Some checks failed
Deploy / deploy (push) Has been cancelled
chore(deps): bump boto3 from 1.43.47 to 1.43.52 in /src/health_digest and /src/auto_protect in the minor-and-patch group (#35)
* chore(deps): bump boto3

Bumps the minor-and-patch group in /src/health_digest with 1 update: [boto3](https://github.com/boto/boto3).


Updates `boto3` from 1.43.47 to 1.43.52
- [Release notes](https://github.com/boto/boto3/releases)
- [Commits](https://github.com/boto/boto3/compare/1.43.47...1.43.52)

---
updated-dependencies:
- dependency-name: boto3
  dependency-version: 1.43.52
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
...

Signed-off-by: dependabot[bot] <support@github.com>

* chore(deps): bump boto3 (#36)

Bumps the minor-and-patch group in /src/auto_protect with 1 update: [boto3](https://github.com/boto/boto3).


Updates `boto3` from 1.43.47 to 1.43.52
- [Release notes](https://github.com/boto/boto3/releases)
- [Commits](https://github.com/boto/boto3/compare/1.43.47...1.43.52)

---
updated-dependencies:
- dependency-name: boto3
  dependency-version: 1.43.52
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

---------

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-21 19:23:02 +00:00
.github ci: add github-actions to dependabot coverage (INFRA-130) (#29) 2026-07-08 16:35:10 -04:00
src chore(deps): bump boto3 from 1.43.47 to 1.43.52 in /src/health_digest and /src/auto_protect in the minor-and-patch group (#35) 2026-07-21 19:23:02 +00:00
.gitignore Initial commit: Afi backup monitor SAM stack 2026-04-06 13:42:28 -04:00
README.md docs: document template.yaml and repo structure in README (#32) 2026-07-10 19:51:50 +00:00
template.yaml Attach permissions boundary to all Lambda roles (#17) 2026-06-10 14:15:02 -04:00

Afi Backup Monitor

CI Python AWS SAM Slack

AWS SAM stack with two Lambda functions that integrate the Afi.ai backup API with Slack.

Functions

afi-auto-protect — Runs weekly. Compares tenant resources against active protections and automatically applies the configured backup policy to any unprotected users. Posts a summary to Slack.

afi-health-digest — Runs weekly. Pulls task statistics (last 7 days), storage quotas, and resource coverage, then posts a formatted digest to Slack.

Architecture

  • Runtime: Python 3.12 (arm64)
  • Shared Layer: Afi API client + Slack webhook helper
  • Secrets: Afi API key and Slack webhook URL stored in AWS Secrets Manager
  • Scheduling: EventBridge cron rules (default: Mondays 10am ET)

Repository Structure

template.yaml               # SAM stack: Lambdas, shared layer, IAM, EventBridge schedules
src/
  auto_protect/app.py       # afi-auto-protect handler
  health_digest/app.py      # afi-health-digest handler
  shared/python/            # shared layer
    afi_client.py           # Afi.ai backup API client
    slack.py                # Slack webhook helper

Deployment parameters (secret ARNs, tenant ID, policy ID, schedules) are defined in template.yaml and supplied at deploy time via samconfig.toml.

Documentation

The canonical map of Sea Haven's AWS infrastructure lives in Confluence. This project's afi-backup-monitor stack is represented there as a Mermaid subgraph.

Setup

  1. Store the Afi API key and Slack webhook URL in Secrets Manager:

    aws secretsmanager create-secret --name afi-api-key --secret-string "appkey-YOUR_KEY"
    aws secretsmanager create-secret --name afi-slack-webhook --secret-string "https://hooks.slack.com/services/YOUR/WEBHOOK/URL"
    
  2. Update samconfig.toml with your Secret ARNs (AfiApiKeySecretArn, SlackWebhookSecretArn), Tenant ID, and Policy ID.

  3. Build and deploy:

    sam build && sam deploy
    

Manual Testing

aws lambda invoke --function-name afi-auto-protect --payload '{}' /dev/stdout
aws lambda invoke --function-name afi-health-digest --payload '{}' /dev/stdout