Afi.ai backup monitoring - auto-protect users & weekly health digest via Slack
Find a file
Adam Moussa 435b7e3464
chore(afi): post-cutover hygiene after hcp migration (#48)
Remove stale SAM template and cutover docs, disable SAM validate, add
terraform Dependabot, and complete multi-platform provider lock hashes.
2026-08-05 15:54:51 -04:00
.github chore(afi): post-cutover hygiene after hcp migration (#48) 2026-08-05 15:54:51 -04:00
src chore(deps): bump boto3 (#44) 2026-08-04 18:03:20 -04:00
terraform chore(afi): post-cutover hygiene after hcp migration (#48) 2026-08-05 15:54:51 -04:00
.gitignore feat(iac): add hcp terraform config for prod migration 2026-08-05 12:01:05 -04:00
AGENTS.md ci: add org PR policy caller (PLAT-62) (#41) 2026-08-04 15:56:20 +00:00
README.md chore(afi): post-cutover hygiene after hcp migration (#48) 2026-08-05 15:54:51 -04:00

Afi Backup Monitor

CI Python Terraform Slack

HCP Terraform stack with two Lambda functions that integrate the Afi.ai backup API with Slack. Deployed to seahaven-prod via workspace afi-backup-monitor-prod (PLAT-56).

Functions

afi-auto-protect — Runs weekly. Compares tenant resources against active protections and automatically applies the configured backup policy to any unprotected users. Posts a summary to Slack.

afi-health-digest — Runs weekly. Pulls task statistics (last 7 days), storage quotas, and resource coverage, then posts a formatted digest to Slack.

Architecture

  • Runtime: Python 3.12 (arm64)
  • IaC: Terraform under terraform/ (HCP remote apply, Manual until sealed)
  • Shared Layer: Afi API client + Slack webhook helper
  • Secrets: Afi API key and Slack webhook URL in Secrets Manager (ARNs as Terraform variables; values never in state)
  • Scheduling: EventBridge cron rules (default: Mondays 10am ET)
  • IAM: Execution roles under path /tf-managed/ with seahaven-lambda-execution-boundary

Repository Structure

terraform/                  # HCP Terraform config (sole deploy path)
src/
  auto_protect/app.py       # afi-auto-protect handler
  health_digest/app.py      # afi-health-digest handler
  shared/python/            # shared layer
    afi_client.py           # Afi.ai backup API client
    slack.py                # Slack webhook helper

Workspace Terraform variables: secret ARNs, tenant ID, policy ID (see terraform/terraform.tfvars.example).

Documentation

The canonical map of Sea Haven's AWS infrastructure lives in Confluence. This project's afi-backup-monitor stack is represented there as a Mermaid subgraph.

Setup

  1. Create secrets in seahaven-prod (exact ARNs are wired into the Lambda boundary and Terraform variables):

    aws secretsmanager create-secret --name afi-api-key --secret-string "appkey-YOUR_KEY"
    aws secretsmanager create-secret --name afi-slack-webhook --secret-string "https://hooks.slack.com/services/YOUR/WEBHOOK/URL"
    
  2. Set workspace variables in HCP (afi-backup-monitor-prod) from terraform/terraform.tfvars.example.

  3. Apply from the HCP workspace (Manual apply until the stack is sealed). Do not use local terraform apply against prod.

Manual Testing

aws lambda invoke --function-name afi-auto-protect --payload '{}' /dev/stdout
aws lambda invoke --function-name afi-health-digest --payload '{}' /dev/stdout