Remove stale SAM template and cutover docs, disable SAM validate, add terraform Dependabot, and complete multi-platform provider lock hashes. |
||
|---|---|---|
| .github | ||
| src | ||
| terraform | ||
| .gitignore | ||
| AGENTS.md | ||
| README.md | ||
Afi Backup Monitor
HCP Terraform stack with two Lambda functions that integrate the Afi.ai backup API with Slack. Deployed to seahaven-prod via workspace afi-backup-monitor-prod (PLAT-56).
Functions
afi-auto-protect — Runs weekly. Compares tenant resources against active protections and automatically applies the configured backup policy to any unprotected users. Posts a summary to Slack.
afi-health-digest — Runs weekly. Pulls task statistics (last 7 days), storage quotas, and resource coverage, then posts a formatted digest to Slack.
Architecture
- Runtime: Python 3.12 (arm64)
- IaC: Terraform under
terraform/(HCP remote apply, Manual until sealed) - Shared Layer: Afi API client + Slack webhook helper
- Secrets: Afi API key and Slack webhook URL in Secrets Manager (ARNs as Terraform variables; values never in state)
- Scheduling: EventBridge cron rules (default: Mondays 10am ET)
- IAM: Execution roles under path
/tf-managed/withseahaven-lambda-execution-boundary
Repository Structure
terraform/ # HCP Terraform config (sole deploy path)
src/
auto_protect/app.py # afi-auto-protect handler
health_digest/app.py # afi-health-digest handler
shared/python/ # shared layer
afi_client.py # Afi.ai backup API client
slack.py # Slack webhook helper
Workspace Terraform variables: secret ARNs, tenant ID, policy ID (see terraform/terraform.tfvars.example).
Documentation
The canonical map of Sea Haven's AWS infrastructure lives in Confluence. This project's afi-backup-monitor stack is represented there as a Mermaid subgraph.
- AWS Architecture Map (Confluence, IT space, page 1540098)
Setup
-
Create secrets in seahaven-prod (exact ARNs are wired into the Lambda boundary and Terraform variables):
aws secretsmanager create-secret --name afi-api-key --secret-string "appkey-YOUR_KEY" aws secretsmanager create-secret --name afi-slack-webhook --secret-string "https://hooks.slack.com/services/YOUR/WEBHOOK/URL" -
Set workspace variables in HCP (
afi-backup-monitor-prod) fromterraform/terraform.tfvars.example. -
Apply from the HCP workspace (Manual apply until the stack is sealed). Do not use local
terraform applyagainst prod.
Manual Testing
aws lambda invoke --function-name afi-auto-protect --payload '{}' /dev/stdout
aws lambda invoke --function-name afi-health-digest --payload '{}' /dev/stdout