afi-backup-monitor/README.md
Adam Moussa 22f4268777 Initial commit: Afi backup monitor SAM stack
Two Lambda functions that integrate Afi.ai backup API with Slack:
- Auto-protect: weekly scan for unprotected users, applies backup policy
- Health digest: weekly backup task stats, quotas, and coverage report

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-04-06 13:42:28 -04:00

37 lines
1.2 KiB
Markdown

# Afi Backup Monitor
AWS SAM stack with two Lambda functions that integrate the Afi.ai backup API with Slack.
## Functions
**afi-auto-protect** — Runs weekly. Compares tenant resources against active protections and automatically applies the configured backup policy to any unprotected users. Posts a summary to Slack.
**afi-health-digest** — Runs weekly. Pulls task statistics (last 7 days), storage quotas, and resource coverage, then posts a formatted digest to Slack.
## Architecture
- **Runtime:** Python 3.12 (arm64)
- **Shared Layer:** Afi API client + Slack webhook helper
- **Secrets:** Afi API key stored in AWS Secrets Manager
- **Scheduling:** EventBridge cron rules (default: Mondays 10am ET)
## Setup
1. Store the Afi API key in Secrets Manager:
```bash
aws secretsmanager create-secret --name afi-api-key --secret-string "appkey-YOUR_KEY"
```
2. Update `samconfig.toml` with your Secret ARN, Tenant ID, and Policy ID.
3. Build and deploy:
```bash
sam build && sam deploy
```
## Manual Testing
```bash
aws lambda invoke --function-name afi-auto-protect --payload '{}' /dev/stdout
aws lambda invoke --function-name afi-health-digest --payload '{}' /dev/stdout
```