Afi.ai backup monitoring - auto-protect users & weekly health digest via Slack
Find a file
dependabot[bot] 54fe1e68b6
Bump boto3 in /src/health_digest in the minor-and-patch group (#27)
Bumps the minor-and-patch group in /src/health_digest with 1 update: [boto3](https://github.com/boto/boto3).


Updates `boto3` from 1.43.37 to 1.43.41
- [Release notes](https://github.com/boto/boto3/releases)
- [Commits](https://github.com/boto/boto3/compare/1.43.37...1.43.41)

---
updated-dependencies:
- dependency-name: boto3
  dependency-version: 1.43.41
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-07 15:48:30 -04:00
.github chore(ci): SHA-pin org reusable-workflow caller refs (INFRA-50) (#26) 2026-07-06 18:26:55 -04:00
src Bump boto3 in /src/health_digest in the minor-and-patch group (#27) 2026-07-07 15:48:30 -04:00
.gitignore Initial commit: Afi backup monitor SAM stack 2026-04-06 13:42:28 -04:00
README.md docs: link Confluence AWS Architecture Map (INFRA-53) (#25) 2026-07-06 17:44:15 -04:00
template.yaml Attach permissions boundary to all Lambda roles (#17) 2026-06-10 14:15:02 -04:00

Afi Backup Monitor

CI Python AWS SAM Slack

AWS SAM stack with two Lambda functions that integrate the Afi.ai backup API with Slack.

Functions

afi-auto-protect — Runs weekly. Compares tenant resources against active protections and automatically applies the configured backup policy to any unprotected users. Posts a summary to Slack.

afi-health-digest — Runs weekly. Pulls task statistics (last 7 days), storage quotas, and resource coverage, then posts a formatted digest to Slack.

Architecture

  • Runtime: Python 3.12 (arm64)
  • Shared Layer: Afi API client + Slack webhook helper
  • Secrets: Afi API key stored in AWS Secrets Manager
  • Scheduling: EventBridge cron rules (default: Mondays 10am ET)

Documentation

The canonical map of Sea Haven's AWS infrastructure lives in Confluence. This project's afi-backup-monitor stack is represented there as a Mermaid subgraph.

Setup

  1. Store the Afi API key in Secrets Manager:

    aws secretsmanager create-secret --name afi-api-key --secret-string "appkey-YOUR_KEY"
    
  2. Update samconfig.toml with your Secret ARN, Tenant ID, and Policy ID.

  3. Build and deploy:

    sam build && sam deploy
    

Manual Testing

aws lambda invoke --function-name afi-auto-protect --payload '{}' /dev/stdout
aws lambda invoke --function-name afi-health-digest --payload '{}' /dev/stdout