mirror of
https://github.com/Sea-Haven-Industries/afi-backup-monitor.git
synced 2026-09-30 07:13:11 +00:00
Some checks are pending
Deploy / deploy (push) Waiting to run
Scopes IAM role creation to the seahaven-lambda-execution-boundary policy so the github-cfn-execution-role scope-down (INFRA-97) can safely constrain CreateRole to boundary-attached roles only. Refs: INFRA-103
112 lines
3.3 KiB
YAML
112 lines
3.3 KiB
YAML
AWSTemplateFormatVersion: '2010-09-09'
|
|
Transform: AWS::Serverless-2016-10-31
|
|
Description: Afi.ai Backup Monitor - Auto-protect new users and weekly health digest
|
|
|
|
Parameters:
|
|
AfiApiKeySecretArn:
|
|
Type: String
|
|
Description: ARN of the Secrets Manager secret containing the Afi API key
|
|
AfiTenantId:
|
|
Type: String
|
|
Description: Afi tenant ID for your Google Workspace
|
|
AfiPolicyId:
|
|
Type: String
|
|
Description: Afi backup policy ID to assign to new users
|
|
SlackWebhookSecretArn:
|
|
Type: String
|
|
Description: ARN of the Secrets Manager secret containing the Slack webhook URL
|
|
AutoProtectSchedule:
|
|
Type: String
|
|
Default: 'cron(0 14 ? * MON *)'
|
|
Description: Schedule for auto-protect check (default Monday 10am ET)
|
|
HealthDigestSchedule:
|
|
Type: String
|
|
Default: 'cron(0 14 ? * MON *)'
|
|
Description: Schedule for weekly health digest (default Monday 10am ET)
|
|
|
|
Globals:
|
|
Function:
|
|
Runtime: python3.12
|
|
Timeout: 120
|
|
MemorySize: 256
|
|
Architectures:
|
|
- arm64
|
|
PermissionsBoundary: arn:aws:iam::328440206208:policy/seahaven-lambda-execution-boundary
|
|
Environment:
|
|
Variables:
|
|
AFI_API_KEY_SECRET_ARN: !Ref AfiApiKeySecretArn
|
|
AFI_TENANT_ID: !Ref AfiTenantId
|
|
SLACK_WEBHOOK_SECRET_ARN: !Ref SlackWebhookSecretArn
|
|
|
|
Resources:
|
|
SharedLayer:
|
|
Type: AWS::Serverless::LayerVersion
|
|
Properties:
|
|
LayerName: afi-shared
|
|
Description: Shared Afi API client and utilities
|
|
ContentUri: src/shared/
|
|
CompatibleRuntimes:
|
|
- python3.12
|
|
CompatibleArchitectures:
|
|
- arm64
|
|
|
|
AutoProtectFunction:
|
|
Type: AWS::Serverless::Function
|
|
Properties:
|
|
FunctionName: afi-auto-protect
|
|
Handler: app.handler
|
|
CodeUri: src/auto_protect/
|
|
Layers:
|
|
- !Ref SharedLayer
|
|
Environment:
|
|
Variables:
|
|
AFI_POLICY_ID: !Ref AfiPolicyId
|
|
Policies:
|
|
- Version: '2012-10-17'
|
|
Statement:
|
|
- Effect: Allow
|
|
Action:
|
|
- secretsmanager:GetSecretValue
|
|
Resource:
|
|
- !Ref AfiApiKeySecretArn
|
|
- !Ref SlackWebhookSecretArn
|
|
Events:
|
|
WeeklySchedule:
|
|
Type: Schedule
|
|
Properties:
|
|
Schedule: !Ref AutoProtectSchedule
|
|
Description: Weekly check for unprotected users
|
|
Enabled: true
|
|
|
|
HealthDigestFunction:
|
|
Type: AWS::Serverless::Function
|
|
Properties:
|
|
FunctionName: afi-health-digest
|
|
Handler: app.handler
|
|
CodeUri: src/health_digest/
|
|
Layers:
|
|
- !Ref SharedLayer
|
|
Policies:
|
|
- Version: '2012-10-17'
|
|
Statement:
|
|
- Effect: Allow
|
|
Action:
|
|
- secretsmanager:GetSecretValue
|
|
Resource:
|
|
- !Ref AfiApiKeySecretArn
|
|
- !Ref SlackWebhookSecretArn
|
|
Events:
|
|
WeeklySchedule:
|
|
Type: Schedule
|
|
Properties:
|
|
Schedule: !Ref HealthDigestSchedule
|
|
Description: Weekly backup health digest to Slack
|
|
Enabled: true
|
|
|
|
Outputs:
|
|
AutoProtectFunctionArn:
|
|
Description: Auto-protect Lambda ARN
|
|
Value: !GetAtt AutoProtectFunction.Arn
|
|
HealthDigestFunctionArn:
|
|
Description: Health digest Lambda ARN
|
|
Value: !GetAtt HealthDigestFunction.Arn
|