afi-backup-monitor/template.yaml
Adam Moussa b8353e20aa
Some checks are pending
Deploy / deploy (push) Waiting to run
Attach permissions boundary to all Lambda roles (#17)
Scopes IAM role creation to the seahaven-lambda-execution-boundary
policy so the github-cfn-execution-role scope-down (INFRA-97) can
safely constrain CreateRole to boundary-attached roles only.

Refs: INFRA-103
2026-06-10 14:15:02 -04:00

112 lines
3.3 KiB
YAML

AWSTemplateFormatVersion: '2010-09-09'
Transform: AWS::Serverless-2016-10-31
Description: Afi.ai Backup Monitor - Auto-protect new users and weekly health digest
Parameters:
AfiApiKeySecretArn:
Type: String
Description: ARN of the Secrets Manager secret containing the Afi API key
AfiTenantId:
Type: String
Description: Afi tenant ID for your Google Workspace
AfiPolicyId:
Type: String
Description: Afi backup policy ID to assign to new users
SlackWebhookSecretArn:
Type: String
Description: ARN of the Secrets Manager secret containing the Slack webhook URL
AutoProtectSchedule:
Type: String
Default: 'cron(0 14 ? * MON *)'
Description: Schedule for auto-protect check (default Monday 10am ET)
HealthDigestSchedule:
Type: String
Default: 'cron(0 14 ? * MON *)'
Description: Schedule for weekly health digest (default Monday 10am ET)
Globals:
Function:
Runtime: python3.12
Timeout: 120
MemorySize: 256
Architectures:
- arm64
PermissionsBoundary: arn:aws:iam::328440206208:policy/seahaven-lambda-execution-boundary
Environment:
Variables:
AFI_API_KEY_SECRET_ARN: !Ref AfiApiKeySecretArn
AFI_TENANT_ID: !Ref AfiTenantId
SLACK_WEBHOOK_SECRET_ARN: !Ref SlackWebhookSecretArn
Resources:
SharedLayer:
Type: AWS::Serverless::LayerVersion
Properties:
LayerName: afi-shared
Description: Shared Afi API client and utilities
ContentUri: src/shared/
CompatibleRuntimes:
- python3.12
CompatibleArchitectures:
- arm64
AutoProtectFunction:
Type: AWS::Serverless::Function
Properties:
FunctionName: afi-auto-protect
Handler: app.handler
CodeUri: src/auto_protect/
Layers:
- !Ref SharedLayer
Environment:
Variables:
AFI_POLICY_ID: !Ref AfiPolicyId
Policies:
- Version: '2012-10-17'
Statement:
- Effect: Allow
Action:
- secretsmanager:GetSecretValue
Resource:
- !Ref AfiApiKeySecretArn
- !Ref SlackWebhookSecretArn
Events:
WeeklySchedule:
Type: Schedule
Properties:
Schedule: !Ref AutoProtectSchedule
Description: Weekly check for unprotected users
Enabled: true
HealthDigestFunction:
Type: AWS::Serverless::Function
Properties:
FunctionName: afi-health-digest
Handler: app.handler
CodeUri: src/health_digest/
Layers:
- !Ref SharedLayer
Policies:
- Version: '2012-10-17'
Statement:
- Effect: Allow
Action:
- secretsmanager:GetSecretValue
Resource:
- !Ref AfiApiKeySecretArn
- !Ref SlackWebhookSecretArn
Events:
WeeklySchedule:
Type: Schedule
Properties:
Schedule: !Ref HealthDigestSchedule
Description: Weekly backup health digest to Slack
Enabled: true
Outputs:
AutoProtectFunctionArn:
Description: Auto-protect Lambda ARN
Value: !GetAtt AutoProtectFunction.Arn
HealthDigestFunctionArn:
Description: Health digest Lambda ARN
Value: !GetAtt HealthDigestFunction.Arn