Afi.ai backup monitoring - auto-protect users & weekly health digest via Slack
Find a file
dependabot[bot] 947861769b
chore(deps): bump boto3 (#58)
Bumps the minor-and-patch group in /src/health_digest with 1 update: [boto3](https://github.com/boto/boto3).


Updates `boto3` from 1.43.67 to 1.43.72
- [Release notes](https://github.com/boto/boto3/releases)
- [Commits](https://github.com/boto/boto3/compare/1.43.67...1.43.72)

---
updated-dependencies:
- dependency-name: boto3
  dependency-version: 1.43.72
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-08-18 20:12:13 +00:00
.github chore(deps): bump the minor-and-patch group with 4 updates (#57) 2026-08-18 20:11:24 +00:00
src chore(deps): bump boto3 (#58) 2026-08-18 20:12:13 +00:00
terraform chore(deps): bump hashicorp/aws from 5.100.0 to 6.57.1 in /terraform (#51) 2026-08-05 16:19:02 -04:00
.gitignore feat(iac): add hcp terraform config for prod migration 2026-08-05 12:01:05 -04:00
AGENTS.md ci: add org PR policy caller (PLAT-62) (#41) 2026-08-04 15:56:20 +00:00
README.md chore(afi): post-cutover hygiene after hcp migration (#48) 2026-08-05 15:54:51 -04:00

Afi Backup Monitor

CI Python Terraform Slack

HCP Terraform stack with two Lambda functions that integrate the Afi.ai backup API with Slack. Deployed to seahaven-prod via workspace afi-backup-monitor-prod (PLAT-56).

Functions

afi-auto-protect — Runs weekly. Compares tenant resources against active protections and automatically applies the configured backup policy to any unprotected users. Posts a summary to Slack.

afi-health-digest — Runs weekly. Pulls task statistics (last 7 days), storage quotas, and resource coverage, then posts a formatted digest to Slack.

Architecture

  • Runtime: Python 3.12 (arm64)
  • IaC: Terraform under terraform/ (HCP remote apply, Manual until sealed)
  • Shared Layer: Afi API client + Slack webhook helper
  • Secrets: Afi API key and Slack webhook URL in Secrets Manager (ARNs as Terraform variables; values never in state)
  • Scheduling: EventBridge cron rules (default: Mondays 10am ET)
  • IAM: Execution roles under path /tf-managed/ with seahaven-lambda-execution-boundary

Repository Structure

terraform/                  # HCP Terraform config (sole deploy path)
src/
  auto_protect/app.py       # afi-auto-protect handler
  health_digest/app.py      # afi-health-digest handler
  shared/python/            # shared layer
    afi_client.py           # Afi.ai backup API client
    slack.py                # Slack webhook helper

Workspace Terraform variables: secret ARNs, tenant ID, policy ID (see terraform/terraform.tfvars.example).

Documentation

The canonical map of Sea Haven's AWS infrastructure lives in Confluence. This project's afi-backup-monitor stack is represented there as a Mermaid subgraph.

Setup

  1. Create secrets in seahaven-prod (exact ARNs are wired into the Lambda boundary and Terraform variables):

    aws secretsmanager create-secret --name afi-api-key --secret-string "appkey-YOUR_KEY"
    aws secretsmanager create-secret --name afi-slack-webhook --secret-string "https://hooks.slack.com/services/YOUR/WEBHOOK/URL"
    
  2. Set workspace variables in HCP (afi-backup-monitor-prod) from terraform/terraform.tfvars.example.

  3. Apply from the HCP workspace (Manual apply until the stack is sealed). Do not use local terraform apply against prod.

Manual Testing

aws lambda invoke --function-name afi-auto-protect --payload '{}' /dev/stdout
aws lambda invoke --function-name afi-health-digest --payload '{}' /dev/stdout