mirror of
https://github.com/Sea-Haven-Industries/afi-backup-monitor.git
synced 2026-10-04 17:12:08 +00:00
62 lines
3.1 KiB
Markdown
62 lines
3.1 KiB
Markdown
# Afi Backup Monitor
|
|
|
|

|
|

|
|

|
|

|
|
|
|
HCP Terraform stack with two Lambda functions that integrate the Afi.ai backup API with Slack. Deployed to **seahaven-prod** via workspace `afi-backup-monitor-prod` (PLAT-56). The workspace working directory is `terraform/`. VCS file triggers use `trigger-patterns = [terraform/**/*, src/**/*]` because `terraform/lambda.tf` zips `src/`. A `src/`-only merge must still queue a run.
|
|
|
|
## Functions
|
|
|
|
**afi-auto-protect** — Runs weekly. Compares tenant resources against active protections and automatically applies the configured backup policy to any unprotected users. Posts a summary to Slack.
|
|
|
|
**afi-health-digest** — Runs weekly. Pulls task statistics (last 7 days), storage quotas, and resource coverage, then posts a formatted digest to Slack.
|
|
|
|
## Architecture
|
|
|
|
- **Runtime:** Python 3.12 (arm64)
|
|
- **IaC:** Terraform under `terraform/` (HCP remote apply, Manual until sealed)
|
|
- **Shared Layer:** Afi API client + Slack webhook helper
|
|
- **Secrets:** Afi API key and Slack webhook URL in Secrets Manager (ARNs as Terraform variables; values never in state)
|
|
- **Scheduling:** EventBridge cron rules (default: Mondays 10am ET)
|
|
- **IAM:** Execution roles under path `/tf-managed/` with `seahaven-lambda-execution-boundary`
|
|
|
|
## Repository Structure
|
|
|
|
```
|
|
terraform/ # HCP Terraform config (sole deploy path)
|
|
src/
|
|
auto_protect/app.py # afi-auto-protect handler
|
|
health_digest/app.py # afi-health-digest handler
|
|
shared/python/ # shared layer
|
|
afi_client.py # Afi.ai backup API client
|
|
slack.py # Slack webhook helper
|
|
```
|
|
|
|
Workspace Terraform variables: secret ARNs, tenant ID, policy ID (see `terraform/terraform.tfvars.example`).
|
|
|
|
## Documentation
|
|
|
|
The canonical map of Sea Haven's AWS infrastructure lives in Confluence. This project's `afi-backup-monitor` stack is represented there as a Mermaid subgraph.
|
|
|
|
- **[AWS Architecture Map](https://seahaven.atlassian.net/wiki/spaces/IT/pages/1540098)** (Confluence, IT space, page 1540098)
|
|
|
|
## Setup
|
|
|
|
1. Create secrets in seahaven-prod (exact ARNs are wired into the Lambda boundary and Terraform variables):
|
|
```bash
|
|
aws secretsmanager create-secret --name afi-api-key --secret-string "appkey-YOUR_KEY"
|
|
aws secretsmanager create-secret --name afi-slack-webhook --secret-string "https://hooks.slack.com/services/YOUR/WEBHOOK/URL"
|
|
```
|
|
|
|
2. Set workspace variables in HCP (`afi-backup-monitor-prod`) from `terraform/terraform.tfvars.example`.
|
|
|
|
3. Apply from the HCP workspace (Manual apply until the stack is sealed). Do not use local `terraform apply` against prod.
|
|
|
|
## Manual Testing
|
|
|
|
```bash
|
|
aws lambda invoke --function-name afi-auto-protect --payload '{}' /dev/stdout
|
|
aws lambda invoke --function-name afi-health-digest --payload '{}' /dev/stdout
|
|
```
|