|
Some checks are pending
Deploy / deploy (push) Waiting to run
* ci: add org PR policy caller Refs: PLAT-62 * fix(ci): name PR policy workflow Refs: PLAT-62 |
||
|---|---|---|
| .github | ||
| src | ||
| .gitignore | ||
| AGENTS.md | ||
| README.md | ||
| template.yaml | ||
Afi Backup Monitor
AWS SAM stack with two Lambda functions that integrate the Afi.ai backup API with Slack.
Functions
afi-auto-protect — Runs weekly. Compares tenant resources against active protections and automatically applies the configured backup policy to any unprotected users. Posts a summary to Slack.
afi-health-digest — Runs weekly. Pulls task statistics (last 7 days), storage quotas, and resource coverage, then posts a formatted digest to Slack.
Architecture
- Runtime: Python 3.12 (arm64)
- Shared Layer: Afi API client + Slack webhook helper
- Secrets: Afi API key and Slack webhook URL stored in AWS Secrets Manager
- Scheduling: EventBridge cron rules (default: Mondays 10am ET)
Repository Structure
template.yaml # SAM stack: Lambdas, shared layer, IAM, EventBridge schedules
src/
auto_protect/app.py # afi-auto-protect handler
health_digest/app.py # afi-health-digest handler
shared/python/ # shared layer
afi_client.py # Afi.ai backup API client
slack.py # Slack webhook helper
Deployment parameters (secret ARNs, tenant ID, policy ID, schedules) are defined in
template.yaml and supplied at deploy time via samconfig.toml.
Documentation
The canonical map of Sea Haven's AWS infrastructure lives in Confluence. This project's afi-backup-monitor stack is represented there as a Mermaid subgraph.
- AWS Architecture Map (Confluence, IT space, page 1540098)
Setup
-
Store the Afi API key and Slack webhook URL in Secrets Manager:
aws secretsmanager create-secret --name afi-api-key --secret-string "appkey-YOUR_KEY" aws secretsmanager create-secret --name afi-slack-webhook --secret-string "https://hooks.slack.com/services/YOUR/WEBHOOK/URL" -
Update
samconfig.tomlwith your Secret ARNs (AfiApiKeySecretArn,SlackWebhookSecretArn), Tenant ID, and Policy ID. -
Build and deploy:
sam build && sam deploy
Manual Testing
aws lambda invoke --function-name afi-auto-protect --payload '{}' /dev/stdout
aws lambda invoke --function-name afi-health-digest --payload '{}' /dev/stdout