|
Some checks failed
Deploy / deploy (push) Has been cancelled
Daily security sweep flagged that the README omitted template.yaml (the SAM stack) as an existing component. Add a Repository Structure section naming template.yaml and the src layout. Also fix a related setup gap: the Slack webhook Secrets Manager secret (SlackWebhookSecretArn, required by slack.py via SLACK_WEBHOOK_SECRET_ARN) was not covered by the setup instructions. |
||
|---|---|---|
| .github | ||
| src | ||
| .gitignore | ||
| README.md | ||
| template.yaml | ||
Afi Backup Monitor
AWS SAM stack with two Lambda functions that integrate the Afi.ai backup API with Slack.
Functions
afi-auto-protect — Runs weekly. Compares tenant resources against active protections and automatically applies the configured backup policy to any unprotected users. Posts a summary to Slack.
afi-health-digest — Runs weekly. Pulls task statistics (last 7 days), storage quotas, and resource coverage, then posts a formatted digest to Slack.
Architecture
- Runtime: Python 3.12 (arm64)
- Shared Layer: Afi API client + Slack webhook helper
- Secrets: Afi API key and Slack webhook URL stored in AWS Secrets Manager
- Scheduling: EventBridge cron rules (default: Mondays 10am ET)
Repository Structure
template.yaml # SAM stack: Lambdas, shared layer, IAM, EventBridge schedules
src/
auto_protect/app.py # afi-auto-protect handler
health_digest/app.py # afi-health-digest handler
shared/python/ # shared layer
afi_client.py # Afi.ai backup API client
slack.py # Slack webhook helper
Deployment parameters (secret ARNs, tenant ID, policy ID, schedules) are defined in
template.yaml and supplied at deploy time via samconfig.toml.
Documentation
The canonical map of Sea Haven's AWS infrastructure lives in Confluence. This project's afi-backup-monitor stack is represented there as a Mermaid subgraph.
- AWS Architecture Map (Confluence, IT space, page 1540098)
Setup
-
Store the Afi API key and Slack webhook URL in Secrets Manager:
aws secretsmanager create-secret --name afi-api-key --secret-string "appkey-YOUR_KEY" aws secretsmanager create-secret --name afi-slack-webhook --secret-string "https://hooks.slack.com/services/YOUR/WEBHOOK/URL" -
Update
samconfig.tomlwith your Secret ARNs (AfiApiKeySecretArn,SlackWebhookSecretArn), Tenant ID, and Policy ID. -
Build and deploy:
sam build && sam deploy
Manual Testing
aws lambda invoke --function-name afi-auto-protect --payload '{}' /dev/stdout
aws lambda invoke --function-name afi-health-digest --payload '{}' /dev/stdout