engineering-handbook/constructs/README.md
Adam Moussa 4b5d39fb91
Add CDK version policy, update Node 24 and GitHub Actions CI/CD (#6)
* Update CDK version policy, Node 24 runtime, and GitHub Actions CI/CD

- Pin blessed aws-cdk-lib version (2.253.1) with upgrade procedure
- Update Lambda runtime default from Node 22 to Node 24
- Rewrite CI/CD page to reflect GitHub Actions reusable workflows
  (was still referencing CodePipeline/CodeBuild)

* Add pre-push hook for npm ci validation

Catches lock file drift locally before it breaks CI. Includes
install instructions in git-workflow.md.

* Add repo provisioning script

Automates the new-repo checklist: GitHub repo creation, OIDC deploy
role, repo secret, security features, CI/CD workflow stubs, and
pre-push hook installation. Supports both SAM and CDK stack types.

* Add shared VpnEc2Instance CDK construct

Reference construct for the VPN-accessible EC2 pattern used by
file-share and forgejo. Includes VPC/subnet lookup, SG, IAM role,
encrypted EBS, and DLM snapshots. Copy into lib/constructs/.

* Add post-deploy health check template

Template script for project-specific health checks. Copy to
scripts/health-check.sh — CD workflows run it automatically.
2026-05-14 18:39:13 -04:00

1.5 KiB

Shared CDK Constructs

Reference CDK constructs for common Sea Haven infrastructure patterns. Copy into your project's lib/constructs/ directory.

VpnEc2Instance

Encapsulates the full EC2-on-VPN pattern: VPC/subnet lookup, security group with VPN + VPC ingress, IAM role (SSM + Secrets Manager), encrypted EBS, and DLM daily snapshots.

Usage

import { VpnEc2Instance } from "./constructs/vpn-ec2-instance";

const server = new VpnEc2Instance(this, "Server", {
  name: "file-share",
  ingressPorts: [
    { port: 445, description: "SMB" },
    { port: 8080, description: "FileBrowser" },
  ],
  secretsPrefix: "file-share",
  dataVolumeSize: 500,
  userData: myUserData,
});

// Access underlying resources for further configuration:
// server.instance, server.securityGroup, server.role

Props

Prop Type Default Description
name string required Resource name prefix (kebab-case)
ingressPorts IngressPort[] required Ports to open from VPN and VPC CIDRs
secretsPrefix string required Secrets Manager path prefix for IAM policy
instanceType InstanceType t4g.small EC2 instance type
rootVolumeSize number 20 Root EBS volume in GiB
dataVolumeSize number — Optional second EBS volume in GiB (mounted at /dev/xvdf)
userData UserData — EC2 user data script
additionalPolicies PolicyStatement[] — Extra IAM policies for the instance role
snapshotRetentionDays number 30 DLM snapshot retention count