engineering-handbook/constructs
Adam Moussa 3aa634c260 Add shared VpnEc2Instance CDK construct
Reference construct for the VPN-accessible EC2 pattern used by
file-share and forgejo. Includes VPC/subnet lookup, SG, IAM role,
encrypted EBS, and DLM snapshots. Copy into lib/constructs/.
2026-05-14 18:33:44 -04:00
..
README.md Add shared VpnEc2Instance CDK construct 2026-05-14 18:33:44 -04:00
vpn-ec2-instance.ts Add shared VpnEc2Instance CDK construct 2026-05-14 18:33:44 -04:00

Shared CDK Constructs

Reference CDK constructs for common Sea Haven infrastructure patterns. Copy into your project's lib/constructs/ directory.

VpnEc2Instance

Encapsulates the full EC2-on-VPN pattern: VPC/subnet lookup, security group with VPN + VPC ingress, IAM role (SSM + Secrets Manager), encrypted EBS, and DLM daily snapshots.

Usage

import { VpnEc2Instance } from "./constructs/vpn-ec2-instance";

const server = new VpnEc2Instance(this, "Server", {
  name: "file-share",
  ingressPorts: [
    { port: 445, description: "SMB" },
    { port: 8080, description: "FileBrowser" },
  ],
  secretsPrefix: "file-share",
  dataVolumeSize: 500,
  userData: myUserData,
});

// Access underlying resources for further configuration:
// server.instance, server.securityGroup, server.role

Props

Prop Type Default Description
name string required Resource name prefix (kebab-case)
ingressPorts IngressPort[] required Ports to open from VPN and VPC CIDRs
secretsPrefix string required Secrets Manager path prefix for IAM policy
instanceType InstanceType t4g.small EC2 instance type
rootVolumeSize number 20 Root EBS volume in GiB
dataVolumeSize number — Optional second EBS volume in GiB (mounted at /dev/xvdf)
userData UserData — EC2 user data script
additionalPolicies PolicyStatement[] — Extra IAM policies for the instance role
snapshotRetentionDays number 30 DLM snapshot retention count