mirror of
https://github.com/Sea-Haven-Industries/engineering-handbook.git
synced 2026-09-30 06:53:15 +00:00
* Update CDK version policy, Node 24 runtime, and GitHub Actions CI/CD - Pin blessed aws-cdk-lib version (2.253.1) with upgrade procedure - Update Lambda runtime default from Node 22 to Node 24 - Rewrite CI/CD page to reflect GitHub Actions reusable workflows (was still referencing CodePipeline/CodeBuild) * Add pre-push hook for npm ci validation Catches lock file drift locally before it breaks CI. Includes install instructions in git-workflow.md. * Add repo provisioning script Automates the new-repo checklist: GitHub repo creation, OIDC deploy role, repo secret, security features, CI/CD workflow stubs, and pre-push hook installation. Supports both SAM and CDK stack types. * Add shared VpnEc2Instance CDK construct Reference construct for the VPN-accessible EC2 pattern used by file-share and forgejo. Includes VPC/subnet lookup, SG, IAM role, encrypted EBS, and DLM snapshots. Copy into lib/constructs/. * Add post-deploy health check template Template script for project-specific health checks. Copy to scripts/health-check.sh — CD workflows run it automatically.
1.5 KiB
1.5 KiB
Shared CDK Constructs
Reference CDK constructs for common Sea Haven infrastructure patterns. Copy into your project's lib/constructs/ directory.
VpnEc2Instance
Encapsulates the full EC2-on-VPN pattern: VPC/subnet lookup, security group with VPN + VPC ingress, IAM role (SSM + Secrets Manager), encrypted EBS, and DLM daily snapshots.
Usage
import { VpnEc2Instance } from "./constructs/vpn-ec2-instance";
const server = new VpnEc2Instance(this, "Server", {
name: "file-share",
ingressPorts: [
{ port: 445, description: "SMB" },
{ port: 8080, description: "FileBrowser" },
],
secretsPrefix: "file-share",
dataVolumeSize: 500,
userData: myUserData,
});
// Access underlying resources for further configuration:
// server.instance, server.securityGroup, server.role
Props
| Prop | Type | Default | Description |
|---|---|---|---|
name |
string | required | Resource name prefix (kebab-case) |
ingressPorts |
IngressPort[] |
required | Ports to open from VPN and VPC CIDRs |
secretsPrefix |
string | required | Secrets Manager path prefix for IAM policy |
instanceType |
InstanceType |
t4g.small | EC2 instance type |
rootVolumeSize |
number | 20 | Root EBS volume in GiB |
dataVolumeSize |
number | — | Optional second EBS volume in GiB (mounted at /dev/xvdf) |
userData |
UserData |
— | EC2 user data script |
additionalPolicies |
PolicyStatement[] |
— | Extra IAM policies for the instance role |
snapshotRetentionDays |
number | 30 | DLM snapshot retention count |