engineering-handbook/constructs/README.md
Adam Moussa 4b5d39fb91
Add CDK version policy, update Node 24 and GitHub Actions CI/CD (#6)
* Update CDK version policy, Node 24 runtime, and GitHub Actions CI/CD

- Pin blessed aws-cdk-lib version (2.253.1) with upgrade procedure
- Update Lambda runtime default from Node 22 to Node 24
- Rewrite CI/CD page to reflect GitHub Actions reusable workflows
  (was still referencing CodePipeline/CodeBuild)

* Add pre-push hook for npm ci validation

Catches lock file drift locally before it breaks CI. Includes
install instructions in git-workflow.md.

* Add repo provisioning script

Automates the new-repo checklist: GitHub repo creation, OIDC deploy
role, repo secret, security features, CI/CD workflow stubs, and
pre-push hook installation. Supports both SAM and CDK stack types.

* Add shared VpnEc2Instance CDK construct

Reference construct for the VPN-accessible EC2 pattern used by
file-share and forgejo. Includes VPC/subnet lookup, SG, IAM role,
encrypted EBS, and DLM snapshots. Copy into lib/constructs/.

* Add post-deploy health check template

Template script for project-specific health checks. Copy to
scripts/health-check.sh — CD workflows run it automatically.
2026-05-14 18:39:13 -04:00

41 lines
1.5 KiB
Markdown

# Shared CDK Constructs
Reference CDK constructs for common Sea Haven infrastructure patterns. Copy into your project's `lib/constructs/` directory.
## VpnEc2Instance
Encapsulates the full EC2-on-VPN pattern: VPC/subnet lookup, security group with VPN + VPC ingress, IAM role (SSM + Secrets Manager), encrypted EBS, and DLM daily snapshots.
### Usage
```typescript
import { VpnEc2Instance } from "./constructs/vpn-ec2-instance";
const server = new VpnEc2Instance(this, "Server", {
name: "file-share",
ingressPorts: [
{ port: 445, description: "SMB" },
{ port: 8080, description: "FileBrowser" },
],
secretsPrefix: "file-share",
dataVolumeSize: 500,
userData: myUserData,
});
// Access underlying resources for further configuration:
// server.instance, server.securityGroup, server.role
```
### Props
| Prop | Type | Default | Description |
|---|---|---|---|
| `name` | string | required | Resource name prefix (kebab-case) |
| `ingressPorts` | `IngressPort[]` | required | Ports to open from VPN and VPC CIDRs |
| `secretsPrefix` | string | required | Secrets Manager path prefix for IAM policy |
| `instanceType` | `InstanceType` | t4g.small | EC2 instance type |
| `rootVolumeSize` | number | 20 | Root EBS volume in GiB |
| `dataVolumeSize` | number | — | Optional second EBS volume in GiB (mounted at /dev/xvdf) |
| `userData` | `UserData` | — | EC2 user data script |
| `additionalPolicies` | `PolicyStatement[]` | — | Extra IAM policies for the instance role |
| `snapshotRetentionDays` | number | 30 | DLM snapshot retention count |