diff --git a/README.md b/README.md index c57d4db..1dff49d 100644 --- a/README.md +++ b/README.md @@ -89,7 +89,7 @@ Prod changes go through HCP Terraform workspace `file-share-prod` (manual apply The management-account CDK workflow no longer runs on push. `workflow_dispatch` remains for an explicit rollback of that stack. -The instance has no public IP. Its route table sends `10.10.0.0/16` and `10.30.0.0/16` through the syslog VPN gateway and everything else through a NAT gateway in the syslog public subnet. `10.10.0.0/16` is the Ronkonkoma office LAN and `10.30.0.0/16` is the Locust office LAN, the same pair the syslog VPN already routes. `10.20.0.0/16` is the management VPC and is not routed here. +The instance has no public IP. Its route table sends `10.10.0.0/16` and `10.30.0.0/16` through the VPN gateway in workspace variable `vpn_gateway_id` and everything else through a NAT gateway in the syslog public subnet. `10.10.0.0/16` is the Ronkonkoma office LAN and `10.30.0.0/16` is the Locust office LAN, the same pair the syslog VPN already routes. `10.20.0.0/16` is the management VPC and is not routed here. Clients use the private IP. Office routing must include `10.40.20.0/24` on the existing syslog IPsec before SMB from the office will work. A check from `10.10.70.0/24` on 2026-09-28 reached the gateway for `10.40.10.254` and got no hop-1 reply for `10.40.20.1`. The nightly DLM policy targets volumes tagged `file-share-backup=true`. Tag the copied volume with that key at cutover. diff --git a/terraform/network.tf b/terraform/network.tf index fde4230..eb8c157 100644 --- a/terraform/network.tf +++ b/terraform/network.tf @@ -12,11 +12,10 @@ data "aws_internet_gateway" "syslog" { } } -# The gateway named syslog-server-office in syslog state is deleted. -# Office traffic uses the one available gateway still attached to this VPC. +# syslog state still names a deleted gateway syslog-server-office. +# vpn_gateway_id selects the gateway that is actually carrying office traffic. data "aws_vpn_gateway" "syslog" { - state = "available" - attached_vpc_id = data.aws_vpc.syslog.id + id = var.vpn_gateway_id } data "aws_subnet" "syslog_public" { @@ -84,8 +83,8 @@ resource "aws_subnet" "file_share" { } precondition { - condition = data.aws_vpn_gateway.syslog.attached_vpc_id == data.aws_vpc.syslog.id - error_message = "syslog VPN gateway is not attached to the syslog VPC." + condition = data.aws_vpn_gateway.syslog.state == "available" && data.aws_vpn_gateway.syslog.attached_vpc_id == data.aws_vpc.syslog.id + error_message = "vpn_gateway_id must be an available VPN gateway attached to the syslog VPC." } } } diff --git a/terraform/variables.tf b/terraform/variables.tf index d2d4b2f..e7ff021 100644 --- a/terraform/variables.tf +++ b/terraform/variables.tf @@ -41,6 +41,16 @@ variable "filebrowser_password_secret_arn" { } } +variable "vpn_gateway_id" { + description = "VPN gateway that carries office traffic into the syslog VPC. Set as an HCP workspace variable. The gateway named syslog-server-office in syslog state is deleted." + type = string + + validation { + condition = startswith(var.vpn_gateway_id, "vgw-") + error_message = "vpn_gateway_id must be a VPN gateway id." + } +} + variable "data_volume_id" { description = "Imported data volume id. Empty until cutover. Terraform attaches this volume and must not create or delete it." type = string