mirror of
https://github.com/Sea-Haven-Industries/file-share.git
synced 2026-09-30 03:13:11 +00:00
fix(infra): look up the live office VPN gateway (PLAT-77) (#57)
* fix(infra): look up the live office VPN gateway (PLAT-77) The gateway tagged syslog-server-office is deleted, so the plan cannot find a route target for the office LANs. * fix(infra): select the office VPN gateway by id (PLAT-77) A state-and-VPC lookup is not unique once syslog recreates its deleted gateway. The workspace variable pins the gateway that is carrying office traffic.
This commit is contained in:
parent
7c72159f31
commit
9f27827dcb
3 changed files with 16 additions and 9 deletions
|
|
@ -89,7 +89,7 @@ Prod changes go through HCP Terraform workspace `file-share-prod` (manual apply
|
||||||
|
|
||||||
The management-account CDK workflow no longer runs on push. `workflow_dispatch` remains for an explicit rollback of that stack.
|
The management-account CDK workflow no longer runs on push. `workflow_dispatch` remains for an explicit rollback of that stack.
|
||||||
|
|
||||||
The instance has no public IP. Its route table sends `10.10.0.0/16` and `10.30.0.0/16` through the syslog VPN gateway and everything else through a NAT gateway in the syslog public subnet. `10.10.0.0/16` is the Ronkonkoma office LAN and `10.30.0.0/16` is the Locust office LAN, the same pair the syslog VPN already routes. `10.20.0.0/16` is the management VPC and is not routed here.
|
The instance has no public IP. Its route table sends `10.10.0.0/16` and `10.30.0.0/16` through the VPN gateway in workspace variable `vpn_gateway_id` and everything else through a NAT gateway in the syslog public subnet. `10.10.0.0/16` is the Ronkonkoma office LAN and `10.30.0.0/16` is the Locust office LAN, the same pair the syslog VPN already routes. `10.20.0.0/16` is the management VPC and is not routed here.
|
||||||
|
|
||||||
Clients use the private IP. Office routing must include `10.40.20.0/24` on the existing syslog IPsec before SMB from the office will work. A check from `10.10.70.0/24` on 2026-09-28 reached the gateway for `10.40.10.254` and got no hop-1 reply for `10.40.20.1`. The nightly DLM policy targets volumes tagged `file-share-backup=true`. Tag the copied volume with that key at cutover.
|
Clients use the private IP. Office routing must include `10.40.20.0/24` on the existing syslog IPsec before SMB from the office will work. A check from `10.10.70.0/24` on 2026-09-28 reached the gateway for `10.40.10.254` and got no hop-1 reply for `10.40.20.1`. The nightly DLM policy targets volumes tagged `file-share-backup=true`. Tag the copied volume with that key at cutover.
|
||||||
|
|
||||||
|
|
|
||||||
|
|
@ -12,13 +12,10 @@ data "aws_internet_gateway" "syslog" {
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
# syslog state still names a deleted gateway syslog-server-office.
|
||||||
|
# vpn_gateway_id selects the gateway that is actually carrying office traffic.
|
||||||
data "aws_vpn_gateway" "syslog" {
|
data "aws_vpn_gateway" "syslog" {
|
||||||
filter {
|
id = var.vpn_gateway_id
|
||||||
name = "tag:Name"
|
|
||||||
values = ["syslog-server-office"]
|
|
||||||
}
|
|
||||||
|
|
||||||
attached_vpc_id = data.aws_vpc.syslog.id
|
|
||||||
}
|
}
|
||||||
|
|
||||||
data "aws_subnet" "syslog_public" {
|
data "aws_subnet" "syslog_public" {
|
||||||
|
|
@ -86,8 +83,8 @@ resource "aws_subnet" "file_share" {
|
||||||
}
|
}
|
||||||
|
|
||||||
precondition {
|
precondition {
|
||||||
condition = data.aws_vpn_gateway.syslog.attached_vpc_id == data.aws_vpc.syslog.id
|
condition = data.aws_vpn_gateway.syslog.state == "available" && data.aws_vpn_gateway.syslog.attached_vpc_id == data.aws_vpc.syslog.id
|
||||||
error_message = "syslog VPN gateway is not attached to the syslog VPC."
|
error_message = "vpn_gateway_id must be an available VPN gateway attached to the syslog VPC."
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
|
||||||
|
|
@ -41,6 +41,16 @@ variable "filebrowser_password_secret_arn" {
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
variable "vpn_gateway_id" {
|
||||||
|
description = "VPN gateway that carries office traffic into the syslog VPC. Set as an HCP workspace variable. The gateway named syslog-server-office in syslog state is deleted."
|
||||||
|
type = string
|
||||||
|
|
||||||
|
validation {
|
||||||
|
condition = startswith(var.vpn_gateway_id, "vgw-")
|
||||||
|
error_message = "vpn_gateway_id must be a VPN gateway id."
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
variable "data_volume_id" {
|
variable "data_volume_id" {
|
||||||
description = "Imported data volume id. Empty until cutover. Terraform attaches this volume and must not create or delete it."
|
description = "Imported data volume id. Empty until cutover. Terraform attaches this volume and must not create or delete it."
|
||||||
type = string
|
type = string
|
||||||
|
|
|
||||||
Loading…
Add table
Reference in a new issue