* fix(infra): look up the live office VPN gateway (PLAT-77)
The gateway tagged syslog-server-office is deleted, so the plan cannot find a route target for the office LANs.
* fix(infra): select the office VPN gateway by id (PLAT-77)
A state-and-VPC lookup is not unique once syslog recreates its deleted gateway. The workspace variable pins the gateway that is carrying office traffic.
* feat(infra): add HCP Terraform for the prod file share (PLAT-77)
The prod host will live on a subnet in the syslog VPC. The data volume stays unmanaged and is attached only after a snapshot copy.
* fix(infra): pin FileBrowser version to a release tag (PLAT-77)
The version is interpolated into the boot script. Reject anything that is not a vX.Y.Z tag.
* fix(infra): keep the file share off the public internet (PLAT-77)
The instance has no public IP. Office routes use the syslog VPN gateway and other egress uses a NAT gateway. DLM targets the tagged data volume, and replacement detaches stop the instance first.
The README described the deployed AWS resources and how to deploy, but
never documented that this is a CDK (infrastructure-as-code) app or what
cdk.json is. Add an Infrastructure (CDK) section covering the app entry
point, the file-share stack, the cdk.json manifest and context cache, and
the synth/diff/deploy commands, so the IaC layer is discoverable.
CDK stack deploying a t4g.small EC2 instance with Samba and FileBrowser
for personal file storage over the site-to-site VPN. Includes 500 GiB
gp3 data volume with daily DLM snapshots.