* fix(infra): run nightly snapshots as a stack-local DLM role (PLAT-77)
The lifecycle policy assumed a service-linked role AWS does not provide, so it stayed in ERROR and never snapshotted the data volume.
* fix(infra): scope DLM snapshot sharing to snapshot ARNs
ModifySnapshotAttribute on every resource can share a snapshot. The boundary allows it only on snapshot ARNs.
* fix(infra): look up the live office VPN gateway (PLAT-77)
The gateway tagged syslog-server-office is deleted, so the plan cannot find a route target for the office LANs.
* fix(infra): select the office VPN gateway by id (PLAT-77)
A state-and-VPC lookup is not unique once syslog recreates its deleted gateway. The workspace variable pins the gateway that is carrying office traffic.
* feat(infra): add HCP Terraform for the prod file share (PLAT-77)
The prod host will live on a subnet in the syslog VPC. The data volume stays unmanaged and is attached only after a snapshot copy.
* fix(infra): pin FileBrowser version to a release tag (PLAT-77)
The version is interpolated into the boot script. Reject anything that is not a vX.Y.Z tag.
* fix(infra): keep the file share off the public internet (PLAT-77)
The instance has no public IP. Office routes use the syslog VPN gateway and other egress uses a NAT gateway. DLM targets the tagged data volume, and replacement detaches stop the instance first.