Commit graph

2 commits

Author SHA1 Message Date
Adam Moussa
71dbdf9c92
fix(infra): run nightly snapshots as a stack-local DLM role (PLAT-77) (#60)
* fix(infra): run nightly snapshots as a stack-local DLM role (PLAT-77)

The lifecycle policy assumed a service-linked role AWS does not provide, so it stayed in ERROR and never snapshotted the data volume.

* fix(infra): scope DLM snapshot sharing to snapshot ARNs

ModifySnapshotAttribute on every resource can share a snapshot. The boundary allows it only on snapshot ARNs.
2026-10-01 20:23:29 +00:00
Adam Moussa
7c72159f31
feat(infra): add HCP Terraform for the prod file share (PLAT-77) (#56)
* feat(infra): add HCP Terraform for the prod file share (PLAT-77)

The prod host will live on a subnet in the syslog VPC. The data volume stays unmanaged and is attached only after a snapshot copy.

* fix(infra): pin FileBrowser version to a release tag (PLAT-77)

The version is interpolated into the boot script. Reject anything that is not a vX.Y.Z tag.

* fix(infra): keep the file share off the public internet (PLAT-77)

The instance has no public IP. Office routes use the syslog VPN gateway and other egress uses a NAT gateway. DLM targets the tagged data volume, and replacement detaches stop the instance first.
2026-09-29 22:32:39 +00:00