Commit graph

9 commits

Author SHA1 Message Date
Adam Moussa
bbbdacd01c
docs(infra): drop the management rollback hold (PLAT-77) (#59)
The old volume, cutover snapshots, and management secrets are deleted, so the docs no longer tell anyone to keep them.
2026-09-29 20:22:41 -04:00
Adam Moussa
3a07b2e968
docs(infra): record the prod HCP path after management decommission (PLAT-77) (#58)
The management stack is deleted, so the docs now describe the live share and the CDK deploy workflow is removed.
2026-09-30 00:03:47 +00:00
Adam Moussa
9f27827dcb
fix(infra): look up the live office VPN gateway (PLAT-77) (#57)
* fix(infra): look up the live office VPN gateway (PLAT-77)

The gateway tagged syslog-server-office is deleted, so the plan cannot find a route target for the office LANs.

* fix(infra): select the office VPN gateway by id (PLAT-77)

A state-and-VPC lookup is not unique once syslog recreates its deleted gateway. The workspace variable pins the gateway that is carrying office traffic.
2026-09-29 22:49:31 +00:00
Adam Moussa
7c72159f31
feat(infra): add HCP Terraform for the prod file share (PLAT-77) (#56)
* feat(infra): add HCP Terraform for the prod file share (PLAT-77)

The prod host will live on a subnet in the syslog VPC. The data volume stays unmanaged and is attached only after a snapshot copy.

* fix(infra): pin FileBrowser version to a release tag (PLAT-77)

The version is interpolated into the boot script. Reject anything that is not a vX.Y.Z tag.

* fix(infra): keep the file share off the public internet (PLAT-77)

The instance has no public IP. Office routes use the syslog VPN gateway and other egress uses a NAT gateway. DLM targets the tagged data volume, and replacement detaches stop the instance first.
2026-09-29 22:32:39 +00:00
Adam Moussa
acdab89dcc
Document CDK app and cdk.json in README (#24)
Some checks failed
Deploy / deploy (push) Has been cancelled
The README described the deployed AWS resources and how to deploy, but
never documented that this is a CDK (infrastructure-as-code) app or what
cdk.json is. Add an Infrastructure (CDK) section covering the app entry
point, the file-share stack, the cdk.json manifest and context cache, and
the synth/diff/deploy commands, so the IaC layer is discoverable.
2026-07-10 16:07:08 -04:00
Adam Moussa
f4a7d4d5f8
docs: link Confluence AWS Architecture Map (INFRA-53) (#20)
Some checks are pending
Deploy / deploy (push) Waiting to run
2026-07-06 17:44:25 -04:00
Adam Moussa
49bc8747b9
Repo hygiene: PR labeler + README badges + dependabot (INFRA-56/57/66) (#8) 2026-06-11 14:14:13 -04:00
Adam Moussa
99a0fc9768
docs: update README for unmanaged data volume, SFTP, cached AMI (#6)
Some checks failed
Deploy / deploy (push) Has been cancelled
Storage architecture changed 2026-06-05 (volume imported by ID, not
CFN-managed) — the old Expanding Storage procedure no longer worked.
2026-06-05 15:54:22 -04:00
Adam Moussa
427242499d Initial file-share stack
CDK stack deploying a t4g.small EC2 instance with Samba and FileBrowser
for personal file storage over the site-to-site VPN. Includes 500 GiB
gp3 data volume with daily DLM snapshots.
2026-05-14 15:23:38 -04:00