file-share/README.md
Adam Moussa 2fcf14a437
docs(infra): drop the management rollback hold (PLAT-77)
The old volume, cutover snapshots, and management secrets are deleted, so the docs no longer tell anyone to keep them.
2026-09-29 20:20:12 -04:00

45 lines
2.4 KiB
Markdown

# File Share
Samba, FileBrowser, and SFTP for the Sea Haven offices. The live host is an EC2 instance in seahaven-prod, managed by HCP Terraform workspace `file-share-prod`.
Clients:
- `smb://10.40.20.185/files`
- `http://10.40.20.185:8080`
- SFTP as user `adam` on port 22
The instance has no public IP. Its route table sends `10.10.0.0/16` (Ronkonkoma) and `10.30.0.0/16` (Locust) through the VPN gateway in workspace variable `vpn_gateway_id`, and everything else through a NAT gateway in the syslog public subnet. Ingress is TCP 445, 8080, and 22 from those two office ranges only.
## Layout
| Path | What it is |
|---|---|
| `terraform/` | Live infrastructure. Subnet `10.40.20.0/24` in the syslog VPC, security group, instance role, DLM, and the instance plus volume attachment. |
| `lib/`, `bin/` | Retired management-account CDK stack. Do not deploy it. The stack was deleted on 2026-09-29. |
The data volume is not created by Terraform. Set `data_volume_id` on the workspace to the existing volume id (`vol-0f873de6adb59745f`). Terraform attaches it at `/dev/xvdf` and the boot script mounts the existing filesystem at `/data`. A `blkid` guard keeps a disk that already has a filesystem from being formatted.
## Apply
Workspace `file-share-prod` is manual apply. Auto-apply stays off until the share has soaked. `user_data_replace_on_change` is false, so an AMI or user-data change does not replace the instance by itself. Snapshot the data volume and confirm before any apply that would replace the instance.
The nightly DLM policy targets volumes tagged `file-share-backup=true` and keeps 30 snapshots.
## Secrets
The instance role reads these secrets in seahaven-prod at boot. Do not put the values in Terraform:
| Secret | Purpose |
|---|---|
| `file-share/smb-password` | Samba user password |
| `file-share/filebrowser-password` | FileBrowser admin password |
The management-account copies of those secrets were deleted on 2026-09-29, along with the old data volume and its cutover snapshots. The management deploy role `githubdeploy-file-share` is left in place. The CDK deploy workflow is gone so a dispatch cannot recreate the stack.
## Expanding storage
Change the volume in seahaven-prod, then grow the filesystem. Terraform does not set the size.
1. `aws ec2 modify-volume --volume-id vol-0f873de6adb59745f --size <new-GiB>`
2. Wait until the modification leaves `modifying`.
3. From an SSM session: `sudo resize2fs /dev/nvme1n1`