file-share/README.md
Adam Moussa 3a07b2e968
docs(infra): record the prod HCP path after management decommission (PLAT-77) (#58)
The management stack is deleted, so the docs now describe the live share and the CDK deploy workflow is removed.
2026-09-30 00:03:47 +00:00

2.6 KiB

File Share

Samba, FileBrowser, and SFTP for the Sea Haven offices. The live host is an EC2 instance in seahaven-prod, managed by HCP Terraform workspace file-share-prod.

Clients:

  • smb://10.40.20.185/files
  • http://10.40.20.185:8080
  • SFTP as user adam on port 22

The instance has no public IP. Its route table sends 10.10.0.0/16 (Ronkonkoma) and 10.30.0.0/16 (Locust) through the VPN gateway in workspace variable vpn_gateway_id, and everything else through a NAT gateway in the syslog public subnet. Ingress is TCP 445, 8080, and 22 from those two office ranges only.

Layout

Path What it is
terraform/ Live infrastructure. Subnet 10.40.20.0/24 in the syslog VPC, security group, instance role, DLM, and the instance plus volume attachment.
lib/, bin/ Retired management-account CDK stack. Do not deploy it. The stack was deleted on 2026-09-29.

The data volume is not created by Terraform. Set data_volume_id on the workspace to the existing volume id (vol-0f873de6adb59745f). Terraform attaches it at /dev/xvdf and the boot script mounts the existing filesystem at /data. A blkid guard keeps a disk that already has a filesystem from being formatted.

Apply

Workspace file-share-prod is manual apply. Auto-apply stays off until the share has soaked. user_data_replace_on_change is false, so an AMI or user-data change does not replace the instance by itself. Snapshot the data volume and confirm before any apply that would replace the instance.

The nightly DLM policy targets volumes tagged file-share-backup=true and keeps 30 snapshots.

Secrets

The instance role reads these secrets in seahaven-prod at boot. Do not put the values in Terraform:

Secret Purpose
file-share/smb-password Samba user password
file-share/filebrowser-password FileBrowser admin password

Copies of the same secret names still exist in the management account until 2026-10-06.

Rollback hold

The management CloudFormation stack is deleted. These stay until 2026-10-06, then they can be deleted:

  • Data volume vol-04d951cccacc435b5 (detached)
  • Snapshot snap-090186cf7e7b49b1c

The management deploy role githubdeploy-file-share is left in place. The CDK deploy workflow is gone so a dispatch cannot recreate the stack.

Expanding storage

Change the volume in seahaven-prod, then grow the filesystem. Terraform does not set the size.

  1. aws ec2 modify-volume --volume-id vol-0f873de6adb59745f --size <new-GiB>
  2. Wait until the modification leaves modifying.
  3. From an SSM session: sudo resize2fs /dev/nvme1n1