Route through seahaven-com ALB for HTTPS

Add target group, listener rule (forgejo.seahaven.com), and alias
the Route53 record to the ALB. SSL termination via wildcard cert.
This commit is contained in:
Adam Moussa 2026-05-11 18:08:36 -04:00
parent 83c381b1da
commit 9e0a14e5b8

View file

@ -1,7 +1,10 @@
import * as cdk from "aws-cdk-lib";
import * as ec2 from "aws-cdk-lib/aws-ec2";
import * as iam from "aws-cdk-lib/aws-iam";
import * as elbv2 from "aws-cdk-lib/aws-elasticloadbalancingv2";
import * as elbv2_targets from "aws-cdk-lib/aws-elasticloadbalancingv2-targets";
import * as route53 from "aws-cdk-lib/aws-route53";
import * as route53Targets from "aws-cdk-lib/aws-route53-targets";
import * as dlm from "aws-cdk-lib/aws-dlm";
import { Construct } from "constructs";
@ -29,6 +32,10 @@ export class ForgejoStack extends cdk.Stack {
allowAllOutbound: true,
});
const albSg = ec2.SecurityGroup.fromSecurityGroupId(
this, "AlbSg", "sg-0b0301deed193258a"
);
sg.addIngressRule(albSg, ec2.Port.tcp(3000), "HTTP from ALB");
sg.addIngressRule(ec2.Peer.ipv4("10.20.0.0/16"), ec2.Port.tcp(3000), "HTTP from VPC");
sg.addIngressRule(ec2.Peer.ipv4("10.10.0.0/16"), ec2.Port.tcp(3000), "HTTP from office VPN");
sg.addIngressRule(ec2.Peer.ipv4("10.20.0.0/16"), ec2.Port.tcp(2222), "SSH git from VPC");
@ -68,7 +75,7 @@ export class ForgejoStack extends cdk.Stack {
"",
"[server]",
"DOMAIN = forgejo.seahaven.com",
"ROOT_URL = http://forgejo.seahaven.com:3000/",
"ROOT_URL = https://forgejo.seahaven.com/",
"HTTP_PORT = 3000",
"START_SSH_SERVER = true",
"SSH_PORT = 2222",
@ -169,6 +176,44 @@ export class ForgejoStack extends cdk.Stack {
},
});
const alb = elbv2.ApplicationLoadBalancer.fromApplicationLoadBalancerAttributes(
this, "Alb", {
loadBalancerArn:
"arn:aws:elasticloadbalancing:us-east-1:328440206208:loadbalancer/app/seahaven-com/222c3257354ab559",
securityGroupId: "sg-0b0301deed193258a",
loadBalancerDnsName: "seahaven-com-1856441924.us-east-1.elb.amazonaws.com",
loadBalancerCanonicalHostedZoneId: "Z35SXDOTRQ7X7K",
}
);
const httpsListener = elbv2.ApplicationListener.fromApplicationListenerAttributes(
this, "HttpsListener", {
listenerArn:
"arn:aws:elasticloadbalancing:us-east-1:328440206208:listener/app/seahaven-com/222c3257354ab559/bab8bcf0da0e2927",
securityGroup: albSg,
}
);
const targetGroup = new elbv2.ApplicationTargetGroup(this, "TargetGroup", {
targetGroupName: "forgejo",
vpc,
port: 3000,
protocol: elbv2.ApplicationProtocol.HTTP,
targetType: elbv2.TargetType.INSTANCE,
healthCheck: {
path: "/",
healthyHttpCodes: "200,302",
},
targets: [new elbv2_targets.InstanceIdTarget(instance.instanceId, 3000)],
});
new elbv2.ApplicationListenerRule(this, "ListenerRule", {
listener: httpsListener,
priority: 4,
conditions: [elbv2.ListenerCondition.hostHeaders(["forgejo.seahaven.com"])],
targetGroups: [targetGroup],
});
const hostedZone = route53.HostedZone.fromHostedZoneAttributes(
this, "SeaHavenZone", {
hostedZoneId: "Z06652411XKH89KTZD3XA",
@ -179,12 +224,13 @@ export class ForgejoStack extends cdk.Stack {
new route53.ARecord(this, "DnsRecord", {
zone: hostedZone,
recordName: "forgejo",
target: route53.RecordTarget.fromIpAddresses(instance.instancePrivateIp),
ttl: cdk.Duration.minutes(5),
target: route53.RecordTarget.fromAlias(
new route53Targets.LoadBalancerTarget(alb)
),
});
new cdk.CfnOutput(this, "ForgejoUrl", {
value: "http://forgejo.seahaven.com:3000",
value: "https://forgejo.seahaven.com",
});
new cdk.CfnOutput(this, "InstanceId", {