From 9e0a14e5b8cef60f3670b19d769f638dae33ac26 Mon Sep 17 00:00:00 2001 From: Adam Moussa <166072409+amoussa1229@users.noreply.github.com> Date: Mon, 11 May 2026 18:08:36 -0400 Subject: [PATCH] Route through seahaven-com ALB for HTTPS Add target group, listener rule (forgejo.seahaven.com), and alias the Route53 record to the ALB. SSL termination via wildcard cert. --- lib/forgejo-stack.ts | 54 ++++++++++++++++++++++++++++++++++++++++---- 1 file changed, 50 insertions(+), 4 deletions(-) diff --git a/lib/forgejo-stack.ts b/lib/forgejo-stack.ts index 67b0aeb..7629e90 100644 --- a/lib/forgejo-stack.ts +++ b/lib/forgejo-stack.ts @@ -1,7 +1,10 @@ import * as cdk from "aws-cdk-lib"; import * as ec2 from "aws-cdk-lib/aws-ec2"; import * as iam from "aws-cdk-lib/aws-iam"; +import * as elbv2 from "aws-cdk-lib/aws-elasticloadbalancingv2"; +import * as elbv2_targets from "aws-cdk-lib/aws-elasticloadbalancingv2-targets"; import * as route53 from "aws-cdk-lib/aws-route53"; +import * as route53Targets from "aws-cdk-lib/aws-route53-targets"; import * as dlm from "aws-cdk-lib/aws-dlm"; import { Construct } from "constructs"; @@ -29,6 +32,10 @@ export class ForgejoStack extends cdk.Stack { allowAllOutbound: true, }); + const albSg = ec2.SecurityGroup.fromSecurityGroupId( + this, "AlbSg", "sg-0b0301deed193258a" + ); + sg.addIngressRule(albSg, ec2.Port.tcp(3000), "HTTP from ALB"); sg.addIngressRule(ec2.Peer.ipv4("10.20.0.0/16"), ec2.Port.tcp(3000), "HTTP from VPC"); sg.addIngressRule(ec2.Peer.ipv4("10.10.0.0/16"), ec2.Port.tcp(3000), "HTTP from office VPN"); sg.addIngressRule(ec2.Peer.ipv4("10.20.0.0/16"), ec2.Port.tcp(2222), "SSH git from VPC"); @@ -68,7 +75,7 @@ export class ForgejoStack extends cdk.Stack { "", "[server]", "DOMAIN = forgejo.seahaven.com", - "ROOT_URL = http://forgejo.seahaven.com:3000/", + "ROOT_URL = https://forgejo.seahaven.com/", "HTTP_PORT = 3000", "START_SSH_SERVER = true", "SSH_PORT = 2222", @@ -169,6 +176,44 @@ export class ForgejoStack extends cdk.Stack { }, }); + const alb = elbv2.ApplicationLoadBalancer.fromApplicationLoadBalancerAttributes( + this, "Alb", { + loadBalancerArn: + "arn:aws:elasticloadbalancing:us-east-1:328440206208:loadbalancer/app/seahaven-com/222c3257354ab559", + securityGroupId: "sg-0b0301deed193258a", + loadBalancerDnsName: "seahaven-com-1856441924.us-east-1.elb.amazonaws.com", + loadBalancerCanonicalHostedZoneId: "Z35SXDOTRQ7X7K", + } + ); + + const httpsListener = elbv2.ApplicationListener.fromApplicationListenerAttributes( + this, "HttpsListener", { + listenerArn: + "arn:aws:elasticloadbalancing:us-east-1:328440206208:listener/app/seahaven-com/222c3257354ab559/bab8bcf0da0e2927", + securityGroup: albSg, + } + ); + + const targetGroup = new elbv2.ApplicationTargetGroup(this, "TargetGroup", { + targetGroupName: "forgejo", + vpc, + port: 3000, + protocol: elbv2.ApplicationProtocol.HTTP, + targetType: elbv2.TargetType.INSTANCE, + healthCheck: { + path: "/", + healthyHttpCodes: "200,302", + }, + targets: [new elbv2_targets.InstanceIdTarget(instance.instanceId, 3000)], + }); + + new elbv2.ApplicationListenerRule(this, "ListenerRule", { + listener: httpsListener, + priority: 4, + conditions: [elbv2.ListenerCondition.hostHeaders(["forgejo.seahaven.com"])], + targetGroups: [targetGroup], + }); + const hostedZone = route53.HostedZone.fromHostedZoneAttributes( this, "SeaHavenZone", { hostedZoneId: "Z06652411XKH89KTZD3XA", @@ -179,12 +224,13 @@ export class ForgejoStack extends cdk.Stack { new route53.ARecord(this, "DnsRecord", { zone: hostedZone, recordName: "forgejo", - target: route53.RecordTarget.fromIpAddresses(instance.instancePrivateIp), - ttl: cdk.Duration.minutes(5), + target: route53.RecordTarget.fromAlias( + new route53Targets.LoadBalancerTarget(alb) + ), }); new cdk.CfnOutput(this, "ForgejoUrl", { - value: "http://forgejo.seahaven.com:3000", + value: "https://forgejo.seahaven.com", }); new cdk.CfnOutput(this, "InstanceId", {