Add ALB egress rule for Forgejo target group

ALB security group has restricted outbound — needed explicit
egress to the Forgejo SG on port 3000 for health checks.
This commit is contained in:
Adam Moussa 2026-05-11 18:13:21 -04:00
parent 9e0a14e5b8
commit ed41fd4eac

View file

@ -33,8 +33,10 @@ export class ForgejoStack extends cdk.Stack {
});
const albSg = ec2.SecurityGroup.fromSecurityGroupId(
this, "AlbSg", "sg-0b0301deed193258a"
this, "AlbSg", "sg-0b0301deed193258a",
{ allowAllOutbound: false }
);
albSg.addEgressRule(sg, ec2.Port.tcp(3000), "Forgejo HTTP");
sg.addIngressRule(albSg, ec2.Port.tcp(3000), "HTTP from ALB");
sg.addIngressRule(ec2.Peer.ipv4("10.20.0.0/16"), ec2.Port.tcp(3000), "HTTP from VPC");
sg.addIngressRule(ec2.Peer.ipv4("10.10.0.0/16"), ec2.Port.tcp(3000), "HTTP from office VPN");