From ed41fd4eac9de5af051c43872aba3bae143bc7f3 Mon Sep 17 00:00:00 2001 From: Adam Moussa <166072409+amoussa1229@users.noreply.github.com> Date: Mon, 11 May 2026 18:13:21 -0400 Subject: [PATCH] Add ALB egress rule for Forgejo target group MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit ALB security group has restricted outbound — needed explicit egress to the Forgejo SG on port 3000 for health checks. --- lib/forgejo-stack.ts | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) diff --git a/lib/forgejo-stack.ts b/lib/forgejo-stack.ts index 7629e90..33385d6 100644 --- a/lib/forgejo-stack.ts +++ b/lib/forgejo-stack.ts @@ -33,8 +33,10 @@ export class ForgejoStack extends cdk.Stack { }); const albSg = ec2.SecurityGroup.fromSecurityGroupId( - this, "AlbSg", "sg-0b0301deed193258a" + this, "AlbSg", "sg-0b0301deed193258a", + { allowAllOutbound: false } ); + albSg.addEgressRule(sg, ec2.Port.tcp(3000), "Forgejo HTTP"); sg.addIngressRule(albSg, ec2.Port.tcp(3000), "HTTP from ALB"); sg.addIngressRule(ec2.Peer.ipv4("10.20.0.0/16"), ec2.Port.tcp(3000), "HTTP from VPC"); sg.addIngressRule(ec2.Peer.ipv4("10.10.0.0/16"), ec2.Port.tcp(3000), "HTTP from office VPN");