From 87c237fe0301e8d6545191fef34891acfa94ea87 Mon Sep 17 00:00:00 2001 From: Adam Moussa <166072409+amoussa1229@users.noreply.github.com> Date: Mon, 27 Jul 2026 12:16:54 -0400 Subject: [PATCH] docs: decommission rustdesk-server (stack torn down 2026-07-27) (#21) MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Stack rustdesk-server (328440206208/us-east-1) fully deleted: EC2, EIP 100.27.82.124 (released), SG, launch template, IAM roles, DLM policy, both Route53 records. Orphaned data volumes deleted with no snapshot (explicit owner decision — no backups exist). Secrets force-deleted, SSM params deleted, OIDC deploy role + repo secret removed. Removes all GitHub automation (workflows, dependabot) ahead of repo archival; README carries the decommission banner, RUNBOOK marked obsolete. Adds a repo-local suppression for the aws-cdk-lib-bundled brace-expansion advisory (unfixable upstream, repo archived). --- .github/dependabot.yml | 23 ----------------------- .github/workflows/ci.yaml | 10 ---------- .github/workflows/dependency-review.yml | 6 ------ .github/workflows/deploy.yaml | 20 -------------------- .github/workflows/labeler.yml | 11 ----------- .security-review/suppressions.json | 8 ++++++++ README.md | 17 ++++++++++++++++- RUNBOOK.md | 2 ++ 8 files changed, 26 insertions(+), 71 deletions(-) delete mode 100644 .github/dependabot.yml delete mode 100644 .github/workflows/ci.yaml delete mode 100644 .github/workflows/dependency-review.yml delete mode 100644 .github/workflows/deploy.yaml delete mode 100644 .github/workflows/labeler.yml create mode 100644 .security-review/suppressions.json diff --git a/.github/dependabot.yml b/.github/dependabot.yml deleted file mode 100644 index 966ef18..0000000 --- a/.github/dependabot.yml +++ /dev/null @@ -1,23 +0,0 @@ -version: 2 -updates: - - package-ecosystem: npm - directory: / - schedule: - interval: weekly - assignees: - - amoussa1229 - ignore: - # @types/node must track the runtime Node major, not the latest release. - # Pure-CDK repo: the runtime is the Node that runs `cdk synth`/`tsc` in CI. - # Dependabot can't see that and a too-new types major still compiles (passes - # CI, wrong at runtime). Sanctioned exception to the no-blanket-ignore rule - # (engineering-handbook github-standards Pinning Principle). Minor/patch flow. - - dependency-name: "@types/node" - update-types: ["version-update:semver-major"] - - - package-ecosystem: github-actions - directory: / - schedule: - interval: weekly - assignees: - - amoussa1229 diff --git a/.github/workflows/ci.yaml b/.github/workflows/ci.yaml deleted file mode 100644 index 4841ebe..0000000 --- a/.github/workflows/ci.yaml +++ /dev/null @@ -1,10 +0,0 @@ -name: CI -on: - pull_request: - branches: [main] - -jobs: - ci: - uses: Sea-Haven-Industries/.github/.github/workflows/ci-typescript-cdk.yaml@fd60e4c9041784f666ac0fdefb9bec3c7fbf5143 # main - with: - node-version: "24" diff --git a/.github/workflows/dependency-review.yml b/.github/workflows/dependency-review.yml deleted file mode 100644 index 2cd8119..0000000 --- a/.github/workflows/dependency-review.yml +++ /dev/null @@ -1,6 +0,0 @@ -name: Dependency Review -on: - pull_request: -jobs: - review: - uses: Sea-Haven-Industries/.github/.github/workflows/callable-dependency-review.yaml@fd60e4c9041784f666ac0fdefb9bec3c7fbf5143 # main diff --git a/.github/workflows/deploy.yaml b/.github/workflows/deploy.yaml deleted file mode 100644 index 4d0aaa7..0000000 --- a/.github/workflows/deploy.yaml +++ /dev/null @@ -1,20 +0,0 @@ -name: Deploy -on: - push: - branches: [main] - -permissions: - id-token: write - contents: read - -concurrency: - group: deploy - cancel-in-progress: false - -jobs: - deploy: - uses: Sea-Haven-Industries/.github/.github/workflows/cd-cdk.yaml@fd60e4c9041784f666ac0fdefb9bec3c7fbf5143 # main - with: - node-version: "24" - secrets: - deploy-role-arn: ${{ secrets.AWS_DEPLOY_ROLE_ARN }} diff --git a/.github/workflows/labeler.yml b/.github/workflows/labeler.yml deleted file mode 100644 index 46b1dc8..0000000 --- a/.github/workflows/labeler.yml +++ /dev/null @@ -1,11 +0,0 @@ -name: Labeler -on: - pull_request: - branches: [main] -permissions: - contents: read - pull-requests: write - issues: write -jobs: - label: - uses: Sea-Haven-Industries/.github/.github/workflows/callable-labeler.yaml@fd60e4c9041784f666ac0fdefb9bec3c7fbf5143 # main diff --git a/.security-review/suppressions.json b/.security-review/suppressions.json new file mode 100644 index 0000000..d06e336 --- /dev/null +++ b/.security-review/suppressions.json @@ -0,0 +1,8 @@ +{ + "suppressions": [ + { + "id": "npmaudit-brace-expansion", + "justification": "Accepted risk on decommission (2026-07-27): brace-expansion <=5.0.7 (CVE-2026-14257, OOM DoS) is bundled inside the aws-cdk-lib tarball and cannot be updated independently; no patched aws-cdk-lib release exists. The rustdesk-server stack was fully torn down 2026-07-27 and this repo is being archived — the dependency will never be installed or executed again. This suppression exists solely to land the final decommission-docs commit." + } + ] +} diff --git a/README.md b/README.md index af22794..5f3a198 100644 --- a/README.md +++ b/README.md @@ -1,5 +1,20 @@ # rustdesk-server +## Decommissioned — 2026-07-27 + +**Status: DECOMMISSIONED.** The `rustdesk-server` stack (account 328440206208, us-east-1) was deployed 2026-06-28 and fully torn down on 2026-07-27. + +What was destroyed: + +- CloudFormation stack `rustdesk-server` deleted: EC2 instance `i-02d98e3476ff82213`, Elastic IP `100.27.82.124` (released — **permanently unrecoverable**), security group, launch template, IAM roles `rustdesk-server-instance` and `rustdesk-server-dlm`, the DLM snapshot policy, and Route 53 records `rustdesk.seahaven.com` / `rustdesk-admin.int.seahaven.com`. +- Orphaned data volumes `vol-0e5a1a57612c2706e` and `vol-0fee83b3e96f3fcc9` deleted with **no final snapshot taken** — an explicit owner decision accepting total loss of the server key pair and the RustDesk connection database. **No backups exist.** +- Secrets `rustdesk/server-key-pair` and `rustdesk/pro-license` force-deleted with no recovery window. SSM parameters `/rustdesk-server/relay-host` and `/rustdesk-server/public-key` deleted. OIDC deploy role `githubdeploy-rustdesk-server` and the repo secret `AWS_DEPLOY_ROLE_ARN` deleted. +- Any RustDesk client still pointed at `rustdesk.seahaven.com` is permanently dead — the Elastic IP was released and will not come back. + +This repository is archived and kept for historical reference only. Everything below this section documents the system as it existed while deployed; it does not describe anything currently running, and should not be used to attempt a redeploy without re-provisioning secrets, key material, and DNS from scratch. + +--- + [![CI](https://github.com/Sea-Haven-Industries/rustdesk-server/actions/workflows/ci.yaml/badge.svg)](https://github.com/Sea-Haven-Industries/rustdesk-server/actions/workflows/ci.yaml) [![Dependency Review](https://github.com/Sea-Haven-Industries/rustdesk-server/actions/workflows/dependency-review.yml/badge.svg)](https://github.com/Sea-Haven-Industries/rustdesk-server/actions/workflows/dependency-review.yml) ![TypeScript](https://img.shields.io/badge/TypeScript-3178C6?logo=typescript&logoColor=white) @@ -7,7 +22,7 @@ Self-hosted [RustDesk Server Pro](https://rustdesk.com/docs/en/self-host/) (remote-desktop relay + rendezvous) for Sea Haven Industries, deployed to AWS via CDK. -> Status: **scaffold** — not yet deployed. See [First deploy](#first-deploy). +> Status: deployed 2026-06-28, decommissioned 2026-07-27. See the decommission notice above. ## Architecture diff --git a/RUNBOOK.md b/RUNBOOK.md index 573a245..8dfba52 100644 --- a/RUNBOOK.md +++ b/RUNBOOK.md @@ -1,5 +1,7 @@ # RustDesk Server — Runbook +> **Obsolete as of 2026-07-27** — the `rustdesk-server` stack no longer exists; this runbook is retained for historical reference only. + Operational procedures for the `rustdesk-server` stack. Account 328440206208, us-east-1. ## Access