docs: decommission rustdesk-server (stack torn down 2026-07-27) (#21)
Stack rustdesk-server (328440206208/us-east-1) fully deleted: EC2, EIP 100.27.82.124 (released), SG, launch template, IAM roles, DLM policy, both Route53 records. Orphaned data volumes deleted with no snapshot (explicit owner decision — no backups exist). Secrets force-deleted, SSM params deleted, OIDC deploy role + repo secret removed. Removes all GitHub automation (workflows, dependabot) ahead of repo archival; README carries the decommission banner, RUNBOOK marked obsolete. Adds a repo-local suppression for the aws-cdk-lib-bundled brace-expansion advisory (unfixable upstream, repo archived).
This commit is contained in:
parent
f1d029f31d
commit
87c237fe03
8 changed files with 26 additions and 71 deletions
23
.github/dependabot.yml
vendored
23
.github/dependabot.yml
vendored
|
|
@ -1,23 +0,0 @@
|
||||||
version: 2
|
|
||||||
updates:
|
|
||||||
- package-ecosystem: npm
|
|
||||||
directory: /
|
|
||||||
schedule:
|
|
||||||
interval: weekly
|
|
||||||
assignees:
|
|
||||||
- amoussa1229
|
|
||||||
ignore:
|
|
||||||
# @types/node must track the runtime Node major, not the latest release.
|
|
||||||
# Pure-CDK repo: the runtime is the Node that runs `cdk synth`/`tsc` in CI.
|
|
||||||
# Dependabot can't see that and a too-new types major still compiles (passes
|
|
||||||
# CI, wrong at runtime). Sanctioned exception to the no-blanket-ignore rule
|
|
||||||
# (engineering-handbook github-standards Pinning Principle). Minor/patch flow.
|
|
||||||
- dependency-name: "@types/node"
|
|
||||||
update-types: ["version-update:semver-major"]
|
|
||||||
|
|
||||||
- package-ecosystem: github-actions
|
|
||||||
directory: /
|
|
||||||
schedule:
|
|
||||||
interval: weekly
|
|
||||||
assignees:
|
|
||||||
- amoussa1229
|
|
||||||
10
.github/workflows/ci.yaml
vendored
10
.github/workflows/ci.yaml
vendored
|
|
@ -1,10 +0,0 @@
|
||||||
name: CI
|
|
||||||
on:
|
|
||||||
pull_request:
|
|
||||||
branches: [main]
|
|
||||||
|
|
||||||
jobs:
|
|
||||||
ci:
|
|
||||||
uses: Sea-Haven-Industries/.github/.github/workflows/ci-typescript-cdk.yaml@fd60e4c9041784f666ac0fdefb9bec3c7fbf5143 # main
|
|
||||||
with:
|
|
||||||
node-version: "24"
|
|
||||||
6
.github/workflows/dependency-review.yml
vendored
6
.github/workflows/dependency-review.yml
vendored
|
|
@ -1,6 +0,0 @@
|
||||||
name: Dependency Review
|
|
||||||
on:
|
|
||||||
pull_request:
|
|
||||||
jobs:
|
|
||||||
review:
|
|
||||||
uses: Sea-Haven-Industries/.github/.github/workflows/callable-dependency-review.yaml@fd60e4c9041784f666ac0fdefb9bec3c7fbf5143 # main
|
|
||||||
20
.github/workflows/deploy.yaml
vendored
20
.github/workflows/deploy.yaml
vendored
|
|
@ -1,20 +0,0 @@
|
||||||
name: Deploy
|
|
||||||
on:
|
|
||||||
push:
|
|
||||||
branches: [main]
|
|
||||||
|
|
||||||
permissions:
|
|
||||||
id-token: write
|
|
||||||
contents: read
|
|
||||||
|
|
||||||
concurrency:
|
|
||||||
group: deploy
|
|
||||||
cancel-in-progress: false
|
|
||||||
|
|
||||||
jobs:
|
|
||||||
deploy:
|
|
||||||
uses: Sea-Haven-Industries/.github/.github/workflows/cd-cdk.yaml@fd60e4c9041784f666ac0fdefb9bec3c7fbf5143 # main
|
|
||||||
with:
|
|
||||||
node-version: "24"
|
|
||||||
secrets:
|
|
||||||
deploy-role-arn: ${{ secrets.AWS_DEPLOY_ROLE_ARN }}
|
|
||||||
11
.github/workflows/labeler.yml
vendored
11
.github/workflows/labeler.yml
vendored
|
|
@ -1,11 +0,0 @@
|
||||||
name: Labeler
|
|
||||||
on:
|
|
||||||
pull_request:
|
|
||||||
branches: [main]
|
|
||||||
permissions:
|
|
||||||
contents: read
|
|
||||||
pull-requests: write
|
|
||||||
issues: write
|
|
||||||
jobs:
|
|
||||||
label:
|
|
||||||
uses: Sea-Haven-Industries/.github/.github/workflows/callable-labeler.yaml@fd60e4c9041784f666ac0fdefb9bec3c7fbf5143 # main
|
|
||||||
8
.security-review/suppressions.json
Normal file
8
.security-review/suppressions.json
Normal file
|
|
@ -0,0 +1,8 @@
|
||||||
|
{
|
||||||
|
"suppressions": [
|
||||||
|
{
|
||||||
|
"id": "npmaudit-brace-expansion",
|
||||||
|
"justification": "Accepted risk on decommission (2026-07-27): brace-expansion <=5.0.7 (CVE-2026-14257, OOM DoS) is bundled inside the aws-cdk-lib tarball and cannot be updated independently; no patched aws-cdk-lib release exists. The rustdesk-server stack was fully torn down 2026-07-27 and this repo is being archived — the dependency will never be installed or executed again. This suppression exists solely to land the final decommission-docs commit."
|
||||||
|
}
|
||||||
|
]
|
||||||
|
}
|
||||||
17
README.md
17
README.md
|
|
@ -1,5 +1,20 @@
|
||||||
# rustdesk-server
|
# rustdesk-server
|
||||||
|
|
||||||
|
## Decommissioned — 2026-07-27
|
||||||
|
|
||||||
|
**Status: DECOMMISSIONED.** The `rustdesk-server` stack (account 328440206208, us-east-1) was deployed 2026-06-28 and fully torn down on 2026-07-27.
|
||||||
|
|
||||||
|
What was destroyed:
|
||||||
|
|
||||||
|
- CloudFormation stack `rustdesk-server` deleted: EC2 instance `i-02d98e3476ff82213`, Elastic IP `100.27.82.124` (released — **permanently unrecoverable**), security group, launch template, IAM roles `rustdesk-server-instance` and `rustdesk-server-dlm`, the DLM snapshot policy, and Route 53 records `rustdesk.seahaven.com` / `rustdesk-admin.int.seahaven.com`.
|
||||||
|
- Orphaned data volumes `vol-0e5a1a57612c2706e` and `vol-0fee83b3e96f3fcc9` deleted with **no final snapshot taken** — an explicit owner decision accepting total loss of the server key pair and the RustDesk connection database. **No backups exist.**
|
||||||
|
- Secrets `rustdesk/server-key-pair` and `rustdesk/pro-license` force-deleted with no recovery window. SSM parameters `/rustdesk-server/relay-host` and `/rustdesk-server/public-key` deleted. OIDC deploy role `githubdeploy-rustdesk-server` and the repo secret `AWS_DEPLOY_ROLE_ARN` deleted.
|
||||||
|
- Any RustDesk client still pointed at `rustdesk.seahaven.com` is permanently dead — the Elastic IP was released and will not come back.
|
||||||
|
|
||||||
|
This repository is archived and kept for historical reference only. Everything below this section documents the system as it existed while deployed; it does not describe anything currently running, and should not be used to attempt a redeploy without re-provisioning secrets, key material, and DNS from scratch.
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
[](https://github.com/Sea-Haven-Industries/rustdesk-server/actions/workflows/ci.yaml)
|
[](https://github.com/Sea-Haven-Industries/rustdesk-server/actions/workflows/ci.yaml)
|
||||||
[](https://github.com/Sea-Haven-Industries/rustdesk-server/actions/workflows/dependency-review.yml)
|
[](https://github.com/Sea-Haven-Industries/rustdesk-server/actions/workflows/dependency-review.yml)
|
||||||

|

|
||||||
|
|
@ -7,7 +22,7 @@
|
||||||
|
|
||||||
Self-hosted [RustDesk Server Pro](https://rustdesk.com/docs/en/self-host/) (remote-desktop relay + rendezvous) for Sea Haven Industries, deployed to AWS via CDK.
|
Self-hosted [RustDesk Server Pro](https://rustdesk.com/docs/en/self-host/) (remote-desktop relay + rendezvous) for Sea Haven Industries, deployed to AWS via CDK.
|
||||||
|
|
||||||
> Status: **scaffold** — not yet deployed. See [First deploy](#first-deploy).
|
> Status: deployed 2026-06-28, decommissioned 2026-07-27. See the decommission notice above.
|
||||||
|
|
||||||
## Architecture
|
## Architecture
|
||||||
|
|
||||||
|
|
|
||||||
|
|
@ -1,5 +1,7 @@
|
||||||
# RustDesk Server — Runbook
|
# RustDesk Server — Runbook
|
||||||
|
|
||||||
|
> **Obsolete as of 2026-07-27** — the `rustdesk-server` stack no longer exists; this runbook is retained for historical reference only.
|
||||||
|
|
||||||
Operational procedures for the `rustdesk-server` stack. Account 328440206208, us-east-1.
|
Operational procedures for the `rustdesk-server` stack. Account 328440206208, us-east-1.
|
||||||
|
|
||||||
## Access
|
## Access
|
||||||
|
|
|
||||||
Reference in a new issue