docs: decommission rustdesk-server (stack torn down 2026-07-27) (#21)
Stack rustdesk-server (328440206208/us-east-1) fully deleted: EC2, EIP 100.27.82.124 (released), SG, launch template, IAM roles, DLM policy, both Route53 records. Orphaned data volumes deleted with no snapshot (explicit owner decision — no backups exist). Secrets force-deleted, SSM params deleted, OIDC deploy role + repo secret removed. Removes all GitHub automation (workflows, dependabot) ahead of repo archival; README carries the decommission banner, RUNBOOK marked obsolete. Adds a repo-local suppression for the aws-cdk-lib-bundled brace-expansion advisory (unfixable upstream, repo archived).
This commit is contained in:
parent
f1d029f31d
commit
87c237fe03
8 changed files with 26 additions and 71 deletions
23
.github/dependabot.yml
vendored
23
.github/dependabot.yml
vendored
|
|
@ -1,23 +0,0 @@
|
|||
version: 2
|
||||
updates:
|
||||
- package-ecosystem: npm
|
||||
directory: /
|
||||
schedule:
|
||||
interval: weekly
|
||||
assignees:
|
||||
- amoussa1229
|
||||
ignore:
|
||||
# @types/node must track the runtime Node major, not the latest release.
|
||||
# Pure-CDK repo: the runtime is the Node that runs `cdk synth`/`tsc` in CI.
|
||||
# Dependabot can't see that and a too-new types major still compiles (passes
|
||||
# CI, wrong at runtime). Sanctioned exception to the no-blanket-ignore rule
|
||||
# (engineering-handbook github-standards Pinning Principle). Minor/patch flow.
|
||||
- dependency-name: "@types/node"
|
||||
update-types: ["version-update:semver-major"]
|
||||
|
||||
- package-ecosystem: github-actions
|
||||
directory: /
|
||||
schedule:
|
||||
interval: weekly
|
||||
assignees:
|
||||
- amoussa1229
|
||||
10
.github/workflows/ci.yaml
vendored
10
.github/workflows/ci.yaml
vendored
|
|
@ -1,10 +0,0 @@
|
|||
name: CI
|
||||
on:
|
||||
pull_request:
|
||||
branches: [main]
|
||||
|
||||
jobs:
|
||||
ci:
|
||||
uses: Sea-Haven-Industries/.github/.github/workflows/ci-typescript-cdk.yaml@fd60e4c9041784f666ac0fdefb9bec3c7fbf5143 # main
|
||||
with:
|
||||
node-version: "24"
|
||||
6
.github/workflows/dependency-review.yml
vendored
6
.github/workflows/dependency-review.yml
vendored
|
|
@ -1,6 +0,0 @@
|
|||
name: Dependency Review
|
||||
on:
|
||||
pull_request:
|
||||
jobs:
|
||||
review:
|
||||
uses: Sea-Haven-Industries/.github/.github/workflows/callable-dependency-review.yaml@fd60e4c9041784f666ac0fdefb9bec3c7fbf5143 # main
|
||||
20
.github/workflows/deploy.yaml
vendored
20
.github/workflows/deploy.yaml
vendored
|
|
@ -1,20 +0,0 @@
|
|||
name: Deploy
|
||||
on:
|
||||
push:
|
||||
branches: [main]
|
||||
|
||||
permissions:
|
||||
id-token: write
|
||||
contents: read
|
||||
|
||||
concurrency:
|
||||
group: deploy
|
||||
cancel-in-progress: false
|
||||
|
||||
jobs:
|
||||
deploy:
|
||||
uses: Sea-Haven-Industries/.github/.github/workflows/cd-cdk.yaml@fd60e4c9041784f666ac0fdefb9bec3c7fbf5143 # main
|
||||
with:
|
||||
node-version: "24"
|
||||
secrets:
|
||||
deploy-role-arn: ${{ secrets.AWS_DEPLOY_ROLE_ARN }}
|
||||
11
.github/workflows/labeler.yml
vendored
11
.github/workflows/labeler.yml
vendored
|
|
@ -1,11 +0,0 @@
|
|||
name: Labeler
|
||||
on:
|
||||
pull_request:
|
||||
branches: [main]
|
||||
permissions:
|
||||
contents: read
|
||||
pull-requests: write
|
||||
issues: write
|
||||
jobs:
|
||||
label:
|
||||
uses: Sea-Haven-Industries/.github/.github/workflows/callable-labeler.yaml@fd60e4c9041784f666ac0fdefb9bec3c7fbf5143 # main
|
||||
8
.security-review/suppressions.json
Normal file
8
.security-review/suppressions.json
Normal file
|
|
@ -0,0 +1,8 @@
|
|||
{
|
||||
"suppressions": [
|
||||
{
|
||||
"id": "npmaudit-brace-expansion",
|
||||
"justification": "Accepted risk on decommission (2026-07-27): brace-expansion <=5.0.7 (CVE-2026-14257, OOM DoS) is bundled inside the aws-cdk-lib tarball and cannot be updated independently; no patched aws-cdk-lib release exists. The rustdesk-server stack was fully torn down 2026-07-27 and this repo is being archived — the dependency will never be installed or executed again. This suppression exists solely to land the final decommission-docs commit."
|
||||
}
|
||||
]
|
||||
}
|
||||
17
README.md
17
README.md
|
|
@ -1,5 +1,20 @@
|
|||
# rustdesk-server
|
||||
|
||||
## Decommissioned — 2026-07-27
|
||||
|
||||
**Status: DECOMMISSIONED.** The `rustdesk-server` stack (account 328440206208, us-east-1) was deployed 2026-06-28 and fully torn down on 2026-07-27.
|
||||
|
||||
What was destroyed:
|
||||
|
||||
- CloudFormation stack `rustdesk-server` deleted: EC2 instance `i-02d98e3476ff82213`, Elastic IP `100.27.82.124` (released — **permanently unrecoverable**), security group, launch template, IAM roles `rustdesk-server-instance` and `rustdesk-server-dlm`, the DLM snapshot policy, and Route 53 records `rustdesk.seahaven.com` / `rustdesk-admin.int.seahaven.com`.
|
||||
- Orphaned data volumes `vol-0e5a1a57612c2706e` and `vol-0fee83b3e96f3fcc9` deleted with **no final snapshot taken** — an explicit owner decision accepting total loss of the server key pair and the RustDesk connection database. **No backups exist.**
|
||||
- Secrets `rustdesk/server-key-pair` and `rustdesk/pro-license` force-deleted with no recovery window. SSM parameters `/rustdesk-server/relay-host` and `/rustdesk-server/public-key` deleted. OIDC deploy role `githubdeploy-rustdesk-server` and the repo secret `AWS_DEPLOY_ROLE_ARN` deleted.
|
||||
- Any RustDesk client still pointed at `rustdesk.seahaven.com` is permanently dead — the Elastic IP was released and will not come back.
|
||||
|
||||
This repository is archived and kept for historical reference only. Everything below this section documents the system as it existed while deployed; it does not describe anything currently running, and should not be used to attempt a redeploy without re-provisioning secrets, key material, and DNS from scratch.
|
||||
|
||||
---
|
||||
|
||||
[](https://github.com/Sea-Haven-Industries/rustdesk-server/actions/workflows/ci.yaml)
|
||||
[](https://github.com/Sea-Haven-Industries/rustdesk-server/actions/workflows/dependency-review.yml)
|
||||

|
||||
|
|
@ -7,7 +22,7 @@
|
|||
|
||||
Self-hosted [RustDesk Server Pro](https://rustdesk.com/docs/en/self-host/) (remote-desktop relay + rendezvous) for Sea Haven Industries, deployed to AWS via CDK.
|
||||
|
||||
> Status: **scaffold** — not yet deployed. See [First deploy](#first-deploy).
|
||||
> Status: deployed 2026-06-28, decommissioned 2026-07-27. See the decommission notice above.
|
||||
|
||||
## Architecture
|
||||
|
||||
|
|
|
|||
|
|
@ -1,5 +1,7 @@
|
|||
# RustDesk Server — Runbook
|
||||
|
||||
> **Obsolete as of 2026-07-27** — the `rustdesk-server` stack no longer exists; this runbook is retained for historical reference only.
|
||||
|
||||
Operational procedures for the `rustdesk-server` stack. Account 328440206208, us-east-1.
|
||||
|
||||
## Access
|
||||
|
|
|
|||
Reference in a new issue