From 9092b3e0e6d7529812fff120a863d00422dbfd36 Mon Sep 17 00:00:00 2001 From: Adam Moussa Date: Sun, 28 Jun 2026 17:21:25 -0400 Subject: [PATCH] Add internal DNS for the Pro admin console The public rustdesk.seahaven.com name resolves to the EIP, which the security group blocks on the admin port (21114). Add an internal-only rustdesk-admin.int.seahaven.com record pointed at the instance private IP so the console is reachable over the VPN without using the raw IP. --- cdk.context.json | 4 ++++ lib/rustdesk-server-stack.ts | 20 ++++++++++++++++++++ 2 files changed, 24 insertions(+) diff --git a/cdk.context.json b/cdk.context.json index d49e851..13097dc 100644 --- a/cdk.context.json +++ b/cdk.context.json @@ -48,5 +48,9 @@ "hosted-zone:account=328440206208:domainName=seahaven.com:region=us-east-1": { "Id": "/hostedzone/Z06652411XKH89KTZD3XA", "Name": "seahaven.com." + }, + "hosted-zone:account=328440206208:domainName=int.seahaven.com:region=us-east-1": { + "Id": "/hostedzone/Z00850883ICXG8M68KGU0", + "Name": "int.seahaven.com." } } diff --git a/lib/rustdesk-server-stack.ts b/lib/rustdesk-server-stack.ts index 1db0b12..08b18f0 100644 --- a/lib/rustdesk-server-stack.ts +++ b/lib/rustdesk-server-stack.ts @@ -25,6 +25,12 @@ const AVAILABILITY_ZONE = "us-east-1a"; const HOSTED_ZONE_NAME = "seahaven.com"; const RECORD_NAME = "rustdesk.seahaven.com"; +// Internal-only name for the Pro admin console, pointed at the instance's +// private IP so it is reachable over the VPN (the public name above resolves to +// the EIP, which the SG blocks on the admin port 21114). +const ADMIN_ZONE_NAME = "int.seahaven.com"; +const ADMIN_RECORD_NAME = "rustdesk-admin.int.seahaven.com"; + // Internal trusted ranges for the admin/management plane. const OFFICE_VPN_CIDR = "10.10.0.0/16"; const VPC_CIDR = "10.20.0.0/16"; @@ -187,6 +193,17 @@ export class RustdeskServerStack extends cdk.Stack { ttl: cdk.Duration.minutes(5), }); + // Internal admin-console name -> instance private IP (VPN-reachable only). + const adminZone = route53.HostedZone.fromLookup(this, "AdminZone", { + domainName: ADMIN_ZONE_NAME, + }); + new route53.ARecord(this, "AdminARecord", { + zone: adminZone, + recordName: ADMIN_RECORD_NAME, + target: route53.RecordTarget.fromIpAddresses(instance.instancePrivateIp), + ttl: cdk.Duration.minutes(5), + }); + // ── Nightly EBS snapshots ─────────────────────────────────────── const dlmRole = new iam.Role(this, "DlmRole", { roleName: "rustdesk-server-dlm", @@ -223,5 +240,8 @@ export class RustdeskServerStack extends cdk.Stack { // ── Outputs ───────────────────────────────────────────────────── new cdk.CfnOutput(this, "PublicIp", { value: eip.ref }); new cdk.CfnOutput(this, "Hostname", { value: RECORD_NAME }); + new cdk.CfnOutput(this, "AdminConsole", { + value: `http://${ADMIN_RECORD_NAME}:21114`, + }); } }