Commit graph

8 commits

Author SHA1 Message Date
Adam Moussa
1b32073680
docs: link Confluence AWS Architecture Map (INFRA-53) (#8) 2026-07-06 17:44:39 -04:00
Adam Moussa
4a2e211750
docs: add README status badges (INFRA-137) (#7) 2026-07-06 17:41:15 -04:00
dependabot[bot]
b70cc7eb77
Bump aws-cdk from 2.1128.1 to 2.1129.0 (#5) 2026-07-04 05:55:59 +00:00
dependabot[bot]
2118a3ab2a
Bump aws-cdk-lib from 2.260.0 to 2.261.0 (#6) 2026-07-04 01:53:01 -04:00
seahaven-openswe[bot]
b0f664961a
fix: pin @types/node to CI runtime major and block dependabot major bumps (#4) 2026-07-04 01:49:40 -04:00
Adam Moussa
eec669d978
Add internal DNS for the Pro admin console (#2)
The public rustdesk.seahaven.com name resolves to the EIP, which the
security group blocks on the admin port (21114). Add an internal-only
rustdesk-admin.int.seahaven.com record pointed at the instance private IP
so the console is reachable over the VPN without using the raw IP.
2026-06-28 17:25:14 -04:00
c68dae7741
Enable unique IMDSv2 launch-template naming
The requireImdsv2 aspect names its launch template "<id>LaunchTemplate"
by default, which collided with an existing account-global
InstanceLaunchTemplate and failed the first deploy. Enabling
@aws-cdk/aws-ec2:uniqueImdsv2TemplateName makes the name hash-unique.
2026-06-28 16:55:53 -04:00
9f18ecab50
Add RustDesk Server Pro self-hosted relay stack
Scaffold the CDK stack for a self-hosted RustDesk Server Pro relay so
remote support no longer depends on the public RustDesk rendezvous/relay
infrastructure.

Single ARM64 EC2 (SSM-managed, no SSH) runs hbbs+hbbr in Docker. The
server key pair and DB live on a standalone RETAINed EBS volume so they
survive instance replacement (clients keep trusting the same key). Relay
ports are public; the Pro admin console (21114) is restricted to the
office VPN + VPC. IMDSv2 is enforced and the data dir is locked to root.
EIP + rustdesk.seahaven.com give clients a stable address.
2026-06-28 16:47:32 -04:00