Commit graph

11 commits

Author SHA1 Message Date
d5dc998dc5
Document CDK app structure in README
The README described the deployed architecture and resources but never
documented that the repo itself is a CDK v2 app, leaving cdk.json and
the bin/lib layout unexplained for anyone opening the codebase.

Add a "CDK app" section mapping cdk.json, bin/app.ts, the stack file,
cdk.context.json, and the TypeScript config to their roles, so the
infrastructure-as-code component is discoverable from the README.
2026-07-10 15:56:34 -04:00
Adam Moussa
6d79577266
build(deps): migrate CDK app ts-node->tsx, adopt typescript 7 (INFRA-183) (#10)
Swap the cdk.json app runner from ts-node to tsx and pin tsx 4.23.0
to match sh-mcp. Bump typescript to ~7.0.2; ts-node 10.x is
incompatible with the TS7 compiler API.
2026-07-08 17:33:56 -04:00
Adam Moussa
8e869a79e2
chore(ci): SHA-pin org reusable-workflow caller refs (INFRA-50) (#9) 2026-07-06 18:27:28 -04:00
Adam Moussa
1b32073680
docs: link Confluence AWS Architecture Map (INFRA-53) (#8) 2026-07-06 17:44:39 -04:00
Adam Moussa
4a2e211750
docs: add README status badges (INFRA-137) (#7) 2026-07-06 17:41:15 -04:00
dependabot[bot]
b70cc7eb77
Bump aws-cdk from 2.1128.1 to 2.1129.0 (#5) 2026-07-04 05:55:59 +00:00
dependabot[bot]
2118a3ab2a
Bump aws-cdk-lib from 2.260.0 to 2.261.0 (#6) 2026-07-04 01:53:01 -04:00
seahaven-openswe[bot]
b0f664961a
fix: pin @types/node to CI runtime major and block dependabot major bumps (#4) 2026-07-04 01:49:40 -04:00
Adam Moussa
eec669d978
Add internal DNS for the Pro admin console (#2)
The public rustdesk.seahaven.com name resolves to the EIP, which the
security group blocks on the admin port (21114). Add an internal-only
rustdesk-admin.int.seahaven.com record pointed at the instance private IP
so the console is reachable over the VPN without using the raw IP.
2026-06-28 17:25:14 -04:00
c68dae7741
Enable unique IMDSv2 launch-template naming
The requireImdsv2 aspect names its launch template "<id>LaunchTemplate"
by default, which collided with an existing account-global
InstanceLaunchTemplate and failed the first deploy. Enabling
@aws-cdk/aws-ec2:uniqueImdsv2TemplateName makes the name hash-unique.
2026-06-28 16:55:53 -04:00
9f18ecab50
Add RustDesk Server Pro self-hosted relay stack
Scaffold the CDK stack for a self-hosted RustDesk Server Pro relay so
remote support no longer depends on the public RustDesk rendezvous/relay
infrastructure.

Single ARM64 EC2 (SSM-managed, no SSH) runs hbbs+hbbr in Docker. The
server key pair and DB live on a standalone RETAINed EBS volume so they
survive instance replacement (clients keep trusting the same key). Relay
ports are public; the Pro admin console (21114) is restricted to the
office VPN + VPC. IMDSv2 is enforced and the data dir is locked to root.
EIP + rustdesk.seahaven.com give clients a stable address.
2026-06-28 16:47:32 -04:00