Commit graph

19 commits

Author SHA1 Message Date
f56b8f3d4e
docs: decommission rustdesk-server (stack torn down 2026-07-27)
Stack rustdesk-server (328440206208/us-east-1) fully deleted: EC2, EIP
100.27.82.124 (released), SG, launch template, IAM roles, DLM policy,
both Route53 records. Orphaned data volumes deleted with no snapshot
(explicit owner decision — no backups exist). Secrets force-deleted,
SSM params deleted, OIDC deploy role + repo secret removed.

Removes all GitHub automation (workflows, dependabot) ahead of repo
archival; README carries the decommission banner, RUNBOOK marked
obsolete. Adds a repo-local suppression for the aws-cdk-lib-bundled
brace-expansion advisory (unfixable upstream, repo archived).
2026-07-27 12:14:26 -04:00
dependabot[bot]
f1d029f31d
build(deps-dev): bump aws-cdk from 2.1132.0 to 2.1133.0 (#19) 2026-07-26 05:06:57 +00:00
dependabot[bot]
e72e5a959a
build(deps): bump constructs from 10.7.0 to 10.7.1 (#17) 2026-07-26 01:05:43 -04:00
dependabot[bot]
208ab38b2b
build(deps-dev): bump aws-cdk from 2.1130.0 to 2.1132.0 (#15) 2026-07-19 15:06:24 +00:00
dependabot[bot]
4ba9e95d90
build(deps-dev): bump tsx from 4.23.0 to 4.23.1 (#14) 2026-07-19 15:05:38 +00:00
dependabot[bot]
56f31228d4
build(deps): bump constructs from 10.6.0 to 10.7.0 (#16) 2026-07-19 11:04:57 -04:00
dependabot[bot]
4f6473cc8c
build(deps-dev): bump aws-cdk from 2.1129.0 to 2.1130.0 (#12) 2026-07-12 13:02:35 +00:00
dependabot[bot]
ea76952d52
build(deps-dev): bump @types/node from 24.13.2 to 24.13.3 (#13) 2026-07-12 08:59:51 -04:00
Adam Moussa
1bb3c4a6a6
Document CDK app structure in README (#11)
The README described the deployed architecture and resources but never
documented that the repo itself is a CDK v2 app, leaving cdk.json and
the bin/lib layout unexplained for anyone opening the codebase.

Add a "CDK app" section mapping cdk.json, bin/app.ts, the stack file,
cdk.context.json, and the TypeScript config to their roles, so the
infrastructure-as-code component is discoverable from the README.
2026-07-10 16:07:16 -04:00
Adam Moussa
6d79577266
build(deps): migrate CDK app ts-node->tsx, adopt typescript 7 (INFRA-183) (#10)
Swap the cdk.json app runner from ts-node to tsx and pin tsx 4.23.0
to match sh-mcp. Bump typescript to ~7.0.2; ts-node 10.x is
incompatible with the TS7 compiler API.
2026-07-08 17:33:56 -04:00
Adam Moussa
8e869a79e2
chore(ci): SHA-pin org reusable-workflow caller refs (INFRA-50) (#9) 2026-07-06 18:27:28 -04:00
Adam Moussa
1b32073680
docs: link Confluence AWS Architecture Map (INFRA-53) (#8) 2026-07-06 17:44:39 -04:00
Adam Moussa
4a2e211750
docs: add README status badges (INFRA-137) (#7) 2026-07-06 17:41:15 -04:00
dependabot[bot]
b70cc7eb77
Bump aws-cdk from 2.1128.1 to 2.1129.0 (#5) 2026-07-04 05:55:59 +00:00
dependabot[bot]
2118a3ab2a
Bump aws-cdk-lib from 2.260.0 to 2.261.0 (#6) 2026-07-04 01:53:01 -04:00
seahaven-openswe[bot]
b0f664961a
fix: pin @types/node to CI runtime major and block dependabot major bumps (#4) 2026-07-04 01:49:40 -04:00
Adam Moussa
eec669d978
Add internal DNS for the Pro admin console (#2)
The public rustdesk.seahaven.com name resolves to the EIP, which the
security group blocks on the admin port (21114). Add an internal-only
rustdesk-admin.int.seahaven.com record pointed at the instance private IP
so the console is reachable over the VPN without using the raw IP.
2026-06-28 17:25:14 -04:00
c68dae7741
Enable unique IMDSv2 launch-template naming
The requireImdsv2 aspect names its launch template "<id>LaunchTemplate"
by default, which collided with an existing account-global
InstanceLaunchTemplate and failed the first deploy. Enabling
@aws-cdk/aws-ec2:uniqueImdsv2TemplateName makes the name hash-unique.
2026-06-28 16:55:53 -04:00
9f18ecab50
Add RustDesk Server Pro self-hosted relay stack
Scaffold the CDK stack for a self-hosted RustDesk Server Pro relay so
remote support no longer depends on the public RustDesk rendezvous/relay
infrastructure.

Single ARM64 EC2 (SSM-managed, no SSH) runs hbbs+hbbr in Docker. The
server key pair and DB live on a standalone RETAINed EBS volume so they
survive instance replacement (clients keep trusting the same key). Relay
ports are public; the Pro admin console (21114) is restricted to the
office VPN + VPC. IMDSv2 is enforced and the data dir is locked to root.
EIP + rustdesk.seahaven.com give clients a stable address.
2026-06-28 16:47:32 -04:00