- Add ignore rule in dependabot.yml for @types/node semver-major updates
- Pin @types/node from ^25 to ^24 (matches node-version in CI workflow)
- Sanctioned exception to the no-blanket-ignore rule: @types/node must
track the runtime Node major, and Dependabot cannot detect the runtime
- Confirmed tsc and cdk synth pass with the pinned version
Closes#3
The public rustdesk.seahaven.com name resolves to the EIP, which the
security group blocks on the admin port (21114). Add an internal-only
rustdesk-admin.int.seahaven.com record pointed at the instance private IP
so the console is reachable over the VPN without using the raw IP.
The requireImdsv2 aspect names its launch template "<id>LaunchTemplate"
by default, which collided with an existing account-global
InstanceLaunchTemplate and failed the first deploy. Enabling
@aws-cdk/aws-ec2:uniqueImdsv2TemplateName makes the name hash-unique.
Scaffold the CDK stack for a self-hosted RustDesk Server Pro relay so
remote support no longer depends on the public RustDesk rendezvous/relay
infrastructure.
Single ARM64 EC2 (SSM-managed, no SSH) runs hbbs+hbbr in Docker. The
server key pair and DB live on a standalone RETAINed EBS volume so they
survive instance replacement (clients keep trusting the same key). Relay
ports are public; the Pro admin console (21114) is restricted to the
office VPN + VPC. IMDSv2 is enforced and the data dir is locked to root.
EIP + rustdesk.seahaven.com give clients a stable address.