Add internal DNS for the Pro admin console #2
2 changed files with 24 additions and 0 deletions
|
|
@ -48,5 +48,9 @@
|
||||||
"hosted-zone:account=328440206208:domainName=seahaven.com:region=us-east-1": {
|
"hosted-zone:account=328440206208:domainName=seahaven.com:region=us-east-1": {
|
||||||
"Id": "/hostedzone/Z06652411XKH89KTZD3XA",
|
"Id": "/hostedzone/Z06652411XKH89KTZD3XA",
|
||||||
"Name": "seahaven.com."
|
"Name": "seahaven.com."
|
||||||
|
},
|
||||||
|
"hosted-zone:account=328440206208:domainName=int.seahaven.com:region=us-east-1": {
|
||||||
|
"Id": "/hostedzone/Z00850883ICXG8M68KGU0",
|
||||||
|
"Name": "int.seahaven.com."
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
|
||||||
|
|
@ -25,6 +25,12 @@ const AVAILABILITY_ZONE = "us-east-1a";
|
||||||
const HOSTED_ZONE_NAME = "seahaven.com";
|
const HOSTED_ZONE_NAME = "seahaven.com";
|
||||||
const RECORD_NAME = "rustdesk.seahaven.com";
|
const RECORD_NAME = "rustdesk.seahaven.com";
|
||||||
|
|
||||||
|
// Internal-only name for the Pro admin console, pointed at the instance's
|
||||||
|
// private IP so it is reachable over the VPN (the public name above resolves to
|
||||||
|
// the EIP, which the SG blocks on the admin port 21114).
|
||||||
|
const ADMIN_ZONE_NAME = "int.seahaven.com";
|
||||||
|
const ADMIN_RECORD_NAME = "rustdesk-admin.int.seahaven.com";
|
||||||
|
|
||||||
// Internal trusted ranges for the admin/management plane.
|
// Internal trusted ranges for the admin/management plane.
|
||||||
const OFFICE_VPN_CIDR = "10.10.0.0/16";
|
const OFFICE_VPN_CIDR = "10.10.0.0/16";
|
||||||
const VPC_CIDR = "10.20.0.0/16";
|
const VPC_CIDR = "10.20.0.0/16";
|
||||||
|
|
@ -187,6 +193,17 @@ export class RustdeskServerStack extends cdk.Stack {
|
||||||
ttl: cdk.Duration.minutes(5),
|
ttl: cdk.Duration.minutes(5),
|
||||||
});
|
});
|
||||||
|
|
||||||
|
// Internal admin-console name -> instance private IP (VPN-reachable only).
|
||||||
|
const adminZone = route53.HostedZone.fromLookup(this, "AdminZone", {
|
||||||
|
domainName: ADMIN_ZONE_NAME,
|
||||||
|
});
|
||||||
|
new route53.ARecord(this, "AdminARecord", {
|
||||||
|
zone: adminZone,
|
||||||
|
recordName: ADMIN_RECORD_NAME,
|
||||||
|
target: route53.RecordTarget.fromIpAddresses(instance.instancePrivateIp),
|
||||||
|
ttl: cdk.Duration.minutes(5),
|
||||||
|
});
|
||||||
|
|
||||||
// ── Nightly EBS snapshots ───────────────────────────────────────
|
// ── Nightly EBS snapshots ───────────────────────────────────────
|
||||||
const dlmRole = new iam.Role(this, "DlmRole", {
|
const dlmRole = new iam.Role(this, "DlmRole", {
|
||||||
roleName: "rustdesk-server-dlm",
|
roleName: "rustdesk-server-dlm",
|
||||||
|
|
@ -223,5 +240,8 @@ export class RustdeskServerStack extends cdk.Stack {
|
||||||
// ── Outputs ─────────────────────────────────────────────────────
|
// ── Outputs ─────────────────────────────────────────────────────
|
||||||
new cdk.CfnOutput(this, "PublicIp", { value: eip.ref });
|
new cdk.CfnOutput(this, "PublicIp", { value: eip.ref });
|
||||||
new cdk.CfnOutput(this, "Hostname", { value: RECORD_NAME });
|
new cdk.CfnOutput(this, "Hostname", { value: RECORD_NAME });
|
||||||
|
new cdk.CfnOutput(this, "AdminConsole", {
|
||||||
|
value: `http://${ADMIN_RECORD_NAME}:21114`,
|
||||||
|
});
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
|
||||||
Reference in a new issue