mirror of
https://github.com/Sea-Haven-Industries/syslog-server.git
synced 2026-09-30 10:03:15 +00:00
docs: record prod EIP and bootstrap-then-scoped apply split
Bootstrap cannot CreateVpc; the live collector is 184.193.220.187 until UniFi is re-pointed.
This commit is contained in:
parent
57fba0c87f
commit
7ffb120e12
1 changed files with 5 additions and 5 deletions
10
README.md
10
README.md
|
|
@ -30,7 +30,7 @@ office UniFi devices ──syslog/514──▶ EIP (prod) ──▶ EC2 (rsyslog
|
|||
| HCP plan/apply roles | `hcptf-syslog-server-plan` / `hcptf-syslog-server` |
|
||||
| Instance | `syslog-server`, t4g.nano, Amazon Linux 2023 (arm64), 30 GiB encrypted gp3 |
|
||||
| VPC | dedicated `10.40.0.0/16`, public subnet `10.40.10.0/24` |
|
||||
| Elastic IP | Terraform-managed (see HCP output `public_ip`) |
|
||||
| Elastic IP | `184.193.220.187` (`eipalloc-07d82c1f79a22716a`) — UniFi still points at mgmt until INFRA-11 |
|
||||
| Security group | `syslog-server` — 514 tcp/udp + 22 from office IPs + VPC/VPN CIDRs; 2055/2056 udp from office |
|
||||
| Instance IAM | `/tf-managed/syslog-server-role` with `syslog-server-instance-boundary`; `AmazonSSMManagedInstanceCore` + `CloudWatchAgentServerPolicy` |
|
||||
| Log group | `unifi-syslog` (90-day retention) |
|
||||
|
|
@ -54,12 +54,12 @@ First apply uses the hcptf-bootstrap window (exact `StringEquals` trust, never
|
|||
3. Point workspace `TFC_AWS_APPLY_ROLE_ARN` / `TFC_AWS_PLAN_ROLE_ARN` at
|
||||
`hcptf-bootstrap` / `hcptf-bootstrap-plan`. Set `TFC_AWS_PROVIDER_AUTH=true`.
|
||||
Never `TFC_AWS_RUN_ROLE_ARN`.
|
||||
4. One manual apply. This creates the scoped `hcptf-*` roles, the instance
|
||||
boundary, VPC, instance, EIP, log group, and alarms.
|
||||
4. One manual apply as `hcptf-bootstrap` creates the scoped `hcptf-*` roles,
|
||||
boundary, and instance role. Bootstrap cannot `ec2:CreateVpc`; the rest of
|
||||
the stack applies as `hcptf-syslog-server`.
|
||||
5. Retarget `TFC_AWS_*` to `hcptf-syslog-server` / `hcptf-syslog-server-plan`.
|
||||
Re-run the create script with no `--allow-workspace`.
|
||||
6. Second manual apply as the scoped role. After live-path proof, seal
|
||||
auto-apply on.
|
||||
6. Manual apply as the scoped role. After live-path proof, seal auto-apply on.
|
||||
|
||||
`Syslog-NoIncomingLogs` defaults `treat_missing_data` to `notBreaching` so the
|
||||
empty prod log group does not page `site-alerts` before UniFi is re-pointed.
|
||||
|
|
|
|||
Loading…
Add table
Reference in a new issue