Document CDK app layout in README (#12)
Some checks failed
Deploy / deploy (push) Has been cancelled

The README covered the deployed AWS resources but never described the
CDK app itself — the cdk.json manifest, the bin/lib entry points, and
the committed context cache. Add a "CDK app" section so the
infrastructure-as-code component is documented alongside the resources
it provisions.

Refs: INFRA-12
This commit is contained in:
Adam Moussa 2026-07-10 16:07:36 -04:00 • committed by GitHub
parent 2bd0b7a5bc
commit a4ef862d65
No known key found for this signature in database
GPG key ID: B5690EEEBB952194

View file

@ -33,6 +33,25 @@ office UniFi devices ──syslog/514──▶ EIP 184.72.154.32 ──▶ EC2 (
| Log group | `unifi-syslog` (90-day retention) — created/retained by the CW agent, **not** a CFN resource (holds history; see stack comment) | | Log group | `unifi-syslog` (90-day retention) — created/retained by the CW agent, **not** a CFN resource (holds history; see stack comment) |
| Alarm | `Syslog-NoIncomingLogs` — `IncomingLogEvents` Sum < 1 over 2×1-day, ALARM-only → `site-alerts` | | Alarm | `Syslog-NoIncomingLogs` — `IncomingLogEvents` Sum < 1 over 2×1-day, ALARM-only → `site-alerts` |
## CDK app
Infrastructure is a single-stack AWS CDK app written in TypeScript. `cdk.json` is
the app manifest the CDK CLI reads on every command: its `app` entry
(`npx tsx bin/app.ts`) runs the TypeScript entry point directly through `tsx`, so
`synth`/`deploy` need no separate `tsc` compile step. The file also carries the
`watch` globs (for `cdk watch`) and the CDK feature-flag `context`.
| Path | Role |
|---|---|
| `cdk.json` | CDK app manifest — `app` entry command, `watch` globs, feature-flag context |
| `bin/app.ts` | App entry point; instantiates `SyslogServerStack` with explicit `stackName: "syslog-server"` and env pinned to account `328440206208` / `us-east-1` |
| `lib/syslog-server-stack.ts` | The `syslog-server` stack — every resource in the table above (EC2 instance + rsyslog/CloudWatch/NetFlow user-data, security group, IAM role, EIP association, alarms) |
| `cdk.context.json` | Cached provider lookups — the VPC (`vpc-0d3d4b67bd0cf8a68`) and the pinned AL2023 AMI (`cachedInContext`); committed so synth is deterministic |
`aws-cdk-lib` is pinned to an exact version (`2.261.0`). The npm scripts wrap the
CDK CLI — `npm run synth`, `npm run diff`, `npm run deploy` — plus
`npm run build` (`tsc` type-check).
## Documentation ## Documentation
The canonical map of Sea Haven's AWS infrastructure lives in Confluence. This project's `syslog-server` stack is represented there as a Mermaid subgraph. The canonical map of Sea Haven's AWS infrastructure lives in Confluence. This project's `syslog-server` stack is represented there as a Mermaid subgraph.