diff --git a/lib/syslog-server-stack.ts b/lib/syslog-server-stack.ts index ae2528d..b2f51cd 100644 --- a/lib/syslog-server-stack.ts +++ b/lib/syslog-server-stack.ts @@ -56,6 +56,10 @@ export class SyslogServerStack extends cdk.Stack { sg.addIngressRule(ec2.Peer.ipv4("10.10.0.0/16"), proto, "syslog from office VPN"); sg.addIngressRule(ec2.Peer.ipv4("10.20.0.0/16"), proto, "syslog from VPC"); sg.addIngressRule(ec2.Peer.ipv4("10.30.0.0/16"), proto, "syslog from VPN pool"); + // The UDM gateways forward via syslog-ng / unifi-core, which source from the + // IPsec VTI tunnel inside-address (192.168.0.x), NOT their LAN IP. Without this + // the ENI silently drops all gateway-originated syslog (INFRA-11, 2026-06-09). + sg.addIngressRule(ec2.Peer.ipv4("192.168.0.0/24"), proto, "syslog from UDM IPsec tunnel source"); } // SSH (SSM is the primary access path; 22 kept for break-glass from office/VPC). @@ -239,9 +243,17 @@ export class SyslogServerStack extends cdk.Stack { ], }); - // Re-associate the existing Elastic IP (184.72.154.32) so the UniFi fleet's - // forwarding target is unchanged. The allocation is UNMANAGED (referenced by - // ID) — CloudFormation can associate it but never release it. + // Pin the private IP. The UniFi fleet forwards to this address over the + // site-to-site VPN (the EIP is NOT the forwarding target — gateway-originated + // traffic to a public IP would leave over the WAN). When the instance was + // recreated under IaC on 2026-06-09 the private IP changed .111 -> .221 and + // silently orphaned every console's syslog target. Pinning it keeps the target + // stable across future replacements (INFRA-11). Must be inside this subnet's CIDR. + (instance.node.defaultChild as ec2.CfnInstance).privateIpAddress = "10.20.10.221"; + + // Re-associate the existing Elastic IP (184.72.154.32). The allocation is + // UNMANAGED (referenced by ID) — CloudFormation can associate it but never + // release it. Kept for break-glass / direct reachability; not the syslog target. new ec2.CfnEIPAssociation(this, "EipAssociation", { allocationId: "eipalloc-006bdefc9802f3285", instanceId: instance.instanceId,