mirror of
https://github.com/Sea-Haven-Industries/syslog-server.git
synced 2026-09-30 05:23:16 +00:00
fix(syslog-server): allow UDM tunnel source + pin collector private IP (INFRA-11)
Two durable fixes for the root causes that took the UniFi syslog feed dark when the collector was recreated under IaC on 2026-06-09: 1. SecurityGroup: allow udp/tcp 514 from 192.168.0.0/24. The UDM gateways forward via syslog-ng / unifi-core sourced from the IPsec VTI tunnel inside-address (192.168.0.x), not their LAN IP, so the recreated SG silently denied all gateway-originated syslog at the ENI. (A LAN client keeps its 10.10.x source and was always allowed — which masked the issue.) 2. Pin the instance PrivateIpAddress to 10.20.10.221. The fleet forwards to this address over the site-to-site VPN; the recreation moved it .111->.221 and orphaned every console's syslog target. Pinning keeps it stable across future replacements. DEPLOY NOTES: - (1) was applied live out-of-band to restore service; delete that live SG rule immediately before `cdk deploy` or CFN errors on InvalidPermission.Duplicate. - (2) forces an instance replacement (cdk diff: PrivateIpAddress requires replacement; EIP re-associates). Deploy in a maintenance window — ~2-3 min log-collection gap while user-data re-runs; ends at the same .221 so no console reconfig needed.
This commit is contained in:
parent
97bc751782
commit
c5839e23f4
1 changed files with 15 additions and 3 deletions
|
|
@ -56,6 +56,10 @@ export class SyslogServerStack extends cdk.Stack {
|
|||
sg.addIngressRule(ec2.Peer.ipv4("10.10.0.0/16"), proto, "syslog from office VPN");
|
||||
sg.addIngressRule(ec2.Peer.ipv4("10.20.0.0/16"), proto, "syslog from VPC");
|
||||
sg.addIngressRule(ec2.Peer.ipv4("10.30.0.0/16"), proto, "syslog from VPN pool");
|
||||
// The UDM gateways forward via syslog-ng / unifi-core, which source from the
|
||||
// IPsec VTI tunnel inside-address (192.168.0.x), NOT their LAN IP. Without this
|
||||
// the ENI silently drops all gateway-originated syslog (INFRA-11, 2026-06-09).
|
||||
sg.addIngressRule(ec2.Peer.ipv4("192.168.0.0/24"), proto, "syslog from UDM IPsec tunnel source");
|
||||
}
|
||||
|
||||
// SSH (SSM is the primary access path; 22 kept for break-glass from office/VPC).
|
||||
|
|
@ -239,9 +243,17 @@ export class SyslogServerStack extends cdk.Stack {
|
|||
],
|
||||
});
|
||||
|
||||
// Re-associate the existing Elastic IP (184.72.154.32) so the UniFi fleet's
|
||||
// forwarding target is unchanged. The allocation is UNMANAGED (referenced by
|
||||
// ID) — CloudFormation can associate it but never release it.
|
||||
// Pin the private IP. The UniFi fleet forwards to this address over the
|
||||
// site-to-site VPN (the EIP is NOT the forwarding target — gateway-originated
|
||||
// traffic to a public IP would leave over the WAN). When the instance was
|
||||
// recreated under IaC on 2026-06-09 the private IP changed .111 -> .221 and
|
||||
// silently orphaned every console's syslog target. Pinning it keeps the target
|
||||
// stable across future replacements (INFRA-11). Must be inside this subnet's CIDR.
|
||||
(instance.node.defaultChild as ec2.CfnInstance).privateIpAddress = "10.20.10.221";
|
||||
|
||||
// Re-associate the existing Elastic IP (184.72.154.32). The allocation is
|
||||
// UNMANAGED (referenced by ID) — CloudFormation can associate it but never
|
||||
// release it. Kept for break-glass / direct reachability; not the syslog target.
|
||||
new ec2.CfnEIPAssociation(this, "EipAssociation", {
|
||||
allocationId: "eipalloc-006bdefc9802f3285",
|
||||
instanceId: instance.instanceId,
|
||||
|
|
|
|||
Loading…
Add table
Reference in a new issue