Commit graph

3 commits

Author SHA1 Message Date
Adam Moussa
2b12aba50e
feat(infra): archive UniFi All Traffic to S3 via Vector (PLAT-206) (#41)
Replace the public rsyslog-to-CloudWatch collector with Vector over a
prod 10.40 IPsec VGW, Firehose, 90-day S3, Glue, and Athena.
2026-09-17 18:48:25 +00:00
Adam Moussa
dd61d34cd7
fix(infra): allow scoped apply to create the EC2 recover alarm (PLAT-78) (#40)
* fix(infra): allow scoped apply to create the EC2 recover alarm

PutMetricAlarm with the automate recover action needs RecoverInstances plus CreateServiceLinkedRole for AWSServiceRoleForCloudWatchEvents, which does not exist in seahaven-prod yet.

* docs: record prod EIP and bootstrap-then-scoped apply split

Bootstrap cannot CreateVpc; the live collector is 184.193.220.187 until UniFi is re-pointed.
2026-09-16 21:48:35 +00:00
Adam Moussa
e17b284370
feat(infra): migrate syslog-server to HCP Terraform (PLAT-78) (#38)
* feat(infra): migrate syslog-server to HCP Terraform

Replace the mgmt CDK stack with a seahaven-prod HCP workspace so the
collector is owned by Terraform before UniFi cutover.

* fix(infra): keep no-logs alarm quiet until UniFi cutover

The new prod unifi-syslog group is empty until devices are re-pointed, so treat_missing_data=breaching would page site-alerts on first apply.

* fix(infra): allow scoped apply to modify SG rules in place

Authorize/Revoke plus description updates are not enough for aws_vpc_security_group_*_rule in-place changes after the bootstrap window.
2026-09-16 21:29:43 +00:00