Commit graph

11 commits

Author SHA1 Message Date
Adam Moussa
2bd0b7a5bc
build(deps): migrate CDK app ts-node->tsx, adopt typescript 7 (INFRA-183) (#11)
Some checks failed
Deploy / deploy (push) Has been cancelled
2026-07-08 17:48:22 -04:00
dependabot[bot]
24a204a7e3
chore(deps-dev): bump @types/node from 22.19.20 to 26.1.1 (#10)
Bumps [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node) from 22.19.20 to 26.1.1.
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases)
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node)

---
updated-dependencies:
- dependency-name: "@types/node"
  dependency-version: 26.1.1
  dependency-type: direct:development
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-08 17:03:12 -04:00
dependabot[bot]
326714f058
chore(deps): bump the minor-and-patch group with 2 updates (#8)
Some checks are pending
Deploy / deploy (push) Waiting to run
Bumps the minor-and-patch group with 2 updates: [aws-cdk-lib](https://github.com/aws/aws-cdk/tree/HEAD/packages/aws-cdk-lib) and [aws-cdk](https://github.com/aws/aws-cdk-cli/tree/HEAD/packages/aws-cdk).


Updates `aws-cdk-lib` from 2.257.0 to 2.261.0
- [Release notes](https://github.com/aws/aws-cdk/releases)
- [Changelog](https://github.com/aws/aws-cdk/blob/main/CHANGELOG.v2.alpha.md)
- [Commits](https://github.com/aws/aws-cdk/commits/v2.261.0/packages/aws-cdk-lib)

Updates `aws-cdk` from 2.1126.0 to 2.1129.0
- [Release notes](https://github.com/aws/aws-cdk-cli/releases)
- [Commits](https://github.com/aws/aws-cdk-cli/commits/aws-cdk@v2.1129.0/packages/aws-cdk)

---
updated-dependencies:
- dependency-name: aws-cdk-lib
  dependency-version: 2.261.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: aws-cdk
  dependency-version: 2.1129.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-08 16:45:14 -04:00
Adam Moussa
7f64f00601
ci: add dependabot coverage (INFRA-130) (#7) 2026-07-08 16:32:26 -04:00
Adam Moussa
ef5fc34b75
chore(ci): SHA-pin org reusable-workflow caller refs (INFRA-50) (#6)
Some checks failed
Deploy / deploy (push) Has been cancelled
2026-07-06 18:27:15 -04:00
Adam Moussa
5f19dfb054
docs: link Confluence AWS Architecture Map (INFRA-53) (#5)
Some checks are pending
Deploy / deploy (push) Waiting to run
2026-07-06 17:44:28 -04:00
Adam Moussa
6c34bf7e66
feat(syslog-server): IaC-managed EC2 StatusCheckFailed alarm + auto-recovery (INFRA-58) (#4)
Some checks failed
Deploy / deploy (push) Has been cancelled
Add a CloudFormation-managed EC2 status-check alarm for the live syslog
instance, replacing the orphaned EC2-StatusCheck-syslog-server alarm that
still points at the terminated i-0a7470914f0151b97.

The instance is a CFN resource in this stack, so both alarms dimension on
instance.instanceId (Ref) rather than a literal id — they follow the
instance across future replacements (e.g. userDataCausesReplacement).

- EC2-StatusCheck-syslog-server: combined StatusCheckFailed, Maximum >= 1,
  300s period, 2 eval periods, treatMissingData=breaching, SNS -> site-alerts.
  Mirrors the existing Syslog-NoIncomingLogs SNS reference.
- EC2-StatusCheckSystem-syslog-server-recover: StatusCheckFailed_System with
  an EC2 recover action (+ SNS). AWS only allows RECOVER on the _System
  metric, not the combined metric, so it is a separate alarm;
  treatMissingData=notBreaching per AWS recovery-alarm guidance.

Validated with tsc, cdk synth, cfn-lint (W2001 bootstrap warning only).
The pre-existing orphaned alarm is deleted separately, not here.
2026-06-17 15:02:04 -04:00
Adam Moussa
fbb627027f
Repo hygiene: PR labeler + README badges (INFRA-56/57) (#3)
Some checks failed
Deploy / deploy (push) Has been cancelled
- Add Labeler workflow calling org reusable callable-labeler.yaml
- Add README status badges (TypeScript, AWS CDK, CI)

Part of INFRA-47 (INFRA-56, INFRA-57).
2026-06-11 14:13:59 -04:00
Adam Moussa
6d52b246b1
fix(syslog-server): rotate /var/log/remote so the disk can't fill (INFRA-11) (#2)
Some checks failed
Deploy / deploy (push) Has been cancelled
The collector's remote-syslog spool had no rotation, so each gateway's
/var/log/remote/<host>/<host>.log grew unbounded. Low risk at the old
~109 events/day, but the gateways now forward ~60k/day. CloudWatch (90d)
is the system of record; the local files are only a CW-agent spool, so
keep a short 7-day compressed window. copytruncate keeps rsyslog's open
dynaFile handles valid (truncate in place).

Applied live already; this codifies it so an instance replacement keeps it
(mirrors the existing netflow-retention timer). Deploying this user-data
change forces an instance replacement (userDataCausesReplacement) — the EIP
re-associates and the forwarding target is unchanged, so do it in a window.
2026-06-10 13:14:28 -04:00
97bc751782 feat: reproduce NetFlow collectors + force user-data replacement (INFRA-12)
Some checks are pending
Deploy / deploy (push) Waiting to run
- Build nfdump 1.6.23 from source in user-data (rrdtool-devel for librrd;
  not packaged on AL2023) and run nfcapd collectors as systemd units:
  nfcapd.service (Ronkonkoma udp/2055), nfcapd-locust.service (Locust udp/2056),
  + netflow-retention.timer (30d sweep). 1 GiB swapfile for build headroom.
- userDataCausesReplacement: true — a user-data change must actually re-run,
  so force instance replacement (stateless box, EIP re-associates).

Validated: build + all services active, listeners on 514/2055/2056.
2026-06-09 14:11:58 -04:00
a8276b44fd feat: syslog-server under IaC (INFRA-12)
CDK stack for the EC2 syslog collector (rsyslog 514 -> CloudWatch agent ->
unifi-syslog), mirroring the file-share/forgejo pattern. Recreated from the
captured console config; EIP 184.72.154.32 imported + re-associated so the
UniFi forwarding target is unchanged. Deployed + verified 2026-06-09.

Note: deploy role can assume cdk-hnb659fds-* (account-admin via CDK
bootstrap) — same exposure as every org CDK deploy role; per-app qualifier
is a known org-wide follow-up.
2026-06-09 13:51:17 -04:00