The README covered the deployed AWS resources but never described the
CDK app itself — the cdk.json manifest, the bin/lib entry points, and
the committed context cache. Add a "CDK app" section so the
infrastructure-as-code component is documented alongside the resources
it provisions.
Refs: INFRA-12
CDK stack for the EC2 syslog collector (rsyslog 514 -> CloudWatch agent ->
unifi-syslog), mirroring the file-share/forgejo pattern. Recreated from the
captured console config; EIP 184.72.154.32 imported + re-associated so the
UniFi forwarding target is unchanged. Deployed + verified 2026-06-09.
Note: deploy role can assume cdk-hnb659fds-* (account-admin via CDK
bootstrap) — same exposure as every org CDK deploy role; per-app qualifier
is a known org-wide follow-up.