* feat(infra): migrate syslog-server to HCP Terraform
Replace the mgmt CDK stack with a seahaven-prod HCP workspace so the
collector is owned by Terraform before UniFi cutover.
* fix(infra): keep no-logs alarm quiet until UniFi cutover
The new prod unifi-syslog group is empty until devices are re-pointed, so treat_missing_data=breaching would page site-alerts on first apply.
* fix(infra): allow scoped apply to modify SG rules in place
Authorize/Revoke plus description updates are not enough for aws_vpc_security_group_*_rule in-place changes after the bootstrap window.
The README covered the deployed AWS resources but never described the
CDK app itself — the cdk.json manifest, the bin/lib entry points, and
the committed context cache. Add a "CDK app" section so the
infrastructure-as-code component is documented alongside the resources
it provisions.
Refs: INFRA-12
CDK stack for the EC2 syslog collector (rsyslog 514 -> CloudWatch agent ->
unifi-syslog), mirroring the file-share/forgejo pattern. Recreated from the
captured console config; EIP 184.72.154.32 imported + re-associated so the
UniFi forwarding target is unchanged. Deployed + verified 2026-06-09.
Note: deploy role can assume cdk-hnb659fds-* (account-admin via CDK
bootstrap) — same exposure as every org CDK deploy role; per-app qualifier
is a known org-wide follow-up.