- Build nfdump 1.6.23 from source in user-data (rrdtool-devel for librrd;
not packaged on AL2023) and run nfcapd collectors as systemd units:
nfcapd.service (Ronkonkoma udp/2055), nfcapd-locust.service (Locust udp/2056),
+ netflow-retention.timer (30d sweep). 1 GiB swapfile for build headroom.
- userDataCausesReplacement: true — a user-data change must actually re-run,
so force instance replacement (stateless box, EIP re-associates).
Validated: build + all services active, listeners on 514/2055/2056.
CDK stack for the EC2 syslog collector (rsyslog 514 -> CloudWatch agent ->
unifi-syslog), mirroring the file-share/forgejo pattern. Recreated from the
captured console config; EIP 184.72.154.32 imported + re-associated so the
UniFi forwarding target is unchanged. Deployed + verified 2026-06-09.
Note: deploy role can assume cdk-hnb659fds-* (account-admin via CDK
bootstrap) — same exposure as every org CDK deploy role; per-app qualifier
is a known org-wide follow-up.