# syslog-server CDK stack for the **syslog-server** EC2 collector: receives remote syslog (UDP/TCP 514) from the office UniFi fleet over its Elastic IP and ships it to the `unifi-syslog` CloudWatch Logs group via the CloudWatch agent. Brought under IaC for **INFRA-12** (AWS audit L-6). Previously a console/CLI instance with no drift detection. ## Architecture ``` office UniFi devices ──syslog/514──▶ EIP 184.72.154.32 ──▶ EC2 (rsyslog) │ /var/log/remote//*.log │ CloudWatch agent ──▶ unifi-syslog (90d) │ Syslog-NoIncomingLogs alarm ──▶ site-alerts ``` | Resource | Value | |---|---| | Instance | `syslog-server`, t4g.nano, Amazon Linux 2023 (arm64), 30 GiB encrypted gp3 | | Subnet | `subnet-0eea820effe1b3ae5` (public, us-east-1a, `vpc-0d3d4b67bd0cf8a68`) | | Elastic IP | `184.72.154.32` (`eipalloc-006bdefc9802f3285`) — **unmanaged**, re-associated by ID | | Security group | `syslog-server` — 514 tcp/udp + 22 from office IPs + VPC/VPN CIDRs; 2055/2056 udp reserved (netflow/sflow) | | IAM role | `syslog-server-role` — `AmazonSSMManagedInstanceCore` + `CloudWatchAgentServerPolicy` | | Log group | `unifi-syslog` (90-day retention) — created/retained by the CW agent, **not** a CFN resource (holds history; see stack comment) | | Alarm | `Syslog-NoIncomingLogs` — `IncomingLogEvents` Sum < 1 over 2×1-day, ALARM-only → `site-alerts` | ## Access SSM Session Manager (no key pair). SSH 22 is open from office/VPC for break-glass only. ## Deploy CI/CD via the org reusable workflows (`ci-typescript-cdk.yaml`, `cd-cdk.yaml`); merges to `main` deploy through the `githubdeploy-syslog-server` OIDC role. No Docker assets, so a local `cdk deploy` is also safe. ``` npm ci npm run diff npm run deploy ``` ## Notes - **EIP is unmanaged.** CloudFormation associates it but never releases it, so the public forwarding target survives any instance replacement. - **AMI is pinned in `cdk.context.json`** (`cachedInContext`). An AL2023 AMI change forces instance replacement — refresh deliberately with `cdk context --reset && cdk synth`. - To widen device coverage of the forwarded syslog feed, see **INFRA-11** (UniFi controller remote-logging config).