syslog-server/README.md
Adam Moussa 5f19dfb054
Some checks are pending
Deploy / deploy (push) Waiting to run
docs: link Confluence AWS Architecture Map (INFRA-53) (#5)
2026-07-06 17:44:28 -04:00

67 lines
3.1 KiB
Markdown
Raw Blame History

This file contains ambiguous Unicode characters

This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

# syslog-server
![TypeScript](https://img.shields.io/badge/TypeScript-3178C6?logo=typescript&logoColor=white)
![AWS CDK](https://img.shields.io/badge/AWS-CDK-FF9900?logo=amazonaws&logoColor=white)
![CI](https://github.com/Sea-Haven-Industries/syslog-server/actions/workflows/ci.yaml/badge.svg)
CDK stack for the **syslog-server** EC2 collector: receives remote syslog
(UDP/TCP 514) from the office UniFi fleet over its Elastic IP and ships it to
the `unifi-syslog` CloudWatch Logs group via the CloudWatch agent.
Brought under IaC for **INFRA-12** (AWS audit L-6). Previously a console/CLI
instance with no drift detection.
## Architecture
```
office UniFi devices ──syslog/514──▶ EIP 184.72.154.32 ──▶ EC2 (rsyslog)
│
/var/log/remote/<host>/*.log
│
CloudWatch agent ──▶ unifi-syslog (90d)
│
Syslog-NoIncomingLogs alarm ──▶ site-alerts
```
| Resource | Value |
|---|---|
| Instance | `syslog-server`, t4g.nano, Amazon Linux 2023 (arm64), 30 GiB encrypted gp3 |
| Subnet | `subnet-0eea820effe1b3ae5` (public, us-east-1a, `vpc-0d3d4b67bd0cf8a68`) |
| Elastic IP | `184.72.154.32` (`eipalloc-006bdefc9802f3285`) — **unmanaged**, re-associated by ID |
| Security group | `syslog-server` — 514 tcp/udp + 22 from office IPs + VPC/VPN CIDRs; 2055/2056 udp reserved (netflow/sflow) |
| IAM role | `syslog-server-role` — `AmazonSSMManagedInstanceCore` + `CloudWatchAgentServerPolicy` |
| Log group | `unifi-syslog` (90-day retention) — created/retained by the CW agent, **not** a CFN resource (holds history; see stack comment) |
| Alarm | `Syslog-NoIncomingLogs` — `IncomingLogEvents` Sum < 1 over 2×1-day, ALARM-only → `site-alerts` |
## Documentation
The canonical map of Sea Haven's AWS infrastructure lives in Confluence. This project's `syslog-server` stack is represented there as a Mermaid subgraph.
- **[AWS Architecture Map](https://seahaven.atlassian.net/wiki/spaces/IT/pages/1540098)** (Confluence, IT space, page 1540098)
## Access
SSM Session Manager (no key pair). SSH 22 is open from office/VPC for
break-glass only.
## Deploy
CI/CD via the org reusable workflows (`ci-typescript-cdk.yaml`,
`cd-cdk.yaml`); merges to `main` deploy through the `githubdeploy-syslog-server`
OIDC role. No Docker assets, so a local `cdk deploy` is also safe.
```
npm ci
npm run diff
npm run deploy
```
## Notes
- **EIP is unmanaged.** CloudFormation associates it but never releases it, so
the public forwarding target survives any instance replacement.
- **AMI is pinned in `cdk.context.json`** (`cachedInContext`). An AL2023 AMI
change forces instance replacement — refresh deliberately with
`cdk context --reset <ami key> && cdk synth`.
- To widen device coverage of the forwarded syslog feed, see **INFRA-11**
(UniFi controller remote-logging config).