syslog-server/lib
Adam Moussa c5839e23f4 fix(syslog-server): allow UDM tunnel source + pin collector private IP (INFRA-11)
Two durable fixes for the root causes that took the UniFi syslog feed dark
when the collector was recreated under IaC on 2026-06-09:

1. SecurityGroup: allow udp/tcp 514 from 192.168.0.0/24. The UDM gateways
   forward via syslog-ng / unifi-core sourced from the IPsec VTI tunnel
   inside-address (192.168.0.x), not their LAN IP, so the recreated SG
   silently denied all gateway-originated syslog at the ENI. (A LAN client
   keeps its 10.10.x source and was always allowed — which masked the issue.)

2. Pin the instance PrivateIpAddress to 10.20.10.221. The fleet forwards to
   this address over the site-to-site VPN; the recreation moved it .111->.221
   and orphaned every console's syslog target. Pinning keeps it stable across
   future replacements.

DEPLOY NOTES:
- (1) was applied live out-of-band to restore service; delete that live SG
  rule immediately before `cdk deploy` or CFN errors on InvalidPermission.Duplicate.
- (2) forces an instance replacement (cdk diff: PrivateIpAddress requires
  replacement; EIP re-associates). Deploy in a maintenance window — ~2-3 min
  log-collection gap while user-data re-runs; ends at the same .221 so no
  console reconfig needed.
2026-06-09 18:07:03 -04:00
..
syslog-server-stack.ts fix(syslog-server): allow UDM tunnel source + pin collector private IP (INFRA-11) 2026-06-09 18:07:03 -04:00